FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

CISA creates cybersecurity prioritization, patch protocol

AI accelerates cyberattack speed, forcing federal agencies to better prioritize vulnerability remediation

Yael KatzwerbyYael Katzwer
June 29, 2026
in Risk & Security
Reading Time: 3 mins read
0
Share on Facebook

The U.S. Cybersecurity and Infrastructure Security Agency is requiring federal government agencies to patch cyber vulnerabilities more quickly and by priority.

“Defenders cannot afford to take weeks to patch systems that can be autonomously exploited in mass,” CISA Acting Executive Assistant Director for Cybersecurity Chris Butera said in a June 10 news conference. “Ultimately, this new framework of patching smarter, not harder, ensures that federal civilian agencies address the most critical of vulnerabilities and fast.”

The operational directive, issued June 10, applies to federal civilian executive branch agencies, which include:

  • The Department of the Treasury, which did not respond to multiple requests for comment;
  • The FDIC, which declined to comment;
  • The Federal Reserve Board, which told FinAi News that it would follow the directive and implement any necessary changes; and
  • The Office of the Comptroller of the Currency, which did not respond to multiple requests for comment.

Agencies were required to set up a patch prioritization protocol by mid-June.

“AI has transformed cybersecurity for both defenders and attackers,” Anton Dahbura, co-director of the Johns Hopkins Institute for Assured Autonomy and executive director of the Johns Hopkins University Information Security Institute, told FinAi News. “It enables faster detection of threats, automated incident response and identification of anomalies across massive datasets. At the same time, attackers use AI to generate sophisticated phishing campaigns, create convincing deepfakes and automate malware development.”

“The result is an accelerating arms race in which AI increasingly determines both the speed and sophistication of cyber offense and defense.” — Anton Dahbura, co-director, Johns Hopkins Institute for Assured Autonomy, and executive director, Johns Hopkins University Information Security Institute.

Determining patch timelines

CISA established the Known Exploited Vulnerabilities (KEV) list in 2021 to help federal agencies determine which patches should be expedited and which could wait. The new directive further categorizes KEVs and non-KEVs to help agencies prioritize timely patches. CISA determined the urgency of vulnerability remediation based on whether:

  • The vulnerable hardware or software is publicly exposed;
  • A bad actor can automate all the steps necessary to exploit the vulnerability; and
  • A bad actor, if successful in the attack, can gain partial or total control of the vulnerable hardware or software.

Affected agencies must establish a process immediately and set internal tracking and reporting requirements.

Agencies must also remove Cyber Hygiene source IP addresses from blocklists. CISA’s free Cyber Hygiene service scans agencies’ systems for vulnerabilities — but only if agencies haven’t accidentally blocked its source IPs. All government agencies use Cyber Hygiene.

Prioritizing vulnerabilities

In one unnamed federal agency analyzed by CISA, just 1% of vulnerabilities needed patching within three days — while more than 60% could wait for the next scheduled update, Butera said.

With better patch prioritization, agencies can focus their efforts where it is most needed.

“If vulnerabilities can be weaponized in a day or a week, even waiting 30 days to do a critical patch — which has been typically what regulation has mandated — that’s far too long, and so we have to rethink that,” Troy Leach, chief strategy officer at the nonprofit Cloud Security Alliance, told FinAi News.

Register here for the FinAi Lending Summit, set for Oct. 7-8 in Las Vegas.

Tags: artificial intelligence (AI)Cloud Security Alliance (CSA)cybersecurityFDICFederal ReserveNewsPremiumU.S. Cybersecurity and Infrastructure Security Agency (CISA)U.S. Department of the TreasuryU.S. Office of the Comptroller of the Currency
Previous Post

Blend’s AI Autopilot tool can double conversion for mortgages

Related Posts

Courtesy/Canva
Risk & Security

Bridging the skills gap: Ensuring cybersecurity amid AI proliferation

June 25, 2026
The rise of synthetic fraud in BNPL
Risk & Security

AI helps fraudsters perpetrate ‘zombie business’ schemes

June 23, 2026
agentic
Risk & Security

Ex-Google Cloud AI head building investigative agents for FIs

June 22, 2026

Stay Informed with Our Newsletters

* indicates required

By clicking submit below, you consent to allow FinAi News (Royal Media Group) to store and process the personal information submitted above to provide you the content requested.

For more information, please visit www.royalmedia.com/legal.

We use Mailchimp as our marketing platform. By clicking below to subscribe, you acknowledge that your information will be transferred to Mailchimp for processing. Learn more about Mailchimp’s privacy practices.

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

Hiding in Plain Sight: How to Use Data to Spot Consumer Accounts Being Used by Small Businesses

November 10, 2025

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account