Space Security News
  • Home
  • News

    Vast recruits Slingshot co-founder to lead defense satellite push

    July 27, 2026

    Commerce department launches voluntary certification for novel space missions

    July 27, 2026
    Sentinel satellite overlooking the Strait of Hormuz shipping lanes

    EU halts Copernicus imagery release near Iran war zone

    July 27, 2026
    Military GPS satellite with encrypted signal beams in orbit

    Air Force seizes control of troubled jam-proof GPS receiver project

    July 27, 2026
  • Features

    Classified Chinese satellite sweeps the geostationary belt for threats

    July 24, 2026

    Japan’s JAXA tests reusable rocket RV-X in milestone for space infrastructure

    July 24, 2026

    Software-defined radios open new attack surface for satellite networks

    July 22, 2026

    GPS jamming wave pushes UK toward self-reliant satellite security

    July 21, 2026
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Reading: CISA’s risk-based overhaul: why satellite operators can finally stop patching everything
Share
Search
  • Trending:
  • Alliances
  • Cislunar
  • Commercial
  • Communications
  • Cyber
  • Debris
  • Defense
  • Deterrence
  • Intelligence
  • Launch
  • Strategy
  • Surveillance
  • Missile
  • Navigation
  • War
Font ResizerAa
Space Security NewsSpace Security News
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Follow US
© 2026 Space Security News. All Rights Reserved.
Emerging Threats & TechGround Segment & OperationsNews

CISA’s risk-based overhaul: why satellite operators can finally stop patching everything

By
SSN Staff
Last updated: June 9, 2026
4 Min Read
Share

The Cybersecurity and Infrastructure Security Agency is fundamentally overhauling its approach to vulnerability and risk prioritization, shifting from a blanket patch-everything mandate to a risk-informed model that distinguishes critical assets from less consequential systems.

Contents
  • From Patching Speed to Risk-Based Prioritization
  • Granular Asset Identification for Critical Infrastructure
  • Operational Capacity and Regulatory Momentum

From Patching Speed to Risk-Based Prioritization

Acting CISA Director Nick Andersen announced a binding operational directive for federal agencies, set to be published Wednesday, that revises how agencies manage vulnerabilities. “Overall, our approach to date has been ‘A patch is released, apply this patch as quickly as you can,’” Andersen said. The new directive requires agencies to evaluate each vulnerability against specific criteria: whether the affected asset is internet-exposed, aligns with CISA’s Known Exploited Vulnerabilities catalog, and whether exploitation is automatable. “We need to be able to highlight that some patches just aren’t as important as others,” Andersen explained.

This shift acknowledges that the current threat environment, accelerated by AI-enhanced exploitation capabilities, demands a more surgical focus. Andersen emphasized that the directive has been in development for months, predating recent AI executive orders, and is driven by “a recognition that we’re in a different dynamic environment with shorter timelines to weaponization.”

Granular Asset Identification for Critical Infrastructure

Andersen is applying the same risk calculus to privately owned critical infrastructure, moving beyond broad designations like “Section 9” entities from a 2013 executive order. Past approaches lacked the fidelity needed for measurable risk conversations, he said. “I need to be able to go to a company and say, ‘Here’s the specific function you’re supporting that makes you more critical. Let’s have a conversation about the specific assets that support that function.’”

The goal is to differentiate between, for example, a major bank’s bulk payment processing system and a nearby branch location. “Those things are apples and oranges, even though it’s the same entity,” Andersen said. This granularity, he argued, is essential for achieving measurable resilience.

Operational Capacity and Regulatory Momentum

CISA is simultaneously ramping up its workforce, with plans to hire 329 personnel and job offers extended to 182 by end of June. The first tranche focuses on operational roles in emergency communications, infrastructure security, and regional field offices. This hiring sprint comes amid deep proposed budget cuts and scrutiny of the agency’s capabilities under the current administration.

On the regulatory front, Andersen confirmed that town-hall meetings for the Cyber Incident Reporting for Critical Infrastructure Act of 2022 will begin next week, following delays from government shutdowns. He declined to set a final date for the rulemaking, noting that public comments could “radically change our way of thinking.” The agency’s focus remains on fulfilling congressional intent under CIRCIA.

This recalibration signals a maturation of federal cyber defense: accepting that not all systems are equal, and that protecting the nation’s most vital functions requires the discipline to triage, prioritize, and accept some risk elsewhere.

— Originally reported by CyberScoop. Adapted and republished with editorial context for SpaceSecurityNews.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print

LATEST NEWS

Vast recruits Slingshot co-founder to lead defense satellite push

News
July 27, 2026

Commerce department launches voluntary certification for novel space missions

The Office of Space Commerce rolls out a voluntary certification system for novel space activities…

July 27, 2026
Sentinel satellite overlooking the Strait of Hormuz shipping lanes

EU halts Copernicus imagery release near Iran war zone

The EU imposed a 24-hour restriction on Sentinel satellite imagery of the Gulf of Oman…

July 27, 2026
Military GPS satellite with encrypted signal beams in orbit

Air Force seizes control of troubled jam-proof GPS receiver project

The Air Force absorbed the Pentagon's M-code GPS receiver program from the Space Force after…

July 27, 2026

YOU MAY ALSO LIKE

Space Force plans nationwide network of ‘resilient operations centers’

The U.S.

NewsThreat Actors & Incidents
May 28, 2026

OrbitWhisperer AI Satellite Cybersecurity Framework Presented to NATO

A new AI-driven satellite resilience framework developed by Embry-Riddle researchers is drawing international attention after being presented to NATO. OrbitWhisperer…

Emerging Threats & TechSatellite Security
June 25, 2026

Japan’s JAXA tests reusable rocket RV-X in milestone for space infrastructure

JAXA's RV-X reusable rocket test flight strengthens Japan's independent space access and launch infrastructure security.

News
July 24, 2026

Russian satellites move within striking distance of ICEYE radar satellite supplying intelligence to Ukraine

Russian military satellites have sidled up to a commercial radar spy satellite that feeds intelligence to Ukraine, and the orbital…

Emerging Threats & TechSatellite SecuritySpotlight
May 25, 2026

Breaking developments in space and cybersecurity, decoded for the modern defense and technology landscape.

Follow us: 

  • News
  • Features
  • Spotlight
  • Events
  • About Us
  • Mission
  • Services
  • Contact Us
Copyright © 2026 Space Security News. All Rights Reserved.
Privacy Policy | Legal
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?