Nick Andersen, acting CISA director
Nick Andersen, acting CISA director, speaks at the Billington CyberSecurity Summit on September 9, 2026, in Washington, D.C. Image: Suzanne Smalley / Recorded Future News

CISA head says agency must change quickly to prevent the 'worst that could happen'

The acting director of the Cybersecurity and Infrastructure Security Agency issued a sober warning Wednesday about the significant and possibly devastating cybersecurity vulnerabilities Americans face, blaming past government mistakes, outdated tech and AI as threats.

“We've made a lot of really bad decisions over the last decades, plus you know our technical debt across the board is overwhelming,” Nick Andersen said in an interview at the Billington CyberSecurity Summit in Washington, D.C.

“We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”

It is important that CISA staff up, Andersen said in remarks with reporters after the interview. The agency has a pool of about 250 incoming staff who have been screened and hired and are waiting for their security clearances to come through, he said.

CISA lost about a third of its staff after DOGE-related cuts and through attrition during the first year of the Trump administration.

In late June, Department of Homeland Security Secretary Markwayne Mullin promised to refill about 600 CISA jobs.

“We want to be the [go-to source] for cybersecurity in the nation,” Mullin said at the time. “That means we’re going to hire back up. We are about half-staffed from what we need to be.”

The agency is most focused on hiring people for the agency’s operational division, cybersecurity division, infrastructure security division and emergency communications division. Regional field workers are also a priority, Andersen said.

The AI threat is a gamechanger, Andersen told reporters. Headlines about rogue AI agents appear almost daily. A researcher from AI company Anthropic told the Wall Street Journal that he is quitting the company over concerns about the safety of its advanced models.

“This is an overwhelming time, I think, for a lot of infrastructure operators, just thinking about ‘Oh my gosh! I'm about to just get crushed and overwhelmed with vulnerabilities,’” Andersen said.

Recorded Future
No previous article
No new articles
Suzanne Smalley

Suzanne Smalley

is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.