CISA's Andersen warns technical debt risks 'the worst that could happen'
The acting director says the agency is staffing back up after DOGE cuts and pushing agencies to triage vulnerabilities by actual risk rather than patching everything blindly.
TL;DR
CISA Acting Director Nick Andersen delivered a blunt warning at the Billington CyberSecurity Summit on Wednesday: decades of bad IT decisions and overwhelming technical debt have left the country exposed to serious cyberattacks, and the AI threat is shrinking the window to respond. The agency is hiring about 250 screened staff who are awaiting security clearances, part of a broader push to refill roughly 600 positions after DOGE-related cuts and attrition. Andersen also confirmed a binding operational directive on AI and vulnerability management is due this week, telling reporters the government needs to move faster than the threat.
Nick Andersen's appearance at Billington was part warning, part staffing update, and part policy rollout. The CISA acting director told the audience the federal government has been kicking its IT problems down the road for decades, and the bill is coming due.
"We've made a lot of really bad decisions over the last decades, plus you know our technical debt across the board is overwhelming," Andersen said. "We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough."
That's a striking framing from a sitting agency head, not a GAO report, not a think tank panel, but the person currently running the government's lead civilian cyber agency, saying the people in the room might one day owe their families an explanation.
The AI dimension isn't theoretical
Andersen pointed to AI as compounding the urgency. Headlines about rogue AI agents are now a daily occurrence, he noted, and the recent scaled-back White House AI executive order (which asks companies to voluntarily submit models for government testing 30 days before public release, down from the 90 days originally sought) reflects ongoing tension in the administration over how aggressively to regulate. Andersen confirmed CISA will release a binding operational directive tied to that executive order by the end of the week, focused on vulnerability management and AI-specific access for agency partners.
Vulnerability prioritization gets a rewrite
The directive dovetails with a broader shift Andersen has been telegraphing: CISA wants agencies to stop treating every patch as equally urgent. Speaking earlier this week, he said the agency is asking federal departments to evaluate vulnerabilities by whether the asset is internet-exposed, whether it maps to a known exploited vulnerability, and whether exploitation is automatable. The underlying message is that the historical "patch everything as fast as you can" model is unsustainable, and CISA is now willing to say so explicitly.
Staffing: 250 in the queue, 600 to go
On personnel, Andersen said about 250 new hires have been screened and are waiting on security clearances. DHS Secretary Markwayne Mullin pledged in late June to refill roughly 600 positions after CISA lost about a third of its workforce through DOGE cuts and attrition. The hiring push targets the agency's operational, cybersecurity, infrastructure security, and emergency communications divisions, plus regional field staff.
The optimistic read: CISA is restaffing and simultaneously rewiring how the federal government thinks about vulnerability risk. The less optimistic read is the one Andersen himself laid out, the window is short and the technical debt isn't going anywhere.
Published ·Deep Fathom