Security1 publisher2 min readPublished
FBI's cyber division tells operators quarterly patching is finished
Jason Bilnoski says AI is taking attackers to the next level and Colleen Ferranti wants continuous risk-based remediation, yet the bureau's own list of what would stop them is the same ten controls it named before.
The Watch · Security desk

What happened
- Jason Bilnoski, deputy assistant director of the FBI's cyber division, said Tuesday that AI is taking attackers to the next level, both at the Billington CyberSecurity Summit and in remarks to CyberScoop.
- Colleen Ferranti, assistant section chief for cyber engagement and intelligence, told the same event that quarterly patching is no longer viable and that remediation has to be risk-based and continuous.
- The cyber strategy released Wednesday commits FBI Cyber to rapidly adopting agentic AI to scale defense and disruption, citing President Trump's Cyber Strategy for America.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision The pairing points money at cadence and coverage rather than a new detection tier, because the control list the bureau names for the next 18 months is the one it already published.
- cost Patching all of the time is paid in downtime and regression testing by the teams that hold uptime commitments, a cost that lands on operators rather than a line item a vendor can fill.
- constraint The guidance names no CVE, no actor and no exploitation data, so it can set how often an organization patches but cannot rank what goes first in the queue.
- contradiction The bureau tells operators that basics would stop the coming wave while committing itself to rapid agentic AI adoption; the two positions reconcile only if that AI is for FBI casework throughput rather than network defense.
The mechanism the bureau describes is throughput on the attacker side. AI models are surfacing vulnerabilities faster than defenders schedule downtime, and that is what an FBI official at the Billington summit said should force a rethink of patching [9]. Ferranti's remedy is scheduling, not tooling: risk-based remediation, running all the time, instead of Patch Tuesday or a quarterly window [7][8].
A quarterly cycle is about 91 days long; a monthly cycle is about 30. Dropping quarterly for monthly removes roughly 61 days of worst-case wait between a fix existing and a fix landing, and going continuous takes out most of what is left [16].
Bilnoski's half of the message points the other way from the AI framing. He said the FBI keeps finding basic hygiene failures at the root of its cases, including cases with an AI element [4], that hardening the ten fundamental controls the bureau has been pushing would reduce risk from criminal and nation-state targeting [5], and that the next 18 months of attacks will be stopped by what would have stopped yesterday's [6]. The list he named carries no new spend on a detection product.
The AI the bureau is actually buying is for its own casework. The strategy released Wednesday puts AI-enabled tools on triaging large datasets, accelerating malware analysis, prioritising victim notifications, mapping adversary infrastructure and supporting attribution [11], and commits FBI Cyber to rapid agentic AI adoption for defense and disruption, citing President Trump's Cyber Strategy for America [12]. It also extends the Computer Network Operations program, the court-authorized tooling used to collect against and disrupt actors when ordinary investigation will not get there [14]. That is bureau capacity built for its own operations, not a control an operator can deploy on a subnet.
The tempo claim itself is carried by assertion. "Exponential increase in the use of AI, whether it's nation-state or criminal" is Bilnoski's phrasing and it comes with no number [3], and the new AI section of the FBI's annual digital crime report is cited as demonstrating measurable impact without those figures appearing in his remarks [13]. The rest of the strategy, by CyberScoop's read, largely restates existing practice, with victim relief and a privacy pledge as the fresher emphasis [15].
Priced honestly, the week's ask is labor: multifactor authentication and the rest of the ten controls Bilnoski named, plus a patch pipeline that can run weekly without waiting on a change board [5][7].
What to watch
- Federal guidance that turns "continuous, risk-based patching" into a directive with fixed remediation deadlines rather than advice.
- Publication of the annual digital crime report's AI section with figures attached, which would let the tempo claim be tested instead of quoted.
- Charging documents or takedowns showing what the expanded Computer Network Operations program does with its court-authorized tooling.