Space Security News
  • Home
  • News

    Vast recruits Slingshot co-founder to lead defense satellite push

    July 27, 2026

    Commerce department launches voluntary certification for novel space missions

    July 27, 2026
    Sentinel satellite overlooking the Strait of Hormuz shipping lanes

    EU halts Copernicus imagery release near Iran war zone

    July 27, 2026
    Military GPS satellite with encrypted signal beams in orbit

    Air Force seizes control of troubled jam-proof GPS receiver project

    July 27, 2026
  • Features

    Classified Chinese satellite sweeps the geostationary belt for threats

    July 24, 2026

    Japan’s JAXA tests reusable rocket RV-X in milestone for space infrastructure

    July 24, 2026

    Software-defined radios open new attack surface for satellite networks

    July 22, 2026

    GPS jamming wave pushes UK toward self-reliant satellite security

    July 21, 2026
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Reading: CISA’s risk-based overhaul: why satellite operators can finally stop patching everything
Share
Search
  • Trending:
  • Alliances
  • Cislunar
  • Commercial
  • Communications
  • Cyber
  • Debris
  • Defense
  • Deterrence
  • Intelligence
  • Launch
  • Strategy
  • Surveillance
  • Missile
  • Navigation
  • War
Font ResizerAa
Space Security NewsSpace Security News
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Follow US
© 2026 Space Security News. All Rights Reserved.
Emerging Threats & TechGround Segment & OperationsNews

CISA’s risk-based overhaul: why satellite operators can finally stop patching everything

By
SSN Staff
Last updated: June 9, 2026
4 Min Read
Share

The Cybersecurity and Infrastructure Security Agency is fundamentally overhauling its approach to vulnerability and risk prioritization, shifting from a blanket patch-everything mandate to a risk-informed model that distinguishes critical assets from less consequential systems.

Contents
  • From Patching Speed to Risk-Based Prioritization
  • Granular Asset Identification for Critical Infrastructure
  • Operational Capacity and Regulatory Momentum

From Patching Speed to Risk-Based Prioritization

Acting CISA Director Nick Andersen announced a binding operational directive for federal agencies, set to be published Wednesday, that revises how agencies manage vulnerabilities. “Overall, our approach to date has been ‘A patch is released, apply this patch as quickly as you can,’” Andersen said. The new directive requires agencies to evaluate each vulnerability against specific criteria: whether the affected asset is internet-exposed, aligns with CISA’s Known Exploited Vulnerabilities catalog, and whether exploitation is automatable. “We need to be able to highlight that some patches just aren’t as important as others,” Andersen explained.

This shift acknowledges that the current threat environment, accelerated by AI-enhanced exploitation capabilities, demands a more surgical focus. Andersen emphasized that the directive has been in development for months, predating recent AI executive orders, and is driven by “a recognition that we’re in a different dynamic environment with shorter timelines to weaponization.”

Granular Asset Identification for Critical Infrastructure

Andersen is applying the same risk calculus to privately owned critical infrastructure, moving beyond broad designations like “Section 9” entities from a 2013 executive order. Past approaches lacked the fidelity needed for measurable risk conversations, he said. “I need to be able to go to a company and say, ‘Here’s the specific function you’re supporting that makes you more critical. Let’s have a conversation about the specific assets that support that function.’”

The goal is to differentiate between, for example, a major bank’s bulk payment processing system and a nearby branch location. “Those things are apples and oranges, even though it’s the same entity,” Andersen said. This granularity, he argued, is essential for achieving measurable resilience.

Operational Capacity and Regulatory Momentum

CISA is simultaneously ramping up its workforce, with plans to hire 329 personnel and job offers extended to 182 by end of June. The first tranche focuses on operational roles in emergency communications, infrastructure security, and regional field offices. This hiring sprint comes amid deep proposed budget cuts and scrutiny of the agency’s capabilities under the current administration.

On the regulatory front, Andersen confirmed that town-hall meetings for the Cyber Incident Reporting for Critical Infrastructure Act of 2022 will begin next week, following delays from government shutdowns. He declined to set a final date for the rulemaking, noting that public comments could “radically change our way of thinking.” The agency’s focus remains on fulfilling congressional intent under CIRCIA.

This recalibration signals a maturation of federal cyber defense: accepting that not all systems are equal, and that protecting the nation’s most vital functions requires the discipline to triage, prioritize, and accept some risk elsewhere.

— Originally reported by CyberScoop. Adapted and republished with editorial context for SpaceSecurityNews.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print

LATEST NEWS

Vast recruits Slingshot co-founder to lead defense satellite push

News
July 27, 2026

Commerce department launches voluntary certification for novel space missions

The Office of Space Commerce rolls out a voluntary certification system for novel space activities…

July 27, 2026
Sentinel satellite overlooking the Strait of Hormuz shipping lanes

EU halts Copernicus imagery release near Iran war zone

The EU imposed a 24-hour restriction on Sentinel satellite imagery of the Gulf of Oman…

July 27, 2026
Military GPS satellite with encrypted signal beams in orbit

Air Force seizes control of troubled jam-proof GPS receiver project

The Air Force absorbed the Pentagon's M-code GPS receiver program from the Space Force after…

July 27, 2026

YOU MAY ALSO LIKE

Quantum Computing Is About to Become a National Security Problem in Orbit

Quantum computing’s projected arrival by 2029 threatens to dismantle the cryptographic foundations securing satellite communications, command links, and mission data,…

Emerging Threats & Tech
June 29, 2026

How AI is shaping the future of geospatial intelligence

The integration of artificial intelligence into geospatial intelligence (GEOINT) is fundamentally reshaping how the National Reconnaissance Office (NRO) and National…

Emerging Threats & TechFeatures
June 2, 2026

Satellite Communications Cybersecurity: Protecting Aviation Networks From Emerging Threats

The 2022 cyberattack on Viasat’s KA-SAT network, which disrupted tens of thousands of satellite modems across Europe, remains the most…

Ground Segment & Operations
July 1, 2026

Unseen Threats Overhead: Drones Endanger U.S. Rocket Launch Sites

The rising prevalence of drone incursions over U.S. military launch ranges poses a direct and escalating threat to national security,…

Emerging Threats & Tech
July 1, 2026

Breaking developments in space and cybersecurity, decoded for the modern defense and technology landscape.

Follow us: 

  • News
  • Features
  • Spotlight
  • Events
  • About Us
  • Mission
  • Services
  • Contact Us
Copyright © 2026 Space Security News. All Rights Reserved.
Privacy Policy | Legal
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?