CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
CIA Deputy Director Michael Ellis said Tuesday that the agency’s role in Operation Absolute Resolve is an example of how it has moved to put cyber operations at the center of intelligence collection and field missions, rather than treat them as a separate technical service.
Speaking at the Billington Cybersecurity Conference, Ellis said the agency’s cyber teams built the intelligence picture that supported the operation, which he said allowed U.S. special operations forces to locate and apprehend Nicolás Maduro.
“That operation was only made possible by a flawless intelligence picture, and that flawless intelligence picture was built on cyber operations enabled by our [Center of Cyber Intelligence] team,” Ellis said.
Ellis said the intelligence enabled U.S. forces “to identify the location of Nicolás Maduro and apprehend him within four minutes of landing on the ground.”
He provided no details about the methods, systems or sources involved. He also did not explain how cyber intelligence established Maduro’s location or how the agency confirmed the information before the mission.
Reports from the operation, including statements made by President Donald Trump, stated that power outages during the operation were the result of a cyberattack. Experts told CyberScoop in the aftermath that cyber operations may have been involved, but the visible physical attacks that were also part of the operation alone could plausibly explain the outages.
Still, Ellis used the operation to support the agency’s decision to elevate the Center for Cyber Intelligence to a full mission center. Earlier this year, CIA Director John Ratcliffe said the agency reorganized several of its key acquisition and tech directorates to better embrace emerging technologies like artificial intelligence and quantum computing as they reshape “the reality of conflict and asymmetric warfare.”
Ellis reiterated Tuesday that new status gives cyber work a more direct place in the structure the agency uses to organize people, money and technology around major intelligence goals.
“By elevating our Center for Cyber Intelligence to a mission center in our CIA organizational construct, it’s allowed us to both focus priority on the cyber mission as well as to better align resources around that mission,” Ellis said.
The change could reduce the distance between cyber specialists and the officers who plan and carry out intelligence missions. Cyber teams can collect information from foreign digital systems, while analysts compare that material with reporting from human sources, satellite imagery and other forms of intelligence. Mission planners can then turn the combined findings into information that operators can use.
Operation Absolute Resolve, as Ellis described it, shows that process in practice. The cyber component provided direct operational support by producing intelligence about a specific target within the limited period available for U.S. forces to act.
“Without that kind of operational picture being driven by cyber, we wouldn’t have been able to help enable U.S. Special Forces,” Ellis said.
Ellis further said the CIA’s work in Absolute Resolve was an example of why its reorganization needed to be mission-based, which, given the cyber center’s independent status, allows the agency to direct staff funding and technical support toward operations that require close coordination among cyber specialists, analysts and field officers.
The CIA also created a Directorate of Mission Systems to speed the delivery of technology across the agency. Ellis said its guiding purpose is “to deliver tech to our workforce to enable mission rapidly and efficiently.”
The two changes address linked parts of the same process. The cyber center organizes technical collection around intelligence targets, while the new directorate helps provide the tools needed for that work. Their value depends in part on how quickly the agency can acquire and deploy technology as software, security systems and foreign networks change.
Ellis said the CIA previously took an average of two to three years to bring new technology into use. The agency has since set a six-month acquisition target and completed more than 400 purchases within that period, he said.
“Waiting two or three years is simply too long,” Ellis said.
Artificial intelligence has increased the pressure to shorten that timeline. Ellis said AI can reduce tasks that once required hundreds of hours of work to hours. It can also help analysts process large sets of intelligence, identify patterns and connect information that would be difficult for people to examine at the same speed.
“In cyber operations, it brings speed and scale that would be unimaginable without these AI tools,” Ellis said.
Latest Podcasts
Government
FTC rescinds policy requiring health apps to notify customers after a breach
Lawmakers call on Commerce to sanction hackers-for-hire
FBI cyber chief worries private sector not sharing enough cyber threat information
Feds accuse China of ‘systematic’ distillation of U.S. AI models
Technology
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Threats
Conti ransomware crew member sentenced to four years in prison
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Policy
Wyden seeks upgraded NSA security guidance on commercial VPN use
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Reproduced in full under licence from CyberScoop. © CyberScoop. Written by Greg Otto.
Coverage
One outlet has carried this so far.
2026-09-08 19:49 UTC
Related stories
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · 2026-11-12
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · 2026-10-08
- CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
Infosecurity Magazine · 2026-09-16
- Ministry of Justice apologizes after court staff accessed Southport victims' files
The Register · 2026-09-16
- Windows Server 2022 reaches end of mainstream support next month
BleepingComputer · 2026-09-16