WASHINGTON — As the federal government scrambles to protect its own networks and support critical infrastructure operators, CISA is preparing to bring in roughly 250 new employees to rebuild core teams.
“We’re looking forward to welcoming hundreds of new CISA employees in the very near future,” acting CISA Director Nick Andersen told reporters after a talk at the Billington Cybersecurity Summit here on Wednesday.
The employees have received tentative job offers and are “waiting to get that official start date,” Andersen said during his speech.
The Trump administration has significantly downsized CISA over the past two years, leading to fractured partnerships and widespread concern about the stability and capability of the government’s lead cybersecurity agency. But in June, Secretary of Homeland Security Markwayne Mullin told lawmakers that he wanted to regrow CISA’s workforce by hiring approximately 600 people.
CISA isn’t sure when it will reach that number, but Andersen told reporters that filling “critical gaps” mattered more to him in the short term than hitting the overall goal. “With the emerging threat space that we continue to see,” he said, “do I have the right people in the right roles right now to be able to meet that challenge?”
The agency’s top priority was to fill vacancies in its three operational divisions focused on cybersecurity, infrastructure security and emergency communications, according to Andersen. Other priorities include CISA’s field force of regional advisers and its overworked mission-support offices that handle critical tasks such as security clearances.
CISA’s sweeping mission
CISA has been stretched thin over the past few years as its dwindling workforce has confronted a range of responsibilities. In addition to responding to threats such as the Iran-linked hacking campaign against U.S. water utilities, the agency has been pushing critical infrastructure operators to harden their systems and prepare for disruptions as the U.S. eyes a potential future conflict with China over Taiwan.
AI is high on CISA’s priority list as well. With companies bracing for AI to expose an endless stream of vulnerabilities in their networks, CISA is looking for ways to help them fight back.
“This is an overwhelming time for a lot of infrastructure operators, just thinking about, ‘Oh my gosh, I’m about to just get crushed and overwhelmed with vulnerabilities,’” Andersen said. “We want to be able to provide them with tools to appropriately manage that, to appropriately prioritize, and to contextualize for them where is it that we think they need to be spending their time.”
CISA is also finalizing a rule — required by the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) — that will require infrastructure operators to report cyberattacks and ransomware payments to the government. The final rule is expected to be a pared-back version of the sweeping draft that the agency published during the Biden administration. CISA has said that it plans to publish the final rule this month, but Andersen declined to provide an update when asked on Wednesday.
CIRCIA “continues to be a work in progress,” he said, “but we're looking forward to being able to share more information on that very soon.”
Reenvisioning industry partnerships
Many infrastructure operators are waiting to see what kinds of opportunities they will have to collaborate with CISA under the agency’s new framework, the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI). CISA is still reviewing industry groups’ applications to certify their existing coordinating bodies under the new system. But Andersen said one of the goals was to expand partnerships beyond the old model that oriented everything around specific sectors.
“The sector-based way of organizing” is “really good for getting like-minded people in a room and discussing issues that are common to them all,” he told reporters, but it may not be “the best model to use” for addressing risks that span sectors.
Andersen cited the example of the IT Sector Coordinating Council. “That, in many ways, became the ‘everything council,’” he said, as government officials encouraged everyone from operational technology vendors to undersea cable and data center operators to join it. “That’s a very broad group to try to operate within,” Andersen said.
CISA’s goal with ANCHOR-CI, he said, is to give smaller groups of infrastructure operators “a place to come together and work collaboratively” under different structures. He cited regional cooperation as one example, noting that CISA’s regional directors will have the authority to form local groups.
“Our folks that are working in Boston are probably going to have some different security-related concerns and a different stakeholder group than our regional office in Kansas City,” Andersen said. “We need to be able to recognize that and give them the tools to be able to convene those conversations at a local level, not just here in D.C. at the national level.”
Grim warning about time running out
Andersen used his talk to deliver a dire warning about the looming consequences of the technology industry’s poor security planning.
“We are all part of a community that knows better,” he said. “We know the worst that can happen. And if we don’t make some very serious, very significant changes in quick succession, we are going to have to have a lot of awkward conversations really, really soon. You are going to have to go home and look your family, look your friends in the eyes and explain to them how you knew the worst that could happen and why you didn’t do enough.”
Leaders in government and industry have “made a lot of really bad decisions over the last decade-plus,” Andersen added. “Our technical debt across the board is overwhelming.”