Shrinking Cyber Agency Cited as National Security Risk

Dow Jones
3 hours ago

The federal government's dwindling cybersecurity agency is increasingly seen as a weak link in national security, as ongoing downsizing efforts run up against cyber adversaries armed with advanced artificial intelligence.

Calls to rebuild the Cybersecurity and Infrastructure Security Agency, or CISA, have taken on greater urgency in recent weeks after Iran-linked hackers, using AI to scan for vulnerabilities, disrupted water and wastewater facilities across several states.

"If we're going to take this threat seriously, with regard to our infrastructure, we cannot downsize CISA," Rep. Raja Krishnamoorthi, an Illinois Democrat, said Wednesday at a hearing by the House Permanent Select Committee on Intelligence. "We should be actually resourcing more heavily at this point," Krishnamoorthi said.

Earlier Wednesday, the agency confirmed plans to shutter a half dozen regional programs that provide security assessments to critical infrastructure operators, including its Cyber Resilience Review, Ransomware Readiness Assessment and Incident Management Review services.

"CISA routinely evaluates our services and tools to make necessary changes to improve," Chris Butera, the agency's acting executive assistant director for cybersecurity, said in a statement.

Butera said the existing programs are being replaced by a single assessment designed to achieve the same objectives while improving "data quality and comparability." He said the new program aims to provide data for national-level decision-making and resilience planning, and eliminate redundant services.

The move follows deep spending and job cuts over the past year, which have left the agency with a fraction of its workforce. CISA's 2026 budget was cut by $300 million, from $2.9 billion to $2.6 billion.

"CISA has an extraordinarily important mission and that mission isn't getting any easier," said Matthew Hartman, chief strategy officer at the Merlin Group, a cyber-industry investor. "The priority should be ensuring that CISA has the people and technical expertise it needs," Hartman said.

Mixed messages from the White House, agency officials and lawmakers are only adding to uncertainty about the agency's future.

The Trump administration's proposed 2027 budget seeks another 850 job cuts, which would leave CISA with less than a third of its workforce from two years ago. Yet, as recently as June, Homeland Security Secretary Markwayne Mullin told Congress he plans to hire up to 600 more workers. Meanwhile, in ongoing budget talks, lawmakers have said millions of dollars are being set aside to recruit agency workers in critical areas.

For its part, the agency in recent weeks has posted some open positions online, including a cybersecurity state coordinator, a supervisory IT cybersecurity project manager and an IT cybersecurity specialist.

Rep. Bennie Thompson (D., Miss.), who is a ranking member on the Homeland Security Committee, said the job postings show the administration itself is aware that cuts to CISA "have harmed our national security and need to be reversed."

Confusion surrounding the agency, "has created real uncertainty, and in this environment, uncertainty and ambiguity are serious risks," said Dana Simberkoff, chief risk, privacy and information security officer at cybersecurity firm AvePoint.

Among other issues, Simberkoff said the lack of clarity at the federal level is pushing more responsibilities onto individual organizations. That leaves private-sector cybersecurity teams-including those at a majority of privately operated infrastructure facilities-to make critical decisions on threat prioritization, incident response, third-party risk and resilience, she said.

Dave Gerry, chief executive officer at bug-bounty platform Bugcrowd, said lawmakers generally agree on the need to bolster the agency around its core mission to secure critical infrastructure. "Every indication we have from conversations with members on the Hill indicates there is a bipartisan push to rebuild CISA," Gerry said.

Recruiting is unlikely to pick up before a permanent director is in place, according to Mayuresh Dani, security research manager at cloud-based security platform Qualys. CISA has been overseen by a series of acting directors since early 2025. Even then, Dani said he expects the agency to strip away nonstatutory or politically contested roles, such as election security, and focus recruiting on core cyber defense.

"CISA may ultimately become a smaller agency," said Louis Eichenbaum, federal chief technology officer at cybersecurity firm ColorTokens. What matters, he said, is having the right people in the right positions to provide private-sector industries with cyber capabilities and coordination that are otherwise unavailable. "CISA is an important connective tissue between government and industry," Eichenbaum said.

 

At the request of the copyright holder, you need to log in to view this content

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10