Utility Advances Cybersecurity Grant and Technical Assistance BIL Program to enhance the
cybersecurity posture of electric cooperative, municipal, and small investor-owned utilities. This
program helps these smaller utilities protect against, detect, respond to, and recover from
cybersecurity threats, and increases their participation in cybersecurity threat information sharing
programs.
The ongoing clean energy transition presents opportunities to build in security and resilience
across the foundations of our national infrastructure and clean energy supply chains. Through
implementation of grant programs included in the BIL and IRA, DOE and other Federal partners
are enabling grant recipients to procure and implement safer clean energy technologies. The BIL
also requires that certain projects funded under the law include a cybersecurity plan to maintain
or improve the project’s cybersecurity over its lifecycle.
In July 2023, DOE funded eight innovative small businesses that are advancing cybersecurity for
distributed energy resources (DERs) and in September announced $39 million of funding for
nine new National Laboratory projects to advance the cybersecurity of DERs. Also in
September 2023, the DOE Clean Energy Cybersecurity Accelerator graduated its inaugural
cohort, focusing on enabling technologies that offer authentication and authorization solutions
for industrial control systems. DOE further released an implementation guide for its National
Cyber-Informed Engineering Strategy to assist organizations in building cybersecurity into the
design of energy infrastructure. In January 2024, DOE also announced a $30 million funding
opportunity to support research, development, and demonstration (RD&D) of next generation
tools to protect clean energy delivery infrastructure from cyberattacks.
The Federal Government is funding RD&D in cutting-edge cybersecurity and resilience
technologies. The 2023 Federal Cybersecurity Research and Development Strategic Plan aligns
to the NCS and provides Federal agencies with specific guidance on priorities for Federal
funding, including human-centered cybersecurity, trustworthiness, cyber resilience, metrics, and
RD&D infrastructure. The plan also aligns with an August 2023 joint OMB-OSTP memo
outlining multi-agency research and development priorities for the fiscal year 2025 budget,
including critical and emerging technology and innovation that can mitigate cybersecurity risk.
Through its Secure and Trustworthy Cyberspace program, the NSF is funding research projects
focusing on critical infrastructure security and resilience.
The Administration is coordinating public and private actions to secure longstanding
vulnerabilities in the underlying technical foundations of the Internet. Making the BGP more
secure can significantly reduce harm resulting from unsecured Internet routing. In July 2023, the
FCC and CISA convened Federal partners, nonprofits, and industry partners, including Internet
service providers and cloud content providers, to develop a common understanding of the latest
BGP security improvements and coordinate efforts to accelerate them.
In October 2023, the President signed EO 14110 on the Safe, Secure, and Trustworthy
Development and Use of Artificial Intelligence to direct whole-of-government efforts to shape
the values-aligned development of AI. EO 14110 addresses the various ways by which AI may
impact the cybersecurity community. First, to explore ways to use AI to enable more efficient
cyber defense activities, EO 14110 establishes an advanced cybersecurity program to develop AI
2024 REPORT
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE
23