ZeroHour
CyberScooppublished ()ingested @timstarks

Bob Kolasky, head of CISA's National Risk Management Center, leaving agency

criticalExploit / PoC exploited in the wildimportance 60
Full article747 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Director Jen Easterly said Kolasky has been an "outstanding leader at CISA."

CISA, DHS, Department of Homeland Security, RSA 2019
The DHS and CISA booth at the 2019 RSA conference in San Francisco. (Scoop News Group photo)

Bob Kolasky, head of the National Risk Management Center at CISA, announced Tuesday that he is leaving the agency.

Kolasky’s work with the NRMC since its formation in 2018 has put him in the middle of the federal effort to help critical infrastructure companies assess their cyber risk. He’s also been active in a lot of other agency business.

Bob Kolasky (CISA)

He co-chairs the Information and Communications Technology Supply Chain Risk Management Task Force, leads CISA’s work on secure 5G network development, chairs the High-Level Risk Forum for the international Organisation for Economic Co-operation and Development and serves on the executive Committee for the Election Infrastructure Government Coordinating Council.

Kolasky hasn’t announced his plans after leaving the center, nor has CISA named a successor.

During his 15 years of government service, CISA Director Jen Easterly said, “Bob worked tirelessly to expand collaboration across state, local, tribal, and territorial governments and the private sector to reduce cyber and physical threats to critical infrastructure, ensure our nation’s resilience, and protect American lives.”

Kolasky’s departure comes days after POLITICO reported that Mona Harrington, the departing executive director of the Election Assistance Commission, was joining the NRMC as deputy assistant director.

The NRMC has recently been involved in a project of high interest among CISA leadership and on Capitol Hill. Easterly said she tasked it with developing approaches to identifying entities that are the “systemically important, and we’re doing it based on economic centrality, network centrality and logical dominance in the national critical functions.” Pending legislation dubbed it “systemically important critical infrastructure,” something CISA has instead been calling “primary systemically important entities.”

Easterly said Kolasky has been an “outstanding leader at CISA,” and praised him further on Twitter.

It’s been a real pleasure working with @BobKolasky—a true risk management visionary. He built the NRMC from scratch to be one of the crown jewels of @CISAgov, helping drive down systemic risk to the nation. We’ll miss him but wish him great luck in his next adventure! Well done! https://t.co/DeMaPvYgBv

— Jen Easterly🛡️ (@CISAJen) January 25, 2022

More Scoops

Nick Andersen, CISA acting director, at the Axonius Adapt In Action 2026 event. (Tim Starks, CyberScoop)

CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector

Acting director Nick Andersen said a binding operational directive is en route for agencies, and that more specific discussions need to happen with critical infrastructure owners.

LAS VEGAS, NEVADA – JANUARY 25: U.S. President Donald Trump speaks during a rally at Circa Resort & Casino on January 25, 2025 in Las Vegas, Nevada. The event focused on Trump’s first week in office, including his proposed policy to eliminate taxes on tips for service industry employees. (Photo by Ian Maule/Getty Images)

Trump pauses on grants, aid leaves federal cyber programs in state of confusion

U.S. President Joe Biden and then-Republican presidential candidate, former U.S. President Donald Trump, participate in the CNN Presidential Debate at the CNN Studios on June 27. (Photo by Justin Sullivan/Getty Images)

Biden cyber executive order gets mostly plaudits, but its fate is uncertain

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/bob-kolasky-cisa-national-risk-management-center/