From the Desk of the Editor

September 15, 2026 | By Jonathan Brown


The Cybersecurity and Infrastructure Security Agency has stopped providing six free, facilitated cybersecurity assessments to critical-infrastructure operators. The decision removes Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys from the work performed by CISA’s regional personnel.

CISA describes these as legacy questionnaire assessments whose objectives overlap with the agency’s Cross-Sector Cybersecurity Performance Goals. That explanation minimizes what has actually been lost.

The questionnaires themselves were never the most important part of the service. The important part was the qualified person sitting across from an infrastructure operator, explaining unfamiliar questions, recognizing evasive or mistaken answers, asking for evidence, connecting technical weaknesses to operational consequences and helping the organization decide what to do next.

CISA has not simply retired six forms. It has withdrawn a layer of human expertise from organizations that often have no equivalent expertise of their own.

This matters most outside the major metropolitan utilities, telecommunications companies, financial institutions and heavily regulated energy enterprises that can retain specialized consultants. Rural water systems, municipal governments, small hospitals, electric cooperatives, local transportation authorities and other modestly funded providers cannot easily replace a free federal assessment with a six-figure consulting engagement.

CISA’s cutbacks therefore create a genuine national resilience problem. But they also reveal a practical opportunity. Properly designed artificial intelligence could help small infrastructure operators conduct more rigorous internal assessments, interpret federal standards, develop corrective-action plans and recognize when they need expert intervention.

AI would not eliminate the need for experienced cybersecurity professionals. It could, however, allow the professionals who remain to supervise and validate far more assessments than they could personally conduct from beginning to end.

That distinction is essential. The responsible proposition is not that a chatbot can replace CISA. It is that a secure, standards-grounded AI assessment system could amplify scarce human expertise and make a meaningful level of assistance available to thousands of organizations that would otherwise receive little or none.

What CISA actually removed

CISA’s Cross-Sector Cybersecurity Performance Goals identify a prioritized collection of practices that organizations should implement. They address important controls such as multifactor authentication, asset inventory, vulnerability management, logging, incident planning and recovery.

The CPGs are useful. They are not a substitute for an assessment.

A performance goal tells an operator what it should be trying to accomplish. An assessment examines what the organization has actually accomplished, how reliably it has done so, whether the result has been tested and what would happen if the control failed during a real incident.

Consider backups. A questionnaire might ask whether the organization regularly backs up essential systems. The operator answers yes, and the box is checked.

A competent assessor asks what is being backed up, where the copies are stored, who can alter them, whether they are reachable from the production identity environment and when the organization last restored its most important systems from those copies. In an operational-technology environment, the assessor may ask whether the organization has preserved programmable logic controller configurations, human-machine interface projects, engineering-workstation software, device firmware, licensing information, historian data and the documentation necessary to rebuild communications between components.

The organization may have backups while possessing no demonstrated recovery capability.

The same problem appears throughout cybersecurity assessments. A written incident-response plan may never have been exercised. A network diagram may be five years out of date. A vendor may claim to use multifactor authentication while retaining a shared emergency account protected by a reusable password. A firewall may separate business and control networks while allowing unrestricted management traffic through an undocumented exception. An inventory may list computers but omit cellular gateways, radio links, remote terminal units, programmable controllers and contractor-installed appliances.

A questionnaire records answers. An assessor investigates what those answers mean.

That interpretive work is precisely what rural providers are least equipped to perform by themselves.

The rural expertise problem

The phrase “under-resourced organization” can sound like a polite euphemism for an institution that has simply neglected cybersecurity. That is frequently an unfair characterization.

A small water utility may have enough personnel to operate treatment equipment, maintain pumps, monitor water quality, comply with environmental requirements, repair broken lines, respond to storms and manage billing. Its information-technology function may be performed by one employee who also handles radios, telephone service, office computers and procurement. Some facilities depend on a local IT contractor whose experience lies primarily in commercial desktops and Microsoft 365—not industrial control systems, process safety or cyber incident response.

The operator’s most capable control-systems specialist may be an electrician, instrument technician or treatment engineer who understands the physical process intimately but has never been trained to investigate an identity compromise or interpret a firewall log. Conversely, the outside IT provider may understand endpoint security while knowing little about the operational consequences of rebooting a supervisory-control server, blocking an industrial protocol or installing an update on an engineering workstation.

These are not minor distinctions.

A cybersecurity assessment of critical infrastructure requires several forms of expertise at once:

  • Information technology and identity security
  • Operational technology and industrial communications
  • Network architecture and segmentation
  • Incident detection and forensic evidence
  • Backup, restoration and operational continuity
  • Vendor access and supply-chain dependencies
  • Safety, environmental and public-health consequences
  • Procurement, contracts and insurance
  • Applicable federal, state and sector requirements
  • The facility’s actual physical process

Few small providers employ even one person who covers this entire field.

Rural organizations also inherit technology rather than designing it. Equipment may have been installed by different integrators over several decades. Documentation can be incomplete. A control panel may contain an obsolete computer because the application it runs cannot readily be migrated. Remote access may have been added during an emergency and never formally reviewed. A vendor may maintain an undisclosed cellular connection because it simplifies support. Passwords may be shared because the process must continue during nights, storms and staffing shortages.

The facility cannot simply shut everything down and rebuild according to an ideal reference architecture. It must maintain water pressure, power delivery, medical care, transportation or emergency communications while improving systems that were never designed for modern network exposure.

An experienced assessor understands that reality. The assessor does not merely announce that unsupported equipment is bad. The assessor helps determine what can be isolated, monitored, replaced, backed up or operated manually—and in what order.

The loss of facilitated federal assessments therefore leaves rural providers with more than a knowledge gap. It leaves them with a translation gap between generalized cybersecurity standards and the operational decisions that keep essential services running.

Why ordinary self-assessment fails

Self-assessment is valuable, but it suffers from predictable weaknesses.

People interpret ambiguous questions in ways that validate their existing practices. An organization with a list of office computers may say it has an asset inventory. An organization that once restored a deleted file may say it tests its backups. An operator whose vendor uses a virtual private network may assume remote access is secure without knowing whether accounts are individual, logs are reviewed or the connection reaches more systems than necessary.

Small organizations may not know what evidence should support an answer. They may not recognize dependencies buried in contracts, firewall rules or vendor practices. They may answer based on documented policy even when daily operations have diverged from it.

There is also an understandable reluctance to produce findings that create more work. If a “no” answer implies an expensive project that nobody has the time or budget to complete, the temptation to interpret a partial control as sufficient becomes powerful.

A good external facilitator interrupts that process without treating the operator as incompetent. The facilitator asks:

  • What evidence supports this answer?
  • When was the control last tested?
  • What happened during the test?
  • Who owns the corrective action?
  • What would fail if this dependency became unavailable?
  • Can the organization continue operating safely while the system is restored?
  • Does the documented procedure match what personnel would actually do at two o’clock in the morning?

Those are exactly the kinds of structured, patient and repetitive interactions that an AI system can perform well—provided that it has been designed for assessment rather than casual conversation.

AI as a virtual assessment facilitator

An AI-assisted assessment should not begin by asking an operator to upload its entire network diagram and then requesting a “cybersecurity review.” That would be insecure, poorly bounded and likely to produce a polished collection of generalities.

A credible system would be built around authoritative assessment material. CISA’s Cyber Security Evaluation Tool, the CPGs, National Institute of Standards and Technology guidance, sector-specific standards and approved state requirements would provide the controlling framework. The AI would explain and apply that material, not invent its own standard.

The system could conduct an interview one domain at a time. It could adjust its language to the operator’s level of expertise while preserving the meaning of the underlying requirement.

Suppose a small utility says that it performs nightly backups. The AI should not simply record a positive response. It should ask:

What systems and configurations are included in the backup?
Is at least one current copy isolated from the production network and its ordinary administrative accounts?
On what date did you last restore the supervisory-control application, engineering configuration or another essential operational system from backup?
What evidence records whether the restoration succeeded?
If the primary identity system were compromised, could an attacker also delete or encrypt the backups?
How long could the facility maintain safe operations while restoration was underway?

Those questions transform a compliance answer into a resilience assessment.

If the operator cannot produce evidence of a restoration test, the AI should not mark the control “complete.” It should classify it more accurately:

  • Backup process documented
  • Backup generation reportedly operating
  • Restoration capability not demonstrated
  • Isolation from production identity system unverified
  • Operational recovery time unknown

That is a far more useful finding than either “pass” or “fail.”

The same method can be applied to remote access. The AI could ask for an inventory of vendors, access methods, approving personnel, authentication controls, accessible assets, logging practices and procedures for disabling access when a contract ends. It could detect contradictions—for example, an earlier assertion that all remote access uses multifactor authentication followed by a later disclosure that the equipment manufacturer maintains a shared support account.

AI is particularly capable of maintaining these cross-references across a long interview. It can remember that the organization identified a critical chlorine-control workstation during the asset discussion and later ask whether its software, configuration, credentials and recovery instructions are included in the continuity plan.

A static questionnaire cannot do that.

Evidence must come before credit

An AI assessment system should be designed around a simple rule: a control does not receive full credit merely because someone says it exists.

The system should ask the organization to identify supporting evidence. Depending on the question, that might include:

  • Approved policies and procedures
  • Dated restoration-test records
  • Exercise reports
  • Asset inventories
  • Sanitized configuration exports
  • Network diagrams
  • Identity and access reports
  • Firewall-rule review records
  • Vendor-access lists
  • Support contracts
  • Procurement requirements
  • Training records
  • Incident tickets
  • Patch and vulnerability reports
  • Photographs of equipment labels or control cabinets
  • Minutes showing management acceptance of residual risk

The AI need not receive every sensitive document in full. In many cases, it can ask a human to confirm specific fields, work from redacted material or operate locally where the evidence never leaves the organization.

Its findings should distinguish among controls that are:

  • Claimed but unsupported
  • Documented but not implemented
  • Implemented but not tested
  • Tested with deficiencies
  • Demonstrated through current evidence
  • Independently validated
  • Not applicable for a documented reason
  • Unknown because the necessary evidence was unavailable

This approach would make self-assessment more honest without requiring the AI to pretend that it has independently inspected the facility.

Turning findings into affordable action

Identifying weaknesses is only half of an assessment. A rural provider needs to know what to do with them.

A generic report may recommend replacing unsupported equipment, implementing a security operations center, adopting privileged-access management and providing around-the-clock monitoring. Those recommendations may be technically correct and operationally useless to an organization with a limited capital budget and no dedicated security employee.

AI can help translate findings into staged improvements.

For example, complete replacement of an obsolete operational device may require engineering work, procurement approval and a scheduled outage. The immediate plan might instead include removing unnecessary internet exposure, restricting communications to an approved management station, changing vendor credentials, logging access at a network boundary, obtaining a known-good configuration backup and documenting a manual operating procedure.

The AI could separate actions into categories:

Immediate, no-cost or low-cost measures: Disable unused remote access, remove dormant accounts, change default credentials, collect existing documentation, restrict management interfaces and confirm emergency contacts.

Near-term operational measures: Test recovery, review firewall rules, conduct a tabletop exercise, inventory vendor connections, establish individual accounts and verify logging.

Planned capital improvements: Replace unsupported controllers, redesign segmentation, introduce resilient identity services, modernize backup infrastructure or procure secure remote-access technology.

Expert validation required: Active Directory compromise assessment, industrial-protocol analysis, safety-system review, forensic investigation, penetration testing or redesign of operational networks.

This is where AI could become genuinely valuable. It can take a broad set of standards and convert them into a sequence that reflects the organization’s actual staff, budget, equipment, dependencies and operational constraints.

It can also draft the documents that small organizations struggle to produce: incident checklists, vendor questionnaires, procurement language, exercise scenarios, management briefings and funding justifications. Humans must review them, but beginning with a competent draft is far better than beginning with a blank page.

Why the model scales

Traditional assessments scale poorly because expert time is consumed by activities that must be repeated for every organization: explaining terminology, conducting interviews, organizing evidence, mapping findings to standards and writing reports.

AI can perform much of that preparatory work at very low marginal cost.

The same carefully tested assessment agent could support a hundred utilities or ten thousand. It could remain available during night shifts and emergencies. It could repeat explanations without impatience, resume an assessment after an interruption and retain the relationship among hundreds of answers and evidence items.

Standardization is another advantage. Human assessors vary in emphasis and experience. A well-governed AI system could ask every organization the same required questions while generating additional follow-ups based on each answer. Changes to authoritative guidance could be distributed through a controlled, versioned knowledge package rather than relying on every assessor to update personal materials.

The system could also identify where human attention is most valuable. Instead of spending hours gathering basic information, an expert could receive a structured package containing:

  • The organization’s critical services and assets
  • Unresolved contradictions
  • Unsupported control claims
  • High-consequence dependencies
  • Missing recovery evidence
  • Questions requiring technical judgment
  • A preliminary remediation plan
  • The source material supporting each conclusion

The expert would review the difficult twenty percent rather than manually producing the routine eighty percent.

That is how AI amplifies expertise. It does not convert an unqualified answer into an expert conclusion. It allows one expert to supervise, correct and validate the work of many organizations.

At a state or regional level, anonymized results could also reveal common problems. If dozens of utilities cannot document vendor access, restore control-system configurations or isolate backups, assistance can be directed toward those recurring needs. Training, grants and procurement programs can then address demonstrated patterns rather than assumptions.

Such aggregation would require strict safeguards. Sensitive details about identifiable infrastructure must not become a centralized intelligence prize. But carefully minimized statistics could provide the kind of nationwide resilience visibility that CISA risks losing when it abandons standardized facilitated assessments.

The security problem of the AI itself

AI assistance would introduce risks of its own, and those risks cannot be dismissed because the intended purpose is defensive.

A rural utility should not upload network diagrams, credentials, vulnerability findings, emergency procedures and vendor-access details to an ordinary consumer chatbot. That information could expose the organization if it were retained, disclosed through an account compromise, incorporated into an external service or accessed by an unauthorized employee.

A proper assessment system would need strong architectural protections:

  • Local operation or an appropriately contracted protected environment
  • Encryption in transit and at rest
  • Explicit limits on retention and secondary use
  • A prohibition on using customer data to train general models
  • Role-based access and multifactor authentication
  • Detailed audit logging
  • Separation among participating organizations
  • Redaction of passwords, cryptographic material and unnecessary identifiers
  • Defined deletion and export procedures
  • Human approval before any information is shared externally

For the most sensitive environments, an on-premises system should be able to operate without sending facility data to a remote AI provider. The underlying model need not be the largest available model if it has reliable access to a carefully curated assessment library.

The knowledge base must also be protected. An attacker—or simply a corrupted document—could attempt to manipulate the system through malicious instructions embedded in uploaded files. Documents supplied as evidence must be treated as untrusted data, not as instructions the AI is authorized to follow.

The system should cite the specific standard, assessment question and supplied evidence supporting every material finding. It should identify uncertainty rather than filling gaps with confident prose. Its standards library should be signed, versioned and maintained by an accountable authority.

Most importantly, the AI must not be allowed to make uncontrolled operational changes. It should not reconfigure firewalls, alter controller logic, disable accounts or conduct active testing merely because it believes an improvement is appropriate. Assessment, recommendation, authorization and execution must remain separate functions.

What AI cannot determine by itself

AI can improve the quality of internal assessment without turning it into independent verification.

It cannot establish that a firewall rule works merely by reading a policy. It cannot prove that a backup is clean without participating in a controlled restoration and integrity-validation process. It cannot determine whether a network path exists unless it receives reliable technical evidence. It cannot guarantee that a safety process will behave correctly during a cyber incident.

It may misunderstand unusual equipment, apply the wrong standard, rely on outdated information or produce a plausible conclusion unsupported by evidence. Small operators may be especially vulnerable to false assurance because the generated report can appear far more authoritative than the underlying assessment deserves.

Every conclusion should therefore carry an evidence and confidence designation. A useful report would say:

Reported by operator; documentary evidence not supplied.
Configuration reviewed, but technical behavior not independently tested.
Restoration completed on the stated date; recovery under compromised-identity conditions remains untested.
Potential high-consequence exposure identified; qualified OT review required.

This language matters. AI should make uncertainty more visible, not bury it beneath professional-sounding text.

A practical national model

The most constructive response to CISA’s cutbacks would not be to leave every rural provider to experiment independently with commercial AI services. CISA, the Environmental Protection Agency, the Department of Energy, state cybersecurity offices, national laboratories and sector organizations could jointly develop an open and governed AI assessment capability.

CISA already has an appropriate foundation in CSET. An AI facilitation layer could guide operators through supported assessments, explain questions, request evidence, identify contradictions and create a review package. Sector agencies could contribute water, energy, healthcare, transportation and communications modules. National laboratories and experienced operators could test the system against realistic infrastructure environments.

A scalable service could operate in layers.

AI-led internal assessment

The operator completes a structured, evidence-driven review with assistance from a secure AI facilitator. The system explains terminology, detects missing information and produces preliminary findings.

Human supervisory review

A state cybersecurity office, sector organization, qualified nonprofit, national laboratory or CISA adviser reviews the high-consequence findings, unresolved contradictions and supporting evidence.

Targeted technical validation

Scarce specialists concentrate on the systems that actually require hands-on expertise: operational-network segmentation, identity compromise, exposed remote access, control-system recovery, safety dependencies and forensic evidence.

Periodic reassessment

The AI tracks corrective actions, requests updated evidence and identifies controls that have not been retested. The assessment becomes an ongoing resilience process rather than a report placed on a shelf.

This model could produce more coverage than the old system while preserving human judgment where it matters most.

Project Watershed 250, the recently launched partnership connecting Texas water and wastewater utilities with private-sector cyber resources at no cost, may provide an early environment for testing some of these ideas. But a 60-day pilot in one state and one sector cannot replace a nationwide federal capability. Nor should critical public infrastructure become dependent on temporary corporate generosity.

If AI-assisted assessment becomes part of national infrastructure policy, it should be maintained as durable public-interest infrastructure: transparent in its standards, protected in its handling of sensitive data, independently evaluated and available to organizations that cannot afford commercial services.

AI is not an excuse for government withdrawal

There is a political danger in presenting AI as the solution to CISA’s retreat. Policymakers may decide that if an automated system can administer the questionnaires, the human expertise was unnecessary after all.

That would be precisely the wrong lesson.

The value of AI lies in extending expert capacity, not eliminating responsibility. Someone must maintain the standards, validate the assessment logic, investigate serious findings, coordinate incidents, study national patterns and help operators whose problems exceed what software can responsibly address.

A rural utility confronting a possible compromise does not need a chatbot telling it to contact a professional. It needs to know that a competent professional will answer.

CISA has announced that approximately 250 prospective employees have received tentative offers, with regional advisers among the agency’s hiring priorities. That is encouraging, but it does not restore the six assessment services, replace the institutional knowledge already lost or resolve the deeper question of what the federal government intends to provide.

Even if every proposed employee arrives, the scale problem remains. The United States contains tens of thousands of infrastructure organizations with radically different technology, staffing and maturity. No realistic federal workforce will be able to conduct frequent, intensive manual assessments for all of them.

That is why AI belongs in the solution.

A force multiplier, if we choose to build it

The CISA cutbacks leave rural providers in an unacceptable position. They are responsible for services upon which public health and safety depend, yet many lack the personnel required to translate an expanding body of cybersecurity guidance into operational decisions.

Telling them to consult another checklist is not sufficient.

AI can do better. It can guide a small organization through a serious assessment, insist on evidence, expose contradictions, explain specialized concepts, connect technical weaknesses to operational consequences and convert findings into an affordable sequence of corrective actions. It can preserve continuity when staff members leave. It can make high-quality preparatory work available at a scale that traditional consulting cannot match.

Used carelessly, it can also expose sensitive infrastructure information and manufacture false confidence. The difference will lie in architecture, governance and the continuing involvement of qualified people.

The choice is not between human expertise and artificial intelligence. Rural infrastructure needs both.

The proper model is an AI system that performs the repetitive work, organizes the evidence and identifies the difficult questions—followed by human experts who review the dangerous findings, validate the technical reality and intervene when public safety is at stake.

CISA’s withdrawal has created a gap. We should demand that the government reconsider the loss of direct assistance. At the same time, we should recognize that simply restoring the former program would not solve the larger problem of national scale.

A secure, evidence-driven AI extension to CSET could place a virtual assessment facilitator within reach of every rural utility, hospital, cooperative and municipality. State and federal specialists could then concentrate their limited time where the evidence shows it is most needed.

That would not be a cheap imitation of expert support.

Properly constructed, it would be a way to make expert support reach farther than it ever has before.


Principal sources

Cybersecurity Dive — “CISA scraps 6 free cybersecurity assessments for critical infrastructure operators,” September 1, 2026; updated September 3, 2026:
https://www.cybersecuritydive.com/news/cisa-cybersecurity-assessments-ending/829371/

Cybersecurity Dive — “CISA is on the verge of filling hundreds of critical vacancies,” September 10, 2026:
https://www.cybersecuritydive.com/news/cisa-hiring-circia-anchor-nick-andersen/829980/

CISA and Idaho National Laboratory — Cyber Security Evaluation Tool repository:
https://github.com/cisagov/cset

CISA and Idaho National Laboratory — CSET releases:
https://github.com/cisagov/cset/releases

CISA — Cross-Sector Cybersecurity Performance Goals:
https://www.cisa.gov/cross-sector-cybersecurity-performance-goals/cross-sector-cybersecurity-performance-goals

Office of the Texas Governor — “Governor Abbott, National Cyber Director Launch Project Watershed 250 To Defend Texas Water Supply,” August 31, 2026:
https://gov.texas.gov/news/post/governor-abbott-national-cyber-director-launch-project-watershed-250-to-defend-texas-water-supply

House Homeland Security Committee members — Letter requesting a GAO examination of CISA workforce and programmatic cuts, August 20, 2026:
https://walkinshaw.house.gov/uploadedfiles/2026.08.20_final_letter_to_gao_re_cisa_cuts.pdf


Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.

Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.