New CISA directive would reshape how agencies prioritize cyber risk, official says

https://cdn.nextgov.com/media/img/cd/2026/06/09/060926andersenNG/open-graph.jpg

Roberto Schmidt/Getty Images

ByDavid DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW

June 9, 2026 12:51 PM ET

The forthcoming mandate aims to triage vulnerabilities by real-world consequences of a successful cyberattack, marking a major shift in how the government decides which cyber risks demand attention first.

The Cybersecurity and Infrastructure Security Agency plans to release a binding directive on Wednesday that tasks the federal government with rethinking how it manages risks to its networks and prioritizing cyber vulnerabilities that demand the most urgency, agency acting director Nick Andersen said.

The goal is to push agencies to focus less on the sheer number of known cyber vulnerabilities and more on the risks those flaws pose if they’re exploited by hackers, said Andersen, who added that the cyber community needs to “be okay with saying there are some systems that are less important than others.”

“If we try to...

Copyright of this story solely belongs to nextgov.com. To see the full text click HERE

Read more