CISA’s Operational Output Under Budget Pressure
CISA’s headcount shrank after voluntary separation packages in 2025, but the output didn’t stop. The day of this panel, CISA issued an emergency directive to federal civilian agencies on a Microsoft Exchange vulnerability disclosed at Black Hat the day before, and published 10 industrial control system alerts the same morning. Weeks earlier, Citrix Bleed and a Microsoft SharePoint vulnerability each drew a 24-hour patch deadline, the fastest CISA had ever set. Bob Costello’s office also released a malware analysis tool called Thorium as open source and had 11,000 organizations already enrolled in CISA’s external attack-surface scanning program.
How Adversaries Exploit Faster Than Defenders Patch
Scattered Spider, a group CISA had tracked for years, illustrated the new playbook: AI-assisted social engineering for initial access, then standard cyber techniques to elevate privileges and move laterally. CISA published a joint advisory on the group in the two weeks before the panel. Chris Butera also flagged adversaries chaining low-severity vulnerabilities together to get in, then using living-off-the-land techniques that blend into normal traffic.
“assume breach every day” — Bob Costello
Bob Costello said teams still operating on 30-day patch cycles were already behind. The culture shift meant treating breach as expected, then optimizing for detection speed and containment rather than prevention alone.
CVE, KEV, and the Mechanics of Vulnerability Prioritization
The CVE program grew from 24 CNAs and 6,400 records in 2016 to 460-plus CNAs and 40,000-plus records in 2024. Chris Butera called the next phase the quality era: pushing CNAs to attach patch links and CWE mappings so automation can trigger without human review. The KEV catalog sits on top. When CISA confirms active exploitation, it adds the CVE in machine-readable format; vendors ingest that tag so customers know which patches to ship first. CISA also shipped an open-source eviction strategies tool (21:18) that maps TTPs to MITRE ATT&CK and generates a recovery plan for the active intrusion.
AI as a Force Multiplier for Defenders
Defenders must review enormous volumes of data to find the adversary, while attackers only need one entry point. Chris Butera said AI can shift that asymmetry. CISA is testing AI-augmented querying across cyber mission systems so analysts can interrogate 25 different tools without learning 18 different query languages. Bob Costello’s team has Microsoft Copilot in production for business automation and is evaluating AI functions inside existing security vendor tools. The JCDC’s AI security group published a playbook for responding to AI incidents last year and meets regularly with industry partners to set joint standards.
Internet-Exposed ICS and the Administrative Subpoena Tool
Operational technology and industrial control systems are a lasting CISA priority. Control systems directly connected to the internet still show up frequently in scans, and China’s focus on prepositioning inside critical infrastructure networks was described as very concerning. Congress granted CISA an administrative subpoena authority to identify who owns internet-exposed control systems. CISA can now work through ISPs to find the owner, then contact them to remove the device. Out of 3,000-plus entities contacted, more than 80% removed their systems from the internet.
Notable Quotes
Absolutely. Fail fast. Bob Costello · ▶ 34:48
assume breach every day Bob Costello · ▶ 10:35
In 2024, we now have 460 plus CNAs. So, Chris Butera · ▶ 26:42
Key Takeaways
- CISA issued its first sub-24-hour KEV patch deadline and released 10 ICS alerts in a single day at Black Hat 2025.
- The CVE program grew from 6,400 records and 24 CNAs in 2016 to 40,000+ records and 460+ CNAs in 2024.
- CISA used a new administrative subpoena authority to contact 3,000+ entities and achieved an 80% success rate removing internet-exposed control systems.