MESSAGE FROM THE DIRECTOR I am proud to share the 2023 – 2025 CISA Strategic Plan, the first comprehensive Strategic Plan since CISA was established as an Agency in 2018. The Strategic Plan represents a forward-leaning, unified approach to achieving our vision of ensuring secure and resilient critical infrastructure for the American people. At CISA, we lead the national effort to understand, manage, and reduce risk to the cyber and physical infrastructure that Americans rely on every hour of every day. The risks we face are complex, geographically dispersed, and affect a diverse array of our stakeholders, including federal civilian government agencies, private sector companies, state, local, tribal, and territorial (SLTT) governments, and ultimately the American people. It is our duty to work with our stakeholders to mitigate these risks to preserve our national security, economic stability, and the health and safety of all our citizens. Our Strategic Plan lays out four ambitious goals that we must achieve to address the diverse and dynamic challenges facing our nation. First, we will spearhead a national effort to ensure the defense and resilience of cyberspace. In our role as America’s cyber defense agency, we must build the national capacity to defend against, and recover from, cyberattacks. We must work with federal partners to bolster their cybersecurity and incident response postures and safeguard the federal civilian executive branch networks that support our nation’s essential operations. And we must partner with the private sector and SLTT governments to detect and mitigate cyber threats and vulnerabilities before they become incidents. C I S A ST R AT EG I C PL A N 1

Select target paragraph3