bodtrade-pressNewsThe Broadside2 min read

CISA Threat-Hunting Lead Offers BOD 26-02 Workarounds

Segmentation and monitoring aren't decommissioning, and CISA knows it, the agency is quietly building an on-ramp for resource-strapped federal shops that can't meet the 18-month deadline.


TL;DR

CISA Deputy Associate Director for Threat Hunting Robert Thompson laid out interim mitigations for federal agencies that can't immediately decommission end-of-support edge devices under February's Binding Operational Directive 26-02. The alternatives (network segmentation, IP whitelisting, MFA, and aggressive logging) are meant to buy time for agencies short on funding and staffing. But Thompson stopped short of saying these measures satisfy the directive's 18-month decommissioning requirement, leaving agencies that stall on replacement exposed if those devices are breached.

CISA Threat-Hunting Lead Offers BOD 26-02 Workarounds
Editorial illustration · drawn by The Broadside

Robert Thompson, CISA's deputy associate director for threat hunting, acknowledged what every federal network engineer already knows: "you can't just waltz into your office on Monday morning and decide to unplug a device and replace it." His August 13 webinar remarks (offering segmentation, IP whitelisting, MFA, and heavy auditing as stopgaps for agencies that can't meet BOD 26-02's decommissioning timeline) are the closest CISA has come to admitting the directive's 18-month clock is aspirational for resource-strapped shops.

That's not a criticism. It's practical. The February directive requires FCEB agencies to inventory all end-of-support edge devices by May 5, decommission agency-listed devices within one year, and clear all EOS edge devices within 18 months. Thompson called implementation "oftentimes not for the faint of heart" and "a long arduous journey." He's right. Budget cycles don't align, procurement lags, and edge devices touching production networks can't be yanked on a Thursday afternoon.

The gap CISA won't close

What Thompson didn't do was declare segmentation and monitoring sufficient for compliance. He offered them as what agencies should do "if there is an instance when resources are an issue, and an organization is unable to decommission those end-of-support devices." That's a conditional, not a ruling. Agencies opting for workarounds without a decommissioning schedule are operating against the plain text of the directive, which says EOS devices "should never remain on enterprise networks," as Acting Director Madhu Gottumukkala put it in February.

The liability lands exactly where you'd expect. If a segmented, monitored EOS firewall gets popped and the adversary pivots, the agency won't be able to point to Thompson's webinar slides as a defense. CISA's posture is clear: the mitigations reduce risk, they don't eliminate it, and the clock is still ticking.

What this signals

The subtext matters. When a threat-hunting lead spends a public webinar walking agencies through workarounds, it means CISA has heard from enough FCEB shops facing genuine resource constraints that a flat "decommission or else" message would undermine the directive's credibility. The agency is choosing pragmatism over purity, but it's leaving the compliance question deliberately fuzzy.

Thompson also urged private-sector and state and local organizations to adopt the BOD's inventory-and-decommission framework voluntarily, calling it "a very sound, practical approach to asset management." He encouraged organizations not to "wait for regulation to take action." For state CISOs and municipal IT directors watching the federal implementation, the signal is that CISA views BOD 26-02 as a template for broader critical-infrastructure expectations, even if it lacks the authority to mandate them.


Published ·Deep Fathom