CISA-ENISA Joint Messaging @FIRSTdotorg
CISA-ENISA Joint Messaging  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 1 hour ago
Lindsey Cerkovnik (CISA, US), Nuno Rodrigues Carvalho (ENISA, BE)

"The Common Vulnerabilities and Exposures (CVE) Program is a global standard for identifying vulnerabilities, with over 460 CVE Numbering Authorities (CNAs). In this talk, CISA and ENISA will discuss their commitment to the CVE program. CISA will share insights from its 25 years of involvement as a sponsor and participant while ENISA will elaborate on its current work and outline its plans for further expanding its role in the CVE program. Together they will discuss the program’s future and other topics to such as program diversification, internationalization, partnerships, infrastructure modernization, and data quality. Participants will gain valuable insights from ENISA’s and CISA’s unique perspectives as representatives of nation states. The talk will highlight the strong partnerships between CISA and ENISA and their dedication to the CVE program, emphasizing its importance as a public good. Additionally, it will showcase their operational and strategic efforts to enhance the CVE Program's role in global cybersecurity. "

---

Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure

(CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.

Nuno Rodrigues Carvalho currently serves as Head of Sector of the Incident & Vulnerabilities Services within the Operations and Situational Awareness Unit (OSA) of the European Union Agency for Cybersecurity (ENISA). Before joining ENISA as a Senior Threat and Vulnerability Analyst, he developed more than 15 years of experience in strategic, tactical, and operational analysis and situational awareness through roles at both national and international levels. Previously, he also worked at the European Parliament and in the banking sector.
CISA-ENISA Joint MessagingPanel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...Bringing Actionable Data to Internet DefendersUnlocking Insights: The Role of TI in Modern DFIR OperationsThe Quality Era of CVE: A Blueprint for Global Software SafetyBattle-Tested Incident Recovery: Lessons from the Front LinesThe AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect InsiderBoosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?Improving Security Across Nations with FIRST: Esmeralda Kazia, FIRST MemberThe Weaponization Gap: What 20 Million KEV Detections Reveal About Edge RemediationAztronomy: Establishing the Foundation of Attack Path Analysis in Azure
FIRST |

CISA-ENISA Joint Messaging

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER