CISA Warns AI Could Overwhelm Defenders Already Buried in Technical Debt

Key Takeaways

CISA warns AI could increase vulnerability pressure as critical infrastructure operators contend with years of accumulated technical debt.

Vulnerability prioritization is becoming more important as defenders decide which weaknesses pose the greatest operational and business consequences.

ERP security teams need stronger enterprise context as vulnerability and access data increasingly feed broader monitoring, incident response, and risk-prioritization processes.

Nick Andersen, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), warned that years of poor technology decisions have left the US carrying “overwhelming” technical debt as cyber risks to critical infrastructure continue to grow.

Speaking at the Billington CyberSecurity Summit in Washington, D.C., Andersen said the potential consequences are already understood. “We know the worst that can happen,” he said, warning that government and industry need to make significant changes quickly. His remarks echoed an August 27 warning from more than 150 organizations that AI could shrink the time defenders have to respond.

Andersen called AI a “gamechanger” and said infrastructure operators fear being “crushed and overwhelmed with vulnerabilities.” CISA is looking for ways to help operators manage that volume, prioritize the vulnerabilities that matter most, and put them in enough context to determine where limited defensive resources should go.

The warning comes as CISA rebuilds parts of its workforce and expands efforts to help government agencies and critical infrastructure operators respond to a threat environment Andersen says is becoming harder to manage.

CISA Says Defenders Cannot Treat Every Vulnerability Equally

Andersen said CISA is prioritizing public health and safety, the economy, national security, and critical infrastructure because the government cannot protect every system equally. Resilience will require government and industry to direct limited resources toward risks with the greatest potential consequences.

That task is becoming harder as infrastructure operators confront what Andersen described as an overwhelming vulnerability problem. “This is an overwhelming time for a lot of infrastructure operators,” he said, describing fears that they are “about to just get crushed and overwhelmed with vulnerabilities.”

CISA wants to help operators decide which weaknesses deserve attention first. “We want to be able to provide them with tools to appropriately manage that, to appropriately prioritize, and to contextualize for them where is it that we think they need to be spending their time,” Andersen said.

The consequences extend beyond individual networks. “It’s the impacts to Americans in the way that we live,” Andersen said. “That’s what’s most critically at risk here.” He expects adversaries to continue targeting civilian-operated critical infrastructure and warned that those attacks are “only going to get worse” and become more significant, including through their psychological impact on Americans.

CISA Rebuilds While the Threat Environment Accelerates

CISA is preparing to bring in roughly 250 employees as it rebuilds core teams following significant workforce reductions. The prospective employees are moving through the final hiring and clearance process, while Homeland Security Secretary Markwayne Mullin has previously said the agency intends to hire about 600 people.

Andersen said reaching a particular headcount matters less in the near term than filling “critical gaps.” CISA is prioritizing vacancies across cybersecurity, infrastructure security, and emergency communications, along with regional personnel and mission-support offices.

The hiring push comes as CISA works to finalize the Cyber Incident Reporting for Critical Infrastructure Act rule, which will require covered infrastructure operators to report cyberattacks and ransomware payments, and establish ANCHOR-CI, a new framework for coordinating with critical infrastructure operators. Andersen said the framework is intended to make collaboration more flexible around risks that do not fit neatly within traditional industry sectors.

Those efforts form part of the broader changes Andersen said are needed as accumulated technical debt collides with a threat environment that is becoming harder for government and infrastructure operators to manage.

What This Means for ERP Insiders

Technical debt is becoming a security constraint. Andersen’s warning reframes technical debt as more than a modernization problem. Older systems, accumulated dependencies, and long-standing architecture decisions can increase exposure while also making remediation slower and more disruptive when defenders have less time to respond.

Decision speed matters as much as patch speed. An overwhelming vulnerability queue makes rapid triage more important than simply applying fixes faster. Security teams need enough architectural and business context to distinguish exploitable, consequential weaknesses from lower-risk findings before scarce remediation capacity is consumed.

Connect ERP security to enterprise operations. CISA’s emphasis on contextualizing risk reinforces the need to connect application security with broader Security Operations. Vulnerability and access data becomes more useful when it feeds enterprise monitoring, incident response, and risk-prioritization processes.

A version of this article was first published by SAPinsider.