Pillar Two: Disrupt and Dismantle Threat Actors
2.1
2.2
2.3
2.4
2.5
Integrate Federal Disruption Activities
2.1.1 Publish an updated DOD Cyber Strategy
2.1.2 Strengthen the National Cyber Investigative Joint Task Force (NCIJTF) capacity
2.1.3 Expand organizational platforms dedicated to disruption campaigns
2.1.4 Propose legislation to disrupt and deter cybercrime and cyber-enabled crime
2.1.5 Increase speed and scale of disruption operations
Enhance Public-Private Operational Collaboration to Disrupt Adversaries
2.2.1 Identify mechanisms for increased adversarial disruption through public-private
operational collaboration
Increase the Speed and Scale of Intelligence Sharing and Victim Notification
2.3.1 Identify and operationalize sector-specific intelligence needs and priorities
2.3.2 Remove barriers to delivering cyber threat intelligence and data to critical
infrastructure owners and operators
Prevent Abuse of U.S.-Based Infrastructure
2.4.1 Publish a Notice of Proposed Rulemaking on requirements, standards, and
procedures for Infrastructure-as-a-Service (IaaS) providers and resellers
Counter Cybercrime, Defeat Ransomware
2.5.1 Disincentivize safe havens for ransomware criminals
2.5.2 Disrupt ransomware crimes
2.5.3 Investigate ransomware crimes and disrupt the ransomware ecosystem
2.5.4 Support private sector and state, local, Tribal, and territorial (SLTT) efforts to
mitigate ransomware risk
2.5.5 Support other countries' efforts to adopt and implement the global anti-money
laundering/countering the financing of terrorism (AML/CFT) standards for virtual
asset service providers
NATIONAL CYBERSECURITY STRATEGY
IMPLEMENTATION PLAN
7