April 8, 2024 By Jennifer Gregory 3 min read

The White House recently released its budget for the 2025 fiscal year, which supports the government’s commitment to cybersecurity. The cybersecurity funding allocations line up with the FY 2025 cybersecurity spending priorities released last year that included the following pillars:

  • Defend critical infrastructure
  • Disrupt and dismantle threat actors
  • Shape market forces to drive security and resilience
  • Invest in a resilient future
  • Forge international partnerships to pursue shared goals.

In 2023, the White House released a 35-page document detailing the new National Cybersecurity Strategy, with an updated strategy expected this summer. The measures in the strategy focused on encouraging secure development practices, which transfer the liability for software products and services to corporations. Many of the investments included in the new budget provide the funding needed for the new cybersecurity strategy and implementation of Executive Order 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.”

Four key areas of investment

The budget provides more than $13 billion in funding for civilian agencies to reduce cybersecurity risk through improving resiliency and defendability. Because of the 95% increase in large data breaches reported to the U.S. Health and Human Services (HHS), the budget includes an emphasis on healthcare.

Here are four key areas of investment outlined in the new budget:

1. Sustain FBI cyber and counterintelligence investigative capabilities

These funds help the FBI’s cyber intelligence, counterintelligence, cyber response and analysis capabilities. Additionally, the budget provides money for the Department of Justices to create a new section for cyber threats in the National Security Division and focus on using AI in a safe, secure and trustworthy manner per Order 14110.

2. Protect against foreign adversaries and safeguard the federal system

The bulk of these funds ensure that each federal agency increases the security of public services by funding civilian departments and agencies. Additionally, the budget funds the Cybersecurity and Infrastructure Security Agency (CISA), which includes Federal network tools, internal cybersecurity and analytical capabilities, critical infrastructure security coordination and critical infrastructure cyber event reporting.

3. Extend the frontiers of AI for science and technology and increase AI’s safety, security and resilience

By funding the Department of Energy’s computing capabilities, developing AI testbeds and evaluating AI outputs, the DOE can build AI models for energy security, national security and climate resilience. The budget provides training for new AI researchers from diverse backgrounds.

4. Protect the US healthcare system from cyber threats

As part of the goal of protecting the healthcare system, the budget makes it possible for the Administration for Strategic Preparedness and Response to coordinate the HHS’s cybersecurity efforts as well as funding for the HHS to focus on improving the cybersecurity of their systems and modernizing the Health Insurance Portability and Accountability Act of 1996. The proposed budget also directly helps healthcare systems, including funding essential cybersecurity efforts at high-need, low-resourced hospitals and an incentive for all hospitals to invest in advanced cybersecurity efforts.

Learn more about AI cybersecurity

The 2025 FY budget is an increase over the 2024 FY for civilian agencies

The proposed budget shows a commitment to cybersecurity by the current administration and a peek into Biden’s election priorities, with an upward trend in cybersecurity funding. However, experts do not expect the current budget to be passed as is. In FY 2024, Biden requested $12.7 billion, but the budget is still under negotiation. However, the funding for civilian agencies is a specific area of increase with $11.3 billion spent in FY 2023, $11.8 billion granted in FY 2024 and $13 billion proposed in FY 2025.

“This budget invests in our homeland security today and lays the groundwork to protect the American people well into the future. It supports efforts to advance the responsible use of Artificial Intelligence across DHS, as well as our work to protect against malicious cyber threats to federal networks and critical infrastructure,” DHS Secretary Alejandro Mayorkas said in a statement.

More from News

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

CISA and FBI release secure by design alert on cross-site scripting 

3 min read - CISA and the FBI are increasingly focusing on proactive cybersecurity and cyber resilience measures. Conjointly, the agencies recently released a new Secure by Design alert aimed at eliminating cross-site Scripting (XSS) vulnerabilities, which have long been exploited to compromise both data and user trust. Cross-site scripting vulnerabilities occur when a web application improperly handles user input, allowing attackers to inject malicious scripts into web pages that are then executed by unsuspecting users. These vulnerabilities are dangerous because they don't attack…

Has BlackCat returned as Cicada3301? Maybe.

4 min read - In 2022, BlackCat ransomware (also known as ALPHV) was among the top malware types tracked by IBM X-Force. The following year, the threat actor group added new tools and tactics to enhance BlackCat's impact. The effort paid off — literally. In March 2024, BlackCat successfully compromised Change Healthcare and received a ransom payment of $22 million in Bitcoin. But here's where things get weird: Immediately after taking payment, BlackCat closed its doors, citing "the feds" as the reason for the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today