Former NSA chief Nakasone says agency overhaul is ‘probably needed’
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
Former National Security Agency Director Paul Nakasone said a reported broad reorganization of the agency is “probably necessary” as it confronts faster-moving cyberthreats, artificial intelligence and competition with China, but he cautioned that the outcome will depend on how the changes are carried out.
Speaking Tuesday at VulnCheck’s ThreatCon1 conference, Nakasone addressed a recent report that the NSA is undergoing a major restructuring centered in part on artificial intelligence and China. According to a report last month from the Washington Post, the agency is creating five new organizations focused on artificial intelligence, China, cybersecurity, combat support, and global intelligence, with each led by a newly elevated “mission director.”
Nakasone, who led the NSA and U.S. Cyber Command from 2018 to 2024, said he found it encouraging that agency leaders recognized the need to adapt.
“I think that the world has changed so dramatically, so it’s hard to imagine [the NSA] not changing,” he said.
But he said large-scale institutional changes can take time, especially in an agency with broad intelligence, cyber and military responsibilities.
“When you’re a big bureaucrat, how effective is that change? I think it depends,” Nakasone said. “It’s not necessarily the change, because I think that’s a good thing. I think it’s how you implement the change.”
Nakasone’s comments reflected a central tension in the current national security environment: Intelligence agencies are under pressure to reorganize around emerging technologies, particularly balancing the need to keep the United States as a leader in AI, while also defending against adversaries like China that will look to use the technology for their own strategic goals.
He specifically highlighted how AI has sharply reduced the time defenders have to detect and respond to cyber intrusions. When he assumed command in 2018, he said, CrowdStrike data showed that an adversary took hours to move laterally through a system after an initial intrusion. As of 2025, that dwell time has dropped to an average of 29 minutes.
“Remember the old mantra, we’d say, ‘Hey, we have one minute to be able to recognize something has happened, 10 minutes to figure out what we’re going to do, and 60 minutes to really enact it,” Nakasone said. “We’re well past that, and this is the challenge that we have as we think about our opportunities to have better defense in the future.”
That attack timeline is particularly significant as organizations are figuring out how AI can be used to defend their networks and systems. Nakasone, who sits on the board of OpenAI, said defenders have a temporary advantage, which he called a “defender’s window,” before adversaries fully exploit AI’s capacity against critical infrastructure and sensitive organizations.
“I think there’s a defender’s window right now within AI that really our adversaries haven’t caught up and used the capacity that really could be utilized against our critical infrastructure and most sensitive organizations,” he said.
The ability to adapt also depends on personnel, Nakasone said, pointing to agencies competing with private companies for technical talent. Citing figures for the government’s national security workforce, he said the average age is 47, with half the workforce older than 50, 10% younger than 30 and 13.5% could retire immediately.
DefenseScoop reported last week that federal employees in cybersecurity roles could face significant pay cuts.
“I think our government has to create the atmosphere that wants to make sure that people see that their work for the government is valued,” Nakasone said. “I think that there’s probably no one in this room that wouldn’t say that we can be more efficient in our government, but I also think there are a lot of people in this room that have had [their] government service attacked to say, ‘That’s just for people that can’t get jobs on the outside.’ That’s not right. I think there’s a way that we can talk much more effectively about our service and our work in our government.”
More Scoops
Latest Podcasts
Government
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
New bill would create federal investigative body for AI-driven hacks
Technology
Citing China, President Trump doubles down on hands-off approach to AI regulation
Researchers use AI to find widespread software decoder flaw
The AI hacking apocalypse is not inevitable
What’s next for CISA's CDM program that gives cybersecurity tools to federal agencies
Threats
Citrix discloses third actively exploited NetScaler zero-day in less than a week
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
AI policy circles targeted in China-linked phishing operation
WaterISAC reckons with range of threats after summer of cyberattacks
Policy
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
The president has called for AI leadership. Here’s the mission.
Dems seek top-to-bottom assessment of CISA workforce
Originally published by CyberScoop. © CyberScoop. Written by Greg Otto.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-06 17:56 UTC
Related stories
- Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
The Hacker News · 2026-10-07
- PoeLLM malware infects exposed AI servers in cryptomining attacks
BleepingComputer · 2026-10-07
- Hackers exploit critical Atlassian flaw after public PoC release
BleepingComputer · 2026-10-07
- FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The Hacker News · 2026-10-07
- Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
The Hacker News · 2026-10-07