Securing America: Readiness, Response, and Resilience for Critical Infrastructure Defense

Black Hat USA 2025 · Day 1 · Briefings

Overview

Despite budget cuts, voluntary departures, and intense public scrutiny, CISA's operational leadership insists the agency is accelerating — not retreating. In a frank Black Hat keynote, Acting Cybersecurity Division head Chris Butera and CIO Bob Costello detailed new tools, emergency directives, and a shift toward "quality era" vulnerability management, while calling on the security community to deepen engagement with a leaner but still-active agency. ---

Watch on YouTube

Visual summary for Securing America: Readiness, Response, and Resilience for Critical Infrastructure Defense
Visual summary for Securing America: Readiness, Response, and Resilience for Critical Infrastructure Defense

Key moments

  1. 2:59 CISA emergency directive: first-ever 24-hour patch deadline issued for Citrix Bleed
  2. 4:29 First KEV entry under 24 hours: CISA now tracks exploitation speed as key metric
  3. 4:59 CISA SharePoint response: Saturday morning notification-to-remediation workflow revealed
  4. 8:00 CISA releases Thorium open-source malware forensic analysis tool at conference
  5. 8:59 Scattered Spider update: nation-state-level AI-assisted social engineering before cyberattack
  6. 13:59 Critical infrastructure gap: ICS/OT security monitoring far less mature than IT counterparts
  7. 21:59 CISA budget cuts impact: voluntary departures create capability gaps in federal cyber defense
  8. 30:00 Key recommendation: critical infrastructure operators must treat vendor access as primary attack surface

Securing America: Readiness, Response, and Resilience for Critical Infrastructure Defense

Speakers: Chris Butera, Acting Executive Director of the Cybersecurity Division, CISA; Bob Costello, Chief Information Officer, CISA; Frank Celufro (moderator), Director, McCarrory Institute of Cyber and Critical Information Security, Auburn University

Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas

YouTube: https://www.youtube.com/watch?v=XxQFNgqcJB8

Reading time: 5 min

Type: Keynote

TL;DR

Despite budget cuts, voluntary departures, and intense public scrutiny, CISA's operational leadership insists the agency is accelerating — not retreating. In a frank Black Hat keynote, Acting Cybersecurity Division head Chris Butera and CIO Bob Costello detailed new tools, emergency directives, and a shift toward "quality era" vulnerability management, while calling on the security community to deepen engagement with a leaner but still-active agency.

Introduction

Few agencies have faced more turbulent headlines in recent years than the Cybersecurity and Infrastructure Security Agency. Budget reductions, high-profile personnel departures, and a heated policy debate over its mandate have made CISA a recurring subject of uncertainty. Against that backdrop, two of the agency's most senior operational leaders took the Black Hat stage to make a pointed argument: reports of CISA's diminishment are exaggerated.

The discussion, moderated by Frank Celufro of Auburn University's McCarrory Institute, covered adversary TTPs, the KEV catalog, CVE program evolution, AI adoption, and the acute challenge of defending critical infrastructure when Internet-connected industrial control systems remain disturbingly common. Both Butera and Costello spoke with notable candor about workforce challenges and operational tempo — and made a direct appeal to the security community for continued collaboration.

"We Are Not Retreating"

▶ Watch: CISA's Current Posture and Personnel (02:00)

Bob Costello opened by invoking General Oliver Smith's famous line — "We're not retreating, we're advancing in a new direction" — to address the elephant in the room. CISA did lose personnel through voluntary separation programs, but Costello emphasized that new leadership has stepped into vacated roles and that former CISA staff in the private sector continue to collaborate with the agency. "We see people that came from CISA doing amazing things, continuing to work with us, and continuing to root for us," he said.

On the operational side, Costello and Butera described a pace of releases that, they suggested, undercut narratives of institutional paralysis. In the days immediately before the Black Hat panel, CISA had issued an emergency directive to Federal Civilian Executive Branch agencies regarding Microsoft Exchange, released ten industrial control system alerts, and achieved its first-ever KEV catalog entry in under twenty-four hours. Butera also announced the open-source release of a malware and forensic analysis tool called Thorium.

Adversary Trends: Faster, Stealthier, AI-Assisted

▶ Watch: Nation-State Threats and Changing TTPs (08:01)

Butera offered a practitioner-level view of how adversary behavior has shifted. Nation-states — China, Russia, Iran, and North Korea — remain the primary concern, but the tactics have evolved in two significant directions. First, adversaries are increasingly chaining vulnerabilities: combining low-severity findings into access paths that would individually be dismissed as non-critical. "You see a low, a low, and then all of a sudden they're in," Costello said. Second, living-off-the-land techniques have become more prevalent, using legitimate system tools to avoid detection and complicate forensic attribution.

AI-assisted social engineering has also emerged as a meaningful initial-access vector. Butera cited a joint CISA publication on Scattered Spider as an example of adversaries using AI to enhance the credibility and targeting of social engineering campaigns before moving to technical exploitation. The combination of AI-powered pretexting and chained vulnerabilities represents a materially different threat model than what defenders designed their architectures against five years ago.

CISA's response to accelerating exploitation has been to compress its own timelines. The Microsoft SharePoint vulnerability and the Citrix Bleed vulnerability both triggered twenty-four-hour patching mandates to federal agencies — the first time CISA has set that aggressive a deadline in either case.

The CVE Program's Quality Era

▶ Watch: CVE Program Evolution and KEV Catalog (26:02)

Chris Butera provided the most technically detailed section of the panel in his discussion of the CVE program's evolution. He framed its history in two phases. From 2016 to 2024, CISA focused on growth: the number of CVE Numbering Authorities expanded from 24 to over 460, and annual CVE record volume grew from 6,400 to more than 40,000. That federated, global expansion was intentional — the goal was to pull vulnerability data from as many first-party sources as possible.

The agency is now entering what Butera called "the quality era." The focus has shifted from volume to completeness: ensuring that CVE records include accurate Common Weakness Enumeration mappings, patch links, and CVSS-compatible enrichment fields. CISA adds three fields to every CVE record using its Stakeholder-Specific Vulnerability Categorization (SSVC) methodology — including an exploitability indicator that, when confirmed, triggers KEV catalog inclusion.

The KEV catalog remains a prioritization mechanism rather than a comprehensive risk list. Butera was explicit that its purpose is to help organizations triage what to patch first given real-world exploitation evidence, not to provide comprehensive coverage of every vulnerability. The long-term goal is machine-readable, automated remediation across the ecosystem.

Operational Collaboration and New Tools for State and Local Partners

▶ Watch: Grants, Advisors, and Attack Surface Management (18:01)

Costello and Butera spent considerable time on CISA's efforts to serve partners below the federal level. Over 100 Cybersecurity Advisors are deployed in the field to support state, local, tribal, and territorial governments — and CISA recently released more than $100 million in grant funding available to those entities. A new automated portal is in development that will allow state and local organizations to sign up for CISA's vulnerability scanning program, track their attack surface findings, and engage with regional advisors without relying on email chains.

On the operational technology front, Butera highlighted a significant but underappreciated authority: CISA now holds administrative subpoena power that allows it to identify owners of Internet-exposed industrial control systems through ISPs. As of the Black Hat panel, CISA had contacted over 3,000 entities with exposed ICS devices and achieved an 80 percent success rate in getting those systems removed from public Internet access.

AI for Security and Securing AI

▶ Watch: CISA's AI Adoption and Innovation (30:02)

Both Costello and Butera addressed AI from two directions: as a tool for defenders and as a system that requires its own security. On the defensive side, CISA is integrating generative AI into analyst workflows — deploying Microsoft Copilot and evaluating AI-assisted querying across the cybersecurity mission systems that Costello's office recently took over. The goal is to reduce the cognitive burden of multi-tool, multi-language analysis that currently slows threat hunters and vulnerability management teams.

CISA's Joint Cyber Defense Collaborative (JCDC) maintains a dedicated AI security working group that meets regularly with industry partners and has already published a playbook for responding to AI incidents. DARPA partnerships are underway for longer-term AI research. Costello's broader message was that CISA cannot afford to let uncertainty about AI governance become an excuse for inaction: "You're not gonna learn until you actually get in the field."

Notable Quotes

"We are not retreating. We're advancing in a new direction. And we are driving hard every day."

Bob Costello [[▶ 02:00]](https://www.youtube.com/watch?v=XxQFNgqcJB8&t=120s)

"We've had our first KEV entry in under twenty-four hours — and we've worked several really big issues."

Bob Costello [[▶ 06:01]](https://www.youtube.com/watch?v=XxQFNgqcJB8&t=361s)

"We've contacted over three thousand entities, and we've had over an eighty percent success rate in getting those devices removed from the Internet."

Chris Butera [[▶ 36:02]](https://www.youtube.com/watch?v=XxQFNgqcJB8&t=2162s)

"Trust is the coin of the realm. To build trust takes eons — to lose it can happen really fast."

Frank Celufro [[▶ 16:01]](https://www.youtube.com/watch?v=XxQFNgqcJB8&t=961s)

Key Takeaways

  • CISA's operational tempo is accelerating despite institutional headwinds. Twenty-four-hour patching mandates, the Thorium open-source release, and ten ICS alerts in a single week signal a leaner-but-faster posture rather than a diminished one.
  • Vulnerability chaining and living-off-the-land remain the most dangerous adversary TTPs — defenders still need to rethink architectures designed around individual CVE severity rather than exploitation chains.
  • The CVE program's next phase is quality, not volume. Organizations relying on CVE records for automation should engage with CISA's SSVC enrichment fields and KEV integration to improve prioritization accuracy.
  • Internet-exposed ICS is still a widespread problem. CISA's 3,000+ entity outreach and 80 percent removal success rate suggest the problem is tractable — but only with sustained engagement from critical infrastructure operators.
  • Reauthorization of CISA's information-sharing authority is a live policy risk. Both Butera and Costello urged Congress to renew the statute, warning that its lapse would undermine the trust-based information-sharing that underlies much of CISA's early-warning capability.

Slides: No slides PDF is available for this session.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

CISA leadership stands at the podium and tells you they're not retreating. The 80% ICS removal success rate is a genuine number worth noting, the Thorium release is real, and the 24-hour KEV entry is a milestone. Everything else is institutional reassurance pitched at a skeptical audience. This needed to be a press conference, not a Black Hat briefing.

Heather Calloway (CISO) — SOLID

CISA's 2025 keynote presented the agency's operational posture, pointed to Salt Typhoon as the primary current threat example, and reaffirmed the Secure by Design framing as the policy direction for critical infrastructure. No new research. Useful for understanding where the federal government's defensive posture currently sits and what it is prioritizing.

→ Top-rated talks at Black Hat USA 2025

All talks from Black Hat USA 2025