 In response to significant incidents and malicious cyber activity, Cybersecurity Advisories (CSA) provide critical infrastructure owners and operators and other entities with timely guidance to detect and respond to threats. Coordinating the development of these CSAs across the Federal Government and with international allies and partners improves support to victims. In May 2023, NSA, CISA, FBI, DOE, and international partners released a CSA detailing the tactics, techniques, and procedures (TTPs) of the PRC-sponsored Volt Typhoon actor, and later provided joint guidance for organizations to identify and mitigate these TTPs. The Cyber Safety Review Board (CSRB) reviews and assesses significant cyber incidents and makes recommendations for public and private sector organizations to prevent similar incidents from taking place. In August 2023, the CSRB released its analysis of the Lapsus$ threat actor group, highlighting the group’s exploitation of systemic ecosystem weaknesses to victimize organizations across the country. This report led to subsequent, ongoing efforts by CISA and DHS to ensure that necessary security features are provided to customers without additional cost. The CSRB’s third report, released in April 2024, focuses on the malicious targeting of cloud computing environments and makes recommendations for strengthening identity management and authentication in the cloud. The structured analysis performed by the CSRB plays a crucial role in identifying and sharing lessons learned from significant cyber incidents and developing actionable mitigations. CISA is committed to updating the National Cyber Incident Response Plan (NCIRP) by the end of 2024. The NCIRP outlines our national approach to handling significant cyber incidents, including defining key roles and responsibilities for Federal agencies, private sector entities, and SLTT entities, in accordance with Presidential Policy Directive 41, United States Cyber Incident Coordination. The cyber threat landscape and the cyber defense ecosystem have evolved significantly since the NCIRP was originally published in 2016. The updated NCIRP will provide a modern, agile, flexible framework to enable coordinated national incident response across the Federal Government, private sector, and other key partners. Disrupting and Degrading Adversary Activity The United States remains postured to use all instruments of national power to defend our interests in cyberspace and to disrupt and dismantle cyber threat actors. To counter ransomware and other forms of cybercrime, the Administration is pursuing new measures to improve the integrated use of diplomatic, information, military, financial, intelligence, and law enforcement capabilities, and to engage non-Federal and international partners in these activities. Disruption alone cannot defeat ransomware or other forms of malicious cyber activity, but it can have a meaningful impact on the problem. In September 2023, the DoD finalized its 2023 Department of Defense Cyber Strategy, which highlights the use of cyberspace operations through its policy of defending forward to actively disrupt malicious cyber activity before it can affect the United States and its interests. In March 2024, DoD released the Defense Industrial Base Cybersecurity Strategy to provide an actionable framework for sustaining a more resilient Joint Force and defense ecosystem. In 2023, U.S. Cyber Command’s Cyber National Mission Force deployed 22 times to 17 countries to conduct 2024 REPORT 14 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3