
Meet the Authors
CISA warns AI could increase vulnerability pressure as critical infrastructure operators already contend with years of accumulated technical debt.
Vulnerability prioritization is becoming more important as defenders determine which weaknesses pose the greatest operational and business consequences.
SAP cybersecurity teams face similar prioritization pressures, with SAPinsider research identifying patch backlogs, limited resources, and gaps between SAP and broader Security Operations.
Nick Andersen, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), warned that years of poor technology decisions have left the US carrying “overwhelming” technical debt as cyber risks to critical infrastructure continue to grow.
Speaking at the Billington CyberSecurity Summit in Washington, D.C., Andersen said the potential consequences are already understood. “We know the worst that can happen,” he said, warning that government and industry need to make significant changes quickly. His remarks echoed an August 27 warning from SAP and more than 150 other organizations that AI could shrink the time defenders have to respond.
Andersen called AI a “gamechanger” and said infrastructure operators fear being “crushed and overwhelmed with vulnerabilities.” CISA is looking for ways to help operators manage that volume, prioritize the vulnerabilities that matter most, and put them in enough context to determine where limited defensive resources should go.
The warning comes as CISA rebuilds parts of its workforce and expands efforts to help government agencies and critical infrastructure operators respond to a threat environment Andersen says is becoming harder to manage.
CISA Says Defenders Cannot Treat Every Vulnerability Equally
Andersen said CISA is prioritizing public health and safety, the economy, national security, and critical infrastructure because the government cannot protect every system equally. Resilience will require government and industry to direct limited resources toward risks with the greatest potential consequences.
That task is becoming harder as infrastructure operators confront what Andersen described as an overwhelming vulnerability problem. “This is an overwhelming time for a lot of infrastructure operators,” he said, describing fears that they are “about to just get crushed and overwhelmed with vulnerabilities.”
CISA wants to help operators decide which weaknesses deserve attention first. “We want to be able to provide them with tools to appropriately manage that, to appropriately prioritize, and to contextualize for them where is it that we think they need to be spending their time,” Andersen said.
The consequences extend beyond individual networks. “It’s the impacts to Americans in the way that we live,” Andersen said. “That’s what’s most critically at risk here.” He expects adversaries to continue targeting civilian-operated critical infrastructure and warned that those attacks are “only going to get worse” and become more significant, including through their psychological impact on Americans.
CISA Rebuilds While the Threat Environment Accelerates
CISA is preparing to bring in roughly 250 employees as it rebuilds core teams following significant workforce reductions. The prospective employees are moving through the final hiring and clearance process, while Homeland Security Secretary Markwayne Mullin has previously said the agency intends to hire about 600 people.
Andersen said reaching a particular headcount matters less in the near term than filling “critical gaps.” CISA is prioritizing vacancies across cybersecurity, infrastructure security, and emergency communications, along with regional personnel and mission-support offices.
The hiring push comes as CISA works to finalize the Cyber Incident Reporting for Critical Infrastructure Act rule, which will require covered infrastructure operators to report cyberattacks and ransomware payments, and establish ANCHOR-CI, a new framework for coordinating with critical infrastructure operators. Andersen said the framework is intended to make collaboration more flexible around risks that do not fit neatly within traditional industry sectors.
Those efforts form part of the broader changes Andersen said are needed as accumulated technical debt collides with a threat environment that is becoming harder for government and infrastructure operators to manage.
What This Means for SAPinsiders
- Technical debt is becoming a security constraint. Andersen’s warning reframes technical debt as more than a modernization problem. Older systems, accumulated dependencies, and long-standing architecture decisions can increase exposure while also making remediation slower and more disruptive when defenders have less time to respond.
- Decision speed matters as much as patch speed. An overwhelming vulnerability queue makes rapid triage more important than simply applying fixes faster. Security teams need enough architectural and business context to distinguish exploitable, consequential weaknesses from lower-risk findings before scarce remediation capacity is consumed.
- Connect SAP security to enterprise operations. CISA’s emphasis on contextualizing risk mirrors SAPinsider research showing gaps between SAP teams and broader Security Operations. SAP vulnerability and access data becomes more useful when integrated with enterprise monitoring, incident response, and risk-prioritization processes.




