"I think that the world has changed so dramatically, so it’s hard to imagine [the NSA] not changing," Paul Nakasone said, capturing both urgency and restraint as officials consider a broad overhaul of the agency.
Paul Nakasone on an overhaul: "probably necessary" but implementation matters
Speaking Tuesday at VulnCheck’s ThreatCon1 conference, Nakasone — who led the National Security Agency and U.S. Cyber Command from 2018 to 2024 — described a proposed reorganization of the agency as “probably necessary” while warning that results will hinge on execution. He cautioned that large-scale institutional changes take time in an agency with combined intelligence, cyber and military responsibilities, saying, “When you’re a big bureaucrat, how effective is that change? I think it depends.”
What the reported reorganization would do: five mission-focused organizations
According to a report last month from the Washington Post, the National Security Agency is creating five new organizations focused on artificial intelligence, China, cybersecurity, combat support, and global intelligence, each led by a newly elevated “mission director.” Nakasone said he found it encouraging that agency leaders recognize the need to adapt to faster-moving cyberthreats, AI and competition with China, but he repeatedly returned to the practical question of implementation: “It’s not necessarily the change, because I think that’s a good thing. I think it’s how you implement the change.”

Your town's IT department is one person. Maybe.
Ransomware crews target small municipalities because nobody's watching. Nubivance gives Maine and New Hampshire towns a security program sized to a town budget.
Protect the town officeAI's effect on attack timelines and the "defender’s window"
Nakasone highlighted how artificial intelligence has shortened the time defenders have to detect and respond to intrusions. He contrasted CrowdStrike data from his 2018 assumption of command — when an adversary could take hours to move laterally through a system after an initial intrusion — with a 2025 average dwell time of 29 minutes. He invoked the older operational mantra — “one minute to recognize something has happened, 10 minutes to figure out what we’re going to do, and 60 minutes to really enact it” — and said the environment is now “well past that.”
That shift informs his view that defenders currently hold a temporary advantage. As a member of the OpenAI board, Nakasone described a “defender’s window” before adversaries fully harness AI “against our critical infrastructure and most sensitive organizations.” The phrase captures both opportunity and vulnerability: agencies, companies and operators have a limited period to apply AI for defense before offensive uses narrow or eliminate that margin.
Workforce realities: age, retirements and pay pressure
Nakasone repeatedly tied the agency’s ability to adapt to talent and personnel dynamics. Citing figures for the government’s national security workforce, he said the average age is 47, half the workforce is older than 50, 10% are younger than 30, and 13.5% could retire immediately. He warned that agencies compete with private companies for technical talent and argued for creating an atmosphere that values public service, saying the government must “make sure that people see that their work for the government is valued.”
Those human-resource concerns are layered atop recent reporting of compensation pressure: DefenseScoop reported last week that federal employees in cybersecurity roles could face significant pay cuts. Nakasone framed the challenge as both practical and reputational, noting that service should not be dismissed as “for people that can’t get jobs on the outside.”
How technologists, policymakers, and adversaries will respond
- Technologists and security teams: They will confront shorter detection windows and aim to leverage the current “defender’s window” by accelerating AI tools for threat detection and response, as Nakasone described the time-to-detection problem and the temporary advantage defenders hold.
- Policymakers and procurement leaders: They will face trade-offs between reorganizing structures — aligning to the five reported mission areas — and addressing workforce composition and pay pressures, given the average age, retirement risk and the DefenseScoop reporting on potential pay cuts.
- Adversaries and threat actors: They will be incentivized to exploit AI capabilities as the technology matures; Nakasone’s warning that adversaries “haven’t caught up” yet implies urgency, because that gap could close as offensive uses of AI improve.
Nakasone’s assessment is straightforward: adaptation is probably needed, but the proof will be in the details of implementation and in the agency’s ability to recruit, retain and deploy talent and technology at operational speed. The reported creation of five mission organizations signals intent; the 29-minute dwell-time statistic and the workforce numbers make the stakes concrete. How leaders translate reorganizational design into faster detection, effective AI-assisted defense and a workforce that can deliver those capabilities remains the decisive question.




