Lawmakers call for investigation into impact of CISA staffing cuts

Members of Congress have asked a government watchdog to examine the effect staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA) have had on the agency’s ability to function.
Bennie Thompson (D-MS), ranking member of the House Committee on Homeland Security, joined several other Democratic representatives in signing a letter asking the Government Accountability Office (GAO) for more information about how CISA is protecting critical infrastructure after nearly one-third of its workforce was slashed at the onset of the Trump administration.
Nearly 1,000 CISA employees have been fired or quit since Trump took office, but acting director Nick Andersen said earlier this year that he planned to hire 300 employees to “rebuild its workforce and address staffing gaps left by the layoffs and voluntary departures.”
“We respectfully request that the [GAO] examine the impact of recent staffing reductions and programmatic cuts at CISA on the agency's ability to carry out its mission requirements, protect critical infrastructure, and respond to evolving cyber and physical threats,” they wrote.
“At precisely the moment when our adversaries are accelerating attacks against critical infrastructure, [CISA]... has lost nearly one-third of its workforce, raising serious concerns about the agency’s ability to fulfill its mission.”
The letter adds that little is known about how the cuts impacted CISA and how the knowledge that was lost has been replaced. Several critical CISA leaders have left the agency over the last year, including David Stern — the driving force behind a key ransomware notification initiative.
CISA did not respond to requests for comment about the letter. GAO spokesperson Sarah Kaczmarek confirmed that they received the congressional request.
“GAO has a process it goes through to determine whether we do work and when, which we are working through right now,” she said.
Markwayne Mullin, Secretary of the Department of Homeland Security, previously said the department has created a plan to rebuild CISA over the next year.
But Friday’s letter notes confusion over the Trump administration’s plan because the fiscal year 2027 budget proposed eliminating nearly 900 additional positions and cutting more than $700 million from CISA.
Dozens of states and senior Congressional leaders have said the cuts to CISA would dangerously impact municipal cybersecurity across the U.S., particularly ahead of the November election season.
Industry leaders and state and local officials told one Senator that they have experienced “reduced responsiveness and support” from CISA and that “staffing turbulence at CISA has disrupted its service delivery and operations.”
The letter references recent advisories from CISA, the FBI and other federal agencies focused on the increased cyber threats facing critical infrastructure organizations. Federal agencies said this week that there is an “active threat” targeting critical infrastructure organizations using AI-generated exploit scripts, in what they called an “evolution” in capabilities.
CISA has not had a confirmed director since Jen Easterly left at the end of the Biden administration. Andersen recently took over on an acting basis for Madhu Gottumukkala, who was removed from the position in February after a series of scandals.
Recorded Future News reported in June that senior Palantir official Shyam Sankar is a lead contender for the CISA director role.
References in this story
- CISA eyes plan for more than 300 new hires | Federal News Network federalnewsnetwork.com After losing roughly one-third of its workforce over the last year, CISA is eyeing a new hiring spree and is loosening restrictions on flexible work schedules.
- Two top cyber officials resign from CISA therecord.media Bob Lord and Lauren Zabierek both posted on LinkedIn Monday morning that they were resigning from the Cybersecurity and Infrastructure Security Agency.
- CISA loses key employee behind early ransomware warnings www.cybersecuritydive.com The future of a program that has helped prevent an estimated $9 billion in economic damages is now unclear.
- DHS chief signals efforts to reshape CISA therecord.media In his first appearance before the panel since being confirmed in March, Mullin said that CISA probably needs “somewhere around” 2,800 employees, despite its ability to hire up to 3,400.
- Warner warns of CISA cuts, staffing gaps in letter to acting chief therecord.media Warner on Tuesday also wrote a letter to DHS Secretary Markwayne Mullin, underscoring that DHS must prioritize CISA and pay for the MS-ISAC.
- NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology therecord.media The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.
- Trump’s pick for CISA director withdraws from consideration therecord.media Sean Plankey reportedly told colleagues that he needed to focus on assuaging concerns about his Coast Guard work that had led Sen. Rick Scott (R-FL) to block his nomination.
- Trump administration removes controversial acting CISA director www.cybersecuritydive.com The new agency chief, Nick Andersen, has significantly more senior cybersecurity leadership experience, which has given some demoralized employees hope.
- Trump considers Palantir exec to lead CISA therecord.media Shyam Sankar, the chief technology officer at Palantir Technologies, has emerged as a lead contender for the long vacant Cybersecurity and Infrastructure Security Agency (CISA) director role, according to the sources…
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51



