The Cybersecurity and Infrastructure Security Agency is fundamentally overhauling its approach to vulnerability and risk prioritization, shifting from a blanket patch-everything mandate to a risk-informed model that distinguishes critical assets from less consequential systems.
From Patching Speed to Risk-Based Prioritization
Acting CISA Director Nick Andersen announced a binding operational directive for federal agencies, set to be published Wednesday, that revises how agencies manage vulnerabilities. “Overall, our approach to date has been ‘A patch is released, apply this patch as quickly as you can,’” Andersen said. The new directive requires agencies to evaluate each vulnerability against specific criteria: whether the affected asset is internet-exposed, aligns with CISA’s Known Exploited Vulnerabilities catalog, and whether exploitation is automatable. “We need to be able to highlight that some patches just aren’t as important as others,” Andersen explained.
This shift acknowledges that the current threat environment, accelerated by AI-enhanced exploitation capabilities, demands a more surgical focus. Andersen emphasized that the directive has been in development for months, predating recent AI executive orders, and is driven by “a recognition that we’re in a different dynamic environment with shorter timelines to weaponization.”
Granular Asset Identification for Critical Infrastructure
Andersen is applying the same risk calculus to privately owned critical infrastructure, moving beyond broad designations like “Section 9” entities from a 2013 executive order. Past approaches lacked the fidelity needed for measurable risk conversations, he said. “I need to be able to go to a company and say, ‘Here’s the specific function you’re supporting that makes you more critical. Let’s have a conversation about the specific assets that support that function.’”
The goal is to differentiate between, for example, a major bank’s bulk payment processing system and a nearby branch location. “Those things are apples and oranges, even though it’s the same entity,” Andersen said. This granularity, he argued, is essential for achieving measurable resilience.
Operational Capacity and Regulatory Momentum
CISA is simultaneously ramping up its workforce, with plans to hire 329 personnel and job offers extended to 182 by end of June. The first tranche focuses on operational roles in emergency communications, infrastructure security, and regional field offices. This hiring sprint comes amid deep proposed budget cuts and scrutiny of the agency’s capabilities under the current administration.
On the regulatory front, Andersen confirmed that town-hall meetings for the Cyber Incident Reporting for Critical Infrastructure Act of 2022 will begin next week, following delays from government shutdowns. He declined to set a final date for the rulemaking, noting that public comments could “radically change our way of thinking.” The agency’s focus remains on fulfilling congressional intent under CIRCIA.
This recalibration signals a maturation of federal cyber defense: accepting that not all systems are equal, and that protecting the nation’s most vital functions requires the discipline to triage, prioritize, and accept some risk elsewhere.
— Originally reported by CyberScoop. Adapted and republished with editorial context for SpaceSecurityNews.