ENA BL ING MEA SURE 1 | We will measure the breadth of our visibility into vulnerabilities, particularly those known to be exploited by adversaries, across critical infrastructure and government networks, whether through our own capabilities or that of our partners. 2 | We will increase trust and collaboration with the research community and the private sector by expanding participation in Coordinated Vulnerability Disclosure efforts. MEA SURE OF EFFEC TI V E N E SS 1 | Reduction in the time-to-remediate Known Exploited Vulnerabilities across critical infrastructure and government networks. 2 | Increase in percentage of recommendations from CISA’s vulnerability and risk assessments adopted by assessed organizations. 3 | Reduction in the number of vulnerabilities disclosed without appropriate coordination or provision of necessary mitigations. OB JEC TIVE 1 . 3 Plan for, exercise, and execute joint cyber defense operations and coordinate the response to significant cybersecurity incidents No single organization can effectively manage, understand, and address the breadth of cyber incidents and threats facing our country. Through our Joint Cyber Defense Collaborative and our expanding regional teams, we will serve as an integrator and force multiplier, bringing together government, private sector, and international partners to measurably reduce cyber risk. We will invest in persistent collaboration defined by reciprocal expectations of transparency and value and minimizing friction to enable scale and data-driven analysis. We will develop, exercise, and execute cyber defense plans that enable effective responses to urgent threats while retaining focus on longer-term risks that require sustained investment. To C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 11

Select target paragraph3