“It’s a Little Bittersweet”: Outgoing CISA Director Jen Easterly on What Keeps Her Up at Night
On a sun-drenched January afternoon in Arlington, Virginia, I step across the threshold of Jen Easterly’s office and am immediately greeted by an enormous taxidermied shark head propped against the floor. Right away I spot her signature: a Rubik’s Cube emblazoned with the logo of the Cybersecurity and Infrastructure Security Agency (CISA) — the organization she’s led for the past three and a half years, first created by former President Donald Trump during his first term.
Now 56, Easterly springs to her feet to welcome me. The first detail that catches my eye is her custom denim jeans: a dragon coiled down one leg, a serpent slithering up the other. Before we even sit down, she’s updating me on CISA’s playful new “Secure Our World” animated public education series — then, in the same breath, she sighs that she hasn’t squeezed in a private guitar lesson in weeks. It reads like any other typical workday for her, with one massive exception: come January 20, Inauguration Day, Easterly’s tenure leading CISA would come to an end.
Trump fired CISA’s founding director Chris Krebs after the agency refused to cast doubt on the integrity of the 2020 presidential election, and Easterly confirms she was never invited to remain in her role under the new Trump administration. Speculation is already rife that key CISA programs — or even the entire agency itself — could soon end up on the administration’s chopping block.
This could not come at a worse moment for the U.S. to lose its top cybersecurity leader. Last year, a Beijing-linked hacking group named Salt Typhoon spent months burrowing deep into U.S. telecommunications networks, stealing call logs, voice recordings, text messages, and even potentially accessing user location data. Many cybersecurity experts have labeled it the most damaging breach in the history of the U.S. telecom sector. Early last year, Easterly and her team inadvertently detected Salt Typhoon activity on federal networks, and those early warning signs ultimately helped unravel the full scope of the espionage operation much faster than would have otherwise been possible.
While the work to kick Salt Typhoon out of compromised networks is still far from finished, pressure is already mounting to restructure CISA. Last week, Trump’s nominee to lead the Department of Homeland Security (which oversees CISA), Kristi Noem, told a Senate committee that the agency should be “smaller” and “more nimble.” Just one day after the inauguration, every member of the Cyber Safety Review Board — the independent panel appointed by Easterly that was actively investigating the Salt Typhoon breaches — was dismissed.
When Easterly officially took over as CISA’s second director in 2021, the U.S. government was still reeling from another high-profile massive hack: SolarWinds. Kremlin-aligned hackers had compromised widely used commercial software to break into networks across dozens of U.S. federal agencies and countless private sector targets. Helping U.S. institutions shore up their defenses suddenly became an even more urgent, daunting priority. Unlike other federal agencies, CISA does not enforce laws or collect intelligence; its core mission is to promote digital security best practices and offer free defensive tools and guidance to organizations, so they can harden their networks to avoid breaches — or, more realistically, limit the damage when breaches do happen. Easterly immediately set to work building collaborative relationships across the federal government, as well as with state and local officials, corporate CEOs, and critical utility operators. Those relationships have proven critical to containing damage quickly during crises like the Salt Typhoon campaign.
Building trust across such a broad, disparate group of stakeholders takes a determined, charismatic leader — and Easterly brings a unique resume to the role. She’s served in the U.S. Army with multiple combat deployments, held leadership roles at the National Security Agency and the National Security Council under the Obama administration, spent nearly five years leading global cybersecurity at Morgan Stanley, and helped stand up U.S. Cyber Command within the Department of Defense. For all that heavyweight experience, she remains remarkably approachable and laid-back. To break the ice and connect with stakeholders across the country, she’s leaned into her personal passions during her tenure: she regularly solves Rubik’s Cubes and jams on guitar with executives and utility operators alike. Her style is equally eclectic, mixing high-end pieces (at least by cybersecurity industry standards) with flared denim and Birkenstocks — but what really defines her work is a quiet, relentless obsession with solving the endless puzzle that is digital defense.
This interview has been edited for length and clarity, combining on-the-record comments from both on-camera and off-camera conversations. Watch the full video interview on WIRED’s YouTube channel.
Q: You’re in your final days as CISA director. How has this stretch felt for you?
A: It’s a little bittersweet.
Q: Why are you leaving CISA at the end of this term?
A: At the end of the day, I’m a Senate-confirmed political appointee. We serve at the pleasure of the sitting president, and I was never asked to stay on for this new term.
Q: There are growing signals that the second Trump administration is hostile to many of CISA’s core priorities. Do you believe the agency has proven its value to the country?
A: We are America’s national cyber defense agency, and our entire annual budget is less than $3 billion. I think the American people are getting an extraordinary return on that investment. Anyone who looks closely at our work can see we’ve made massive progress reducing risk to the critical infrastructure Americans rely on every single hour of every day — that’s water, power, transportation, communications, finance. This is not a political or partisan issue, and these threats are only growing more complex and more dangerous. Rolling back any of the progress we’ve made will only harm the safety and security of the American people.
Q: Salt Typhoon is top of mind for many right now. How did past foreign espionage campaigns like Russia’s SolarWinds attack shape how your team responded to this breach?
A: What we saw when the SolarWinds intrusions came to light in December 2020 — Russian hackers breaking into U.S. federal networks and private businesses around the world — was a remarkably sophisticated supply-chain espionage operation. The biggest takeaway, for me, was that we finally needed to let CISA manage all .gov federal digital assets as one unified enterprise, instead of 100 separate, disconnected departments and agencies operating on their own. That work is still ongoing, but the framework we’ve built across the federal government over the past three and a half years has given us far greater visibility into network activity, letting us detect intrusions much faster, remediate them more quickly, and get ahead of future attacks before they spread.
Q: It’s been worrying how challenging it has been for telecom providers to fully remove the Salt Typhoon hackers from their networks. Have you seen progress on the transparency and shared visibility you’ve been pushing for?
A: After these breaches were revealed, we stood up a unified coordination group to respond. CISA leads the response, the FBI runs the criminal investigation, the National Security Agency contributes intelligence to help us understand how far and deep this intrusion goes. We’ve all been working side-by-side with the victim companies for months now. This incident has gotten a lot of press attention —
(Interviewer: I’d say that’s a good thing!)
You’re right, but any time details become public, there’s a downside: adversaries adjust their tactics to avoid detection. So while transparency for consumers is important, it also makes it harder to track and root out these actors from compromised networks. I don’t expect this to be fully fixed in the near term.
Q: What about the long term? How do we get ahead of these threats?
A: Everyone should operate under the assumption that our adversaries — especially China — are actively targeting our critical infrastructure. The private sector is on the front lines of this fight, because they own and operate the vast majority of U.S. critical infrastructure. That’s why companies need to prioritize collaboration over protecting their own reputations and bottom lines. My vision for the future is one where a major ransomware attack is a shocking anomaly, where dangerous software vulnerabilities exploited by nation-state hackers are as rare as plane crashes. I want a world where the technology we all rely on every day is secure, first and foremost.
Q: Hackers always seem to find new ways to break into networks, no matter how much we harden defenses. Is it even possible to win at cyber defense?
A: You’re absolutely right, defense is hard. I like to call myself America’s cyber goalie, so I know that better than anyone. That’s why this has to be a team effort. Even as we work to hunt down and remove Chinese hackers from U.S. networks, our partners need to hold those actors accountable — whether that’s through offensive cyber operations, criminal indictments, or economic sanctions. It’s still a huge challenge, and we’re on the defensive side of this fight, but that doesn’t mean we can’t make enormous progress. Right now, we’re living through an incredibly scary, precarious moment in cyberspace.
Q: You’ve framed this as a matter of mindset, which makes sense for this kind of work. But I have to ask the classic question: what keeps you up at night?
A: I spent a lot of my career working on counterterrorism, and people always ask that question. But for me, it’s less what keeps me up at night, and more what gets me up in the morning. I love my team, I love this mission. Not every day is easy, but you work through the problems, stay resilient, and stay focused on what matters. That said, if I’m being honest: a major conflict in Asia — specifically a potential Chinese invasion or blockade of Taiwan — would have very real, immediate consequences here in the United States. We could see attacks on pipelines, water systems, severed telecommunications, disrupted rail lines, and power outages. This is all part of a deliberate Chinese strategy to stoke what they call “societal panic” and weaken the U.S.’s ability to mobilize military power and public support for any intervention. We have to be honest that major disruption could happen.
Q: Do you think the public is focusing too much on high-profile espionage campaigns like Salt Typhoon, when we should be more worried about other critical infrastructure threats like China’s Volt Typhoon?
A: CISA is intensely focused on all Chinese cyber actors, full stop. We’re one of the only federal agencies that has been able to detect both Volt Typhoon in critical infrastructure networks and Salt Typhoon in telecom systems. In fact, it was our team’s discovery of Salt Typhoon activity on federal networks several months ago that led law enforcement to identify virtual private servers leased by the hacking group, which ultimately unraveled the entire broader espionage campaign.
Q: We’ve talked before about how Ukraine has faced years of devastating Russian cyberattacks, on top of an ongoing full-scale kinetic war. CISA has partnered with Ukraine’s equivalent cybersecurity agency for several years now. Are you worried the Trump administration will deprioritize that partnership?
A: Ukraine is under active attack by one of the most sophisticated cyber threat actors in the world. Everything we learn from how Ukraine defends against these attacks helps us better protect our own infrastructure here at home. Cyber is a borderless space, so what our foreign partners see and learn absolutely benefits us. We all need to recognize — from technology vendors, to companies that buy tech, to everyday citizens that use it — that we all have a shared role to play in the collective defense of cyberspace and critical infrastructure.
Q: A common critique of U.S. federal cybersecurity is that there are too many overlapping agencies with overlapping roles — too many cooks in the kitchen. Has that been a problem during your tenure?
A: Actually, it hasn’t been an issue anymore, not like it used to be. A lot of people ask me this, so I go back to SolarWinds. When that breach happened, I was looking at it both as the cyber policy lead for the Biden-Harris transition team, and more importantly, from my perspective as Morgan Stanley’s cybersecurity chief. Back then, CISA put out one advisory specifically about SolarWinds, which we didn’t have on our network. The NSA put out a separate advisory focused on VMware, which we did have on our network. It was totally unclear how these two pieces fit together. Then the FBI put out a separate private sector notice about something else entirely. At that point, I’d already been in government for 27 years: I’d served in the military, the Department of Defense, the intelligence community, the White House. I thought I knew how the government worked, and I still couldn’t piece together what the government was trying to tell us about that Russian espionage campaign. That was actually one of the big reasons I wanted to take the CISA director job: I wanted to fix that, to bring the entire federal cyber ecosystem together. Today, the working relationship between CISA, NSA, and the FBI is better than it’s ever been. Some of that is down to personalities, but we’ve actually built permanent institutional connections that will last long after I’m gone. CISA’s role is very clear now. We’ve also sorted out roles at the policy level with the National Security Council and the Office of the National Cyber Director. At the operational level, where CISA does its core work, relationships across the federal cyber ecosystem are stronger than they’ve ever been.
Q: You’ve said you leave a lot of unfinished business at CISA. What do you wish you’d gotten done more of?
A: There’s no question there’s a lot of unfinished work. I’m really proud of the progress we’ve made with our ransomware vulnerability warning pilot and our pre-ransomware notification program — we’re working to stop attacks before they ruin people’s lives, which matters a lot. But ransomware is still a major problem. We’ve been hyper-focused on Chinese cyber activity, and that will continue to be one of the biggest threats this country faces for years to come. I’m proud of where we’ve gotten, but there’s so much more work to do. These are initiatives the next administration should keep driving forward, because at the end of the day, cybersecurity is a core national security issue for this country.
Q: I have to ask about the rumors: are you planning to go on a music tour after you leave CISA?
A: You know, I certainly hope to! I played piano and guitar when I was a kid, but I picked up electric guitar as an adult, and it’s become my real passion, my obsession. My big long-term post-retirement plan, a few years down the line, is to open a bar in lower Manhattan, and have a house band there. We’ll do magic shows, improv comedy, and I’ll be the bartender.
Q: Will there be Rubik’s Cubes on every table?
A: Absolutely, there will be Rubik’s Cubes everywhere. I’m obsessed with them. When I was 11, they launched all over the world, and I was already a huge puzzle and video game kid. I learned how to solve it, and I’d go into toy stores as a little kid with pigtails and say, “If I can solve this in under two minutes, will you give me a free one?” I ended up building up a whole collection of them that way.
Q: Do you see a connection between the Rubik’s Cube and your work leading CISA?
A: Ernő Rubik, the guy who invented it, said something along the lines of: if you’re curious, you’ll find puzzles all around you, and if you’re determined, you’ll solve them. When I think about the incredible technical talent we have here at CISA, that’s exactly what they are: they’re intellectually curious, they have that hacker problem-solving mindset, and they have the relentless determination to tackle the most complicated cybersecurity problems out there. That’s the throughline for me.
Have thoughts on this interview? Send a letter to the editor at [email protected]