The US cybersecurity agency, CISA, is reportedly in a particularly critical state, according to lawmakers from both parties as well as industry executives, who express fears that its ability to carry out its core mission has been weakened, leaving it unprepared for a potential cyber crisis.
See also: CISA: FileZen vulnerability in KEV Catalog

Journalist Tim Starks from the website CyberScoop spoke with sources from Congress, the private cybersecurity sector and other agencies and according to what he reported, there is a broad consensus that CISA has been severely hit by cuts and layoffs during the first year of Donald Trump's administration.
During that time, CISA reportedly lost about a third of its staff, leading to the loss of programs, specialized human resources and expertise, including its ransomware initiative and efforts to promote secure software development. According to a report by TechCrunch, those leaving included members of the election security team. CISA is the federal agency responsible for protecting the electoral process. Some warn that Trump’s insistence on promoting unfounded claims about the 2020 election has led the administration to downplay the agency’s role and importance.
See also: CISA: Federal agencies must fix Dell security flaw within 3 days

CISA also reassigned hundreds of its employees to bolster other Department of Homeland Security agencies, as part of the Trump administration's sweeping crackdown on immigration.
Many of CyberScoop's sources blame the Trump administration, Congress, or both. Others have focused on the acting director of CISA, Madhu Gottumukkala, arguing that he struggled to lead the agency and that his handling of the matter has caused security problems.
CISA has remained without a permanent director since Trump took office in 2025.
The cybersecurity agency is reportedly operating with only about 38% of its staff today, as the partial US federal government shutdown continues, which began on February 14. Lawmakers have refused to approve continued funding for federal immigration authorities, amid strong reactions after the killing of two American citizens by federal agents.
See also: CISA: 4 new security vulnerabilities in the KEV List

In a statement to TechCrunch, Gottumukkala said the agency “remains steadfast in its commitment to protecting federal networks from malicious cyberthreat actors, despite the Department of Homeland Security’s multi-month shutdown.”
