ENA BL ING MEA SURE We will provide guidance and support to help organizations understand, leverage, and reduce harms that accrue from malicious use of AI, CRQCs, and other emergent technologies. MEA SURE OF EFFEC TI V E N E SS Increase in the publication and adoption of guidance to: 1 | Help organizations safely use AI to advance cybersecurity. 2 | Protect AI systems from adversarial manipulation or abuse, building upon NIST’s AI Risk Management Framework. 3 | Protect critical infrastructure organizations from adversarial AI systems. 4 | Publish evaluation of potential cryptographic vulnerabilities in critical infrastructure, particularly focused on ICS/ OT systems. 5 | As verifiably quantum-safe products enter the market, increase in migration to quantum-safe cryptography by Systemically Important Entities and FCEB agencies. OB JEC TIVE 3. 3 Contribute to efforts to build a national cyber workforce Our nation remains challenged by intersecting gaps: a shortage of qualified candidates for many cybersecurity roles and a profound lack of diversity in the cybersecurity workforce. Addressing these gaps remains a challenge for cybersecurity teams across the country, in many ways posing a risk to national security. We will work closely with the Office of the National Cyber Director (ONCD) to implement a national cybersecurity workforce and education strategy. We will seek opportunities to bolster the national cyber and cyber-adjacent workforce — focusing both on ensuring the current cybersecurity workforce has the skills needed for a changing risk and threat environment and expanding the pipeline for the future workforce, from “K to Gray.” C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 21

Select target paragraph3