Security1 distinct publisher2 min readPublished
ICIT's Parham Eftekhari says CISA is rehiring under acting leadership while keeping vulnerability management running, and that states keep writing AI law regardless of Executive Order 14365. Two of his five items already bind.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Sort the five items by what they can compel. Two rest on requirements already written down: the NIST SP 800-171 and DFARS clauses attached to federal contracts, and the standing legal duty on agencies to inventory cryptographic systems and prepare a post-quantum migration [1]. The other three are readings of direction, namely where CISA is heading, where AI rulemaking is heading, and whether policy literacy pays off for the person who has it [2]. The split matters more than the count, because the first two survive a change in political weather without needing anyone's goodwill.
The CISA read is the softest of the three and the one most planning rests on. What the source describes is an agency under acting leadership that has started rebuilding parts of the workforce it lost, while holding vulnerability management and public-private collaboration [1]. No headcount, no timetable. Eftekhari's supporting evidence is a character reference: he separated "politics" from "the folks doing the work," who he said are "genuinely there because they want to make America safer" [2], and told the room that "CISA is in good hands with Nick [Anderson]" [3]. He is the founder and chairman of ICIT, speaking at the CyberRisk Leadership Exchange in Boston last month [4]. Weigh it as a well-placed observer's assessment rather than an agency staffing disclosure, and it still supports the planning call: keep the CISA channels staffed on your side.
Quantum is the item with the thinnest excuse for delay, because the mandate predates the current news cycle. Eftekhari's argument was that attention moved to AI and left quantum behind, and that cryptographic inventories should already be running [9].
One disclosure belongs with the advice. The push to read CISA, NIST and ONCD output directly, instead of headlines, arrives with a pointer to ICIT's own weekly policy update for members, from ICIT's chairman [10]. The interest is worth naming, and the agency feeds he points at are free. The piece of this to re-check in a quarter is the CISA trajectory. The two binding items need no re-checking, only budget.
Ranked by verification strength, evidence, and original report placement.
Eftekhari said: "There's politics, and then there are the folks doing the work. The folks doing the work are genuinely there because they want to make America safer."
Eftekhari, founder and chairman of ICIT, made these remarks at the CyberRisk Leadership Exchange in Boston last month.
Eftekhari urged security leaders to follow updates from agencies such as CISA, NIST and ONCD directly rather than relying solely on news headlines, and pointed the audience to ICIT, which provides a weekly policy update to its members.
Two of the five developments Eftekhari listed rest on obligations already in force: the NIST SP 800-171 and DFARS requirements on federal contractors, and the existing legal requirement for agencies to inventory cryptographic systems and prepare post-quantum migration.
The remaining three of the five developments are assessments of direction rather than current obligations: CISA's rebuilding, the fragmentation of AI rulemaking, and the growing value of policy literacy.
CISA continues to operate under acting leadership and has begun rebuilding portions of its workforce after earlier staffing reductions, while maintaining priorities such as vulnerability management and public-private collaboration; Eftekhari encouraged organizations not to mistake political uncertainty for operational paralysis.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Defense suppliers' cyber scores hit a five-year high just as the audits were paused1 distinct publisher
leadership
Dropping Item 407(j) left boards learning cyber risk from the people they supervise1 distinct publisher
security
CMMC Phase 2 is suspended. DFARS 252.204-7012 is not.1 distinct publisher
security
CMMC Phase 2 Assessments Are Paused. The False Claims Act Is Not.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One stage, one write-up, no documents
Every fact in this story is a month-old conference remark relayed by scworld.com and nobody else. The executive order appears as a bare number, the 'existing federal law' on cryptographic inventories is never named, the Pentagon's CMMC pause carries no date or scope, CISA's rehiring comes with no headcount, and its acting leader shows up as 'Nick [Anderson]'. Two of the five sections even open with sentences that lost their subject in editing — a sign of how little primary material sits behind the recap.
Nothing to count
A policy watch-list generates no adoption surface: no release, no deployment, no compliance-uptake figure, not even a count of how many contractors have completed 800-171 self-assessments or how many agencies have finished a cryptographic inventory. We would be inventing numbers to score this.
Reassurance outruns the receipts
The framing promises five things every CISO should watch; what arrives is two standing legal duties and three readings of direction, which our own dek concedes. The overreach is narrow but specific: 'CISA is in good hands' is doing the heaviest lifting in the piece and is supported by one man's confidence, while the genuinely useful line — the CMMC pause leaves 800-171 and DFARS untouched — is undersold in the third slot.
The man diagnosing the fog sells the compass
Eftekhari's advice — treat Washington as strategic risk intelligence, follow the agencies directly, and prize people who can connect policy to business risk — describes exactly the service his own institute provides, and the talk closes by pointing the room at ICIT's weekly member policy update. Add a vendor-adjacent leadership exchange as the venue and a trade outlet that covers such events, and the alignment is close to total. scworld.com never flags it.
Plausible in direction, unchecked in fact
The regulatory picture drawn here is the one most practitioners would recognise, and the claims are modest enough that they are probably broadly right — which is not the same as verified. With a single interested speaker, a single publisher, no primary documents, and no adoption evidence at all, we can vouch for what was said and for the shape of the list, and very little beyond that.