The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is facing a significant staffing crisis following substantial personnel reductions attributed to Trump-era cuts and a prolonged government shutdown. Acting CISA Director Madhu Gottumukkala acknowledged in an internal memo that these reductions have hampered the agency's ability to fully support national security imperatives, with nearly one-third of the workforce lost in the past year. The memo outlines an urgent need to hire highly qualified professionals by the end of fiscal year 2026 to restore and strengthen CISA's defensive posture, leveraging the Department of Homeland Security's Cyber Talent Management System to attract critical cyber talent at market rates.
In response to mounting cyber threats, particularly from China, CISA is accelerating recruitment, workforce development, and retention initiatives. The agency plans to focus on hiring state cybersecurity coordinators, regional cybersecurity advisors, and making itself more attractive to both industry experts and junior practitioners. Additional measures include expanded collaboration with colleges and universities, reviving internship programs, and considering return-to-office exemptions for certain employees. These efforts are intended to ensure CISA's mission readiness and operational continuity amid increasing cyber risks and resource constraints.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Trump administration officials said they were working to restore CISA staffing after major personnel cuts. DHS Secretary Markwayne Mullin said he wants to add 600 employees, OMB Director Russell Vought said he is open to more staffing if DHS formally requests it, and Acting Director Nick Andersen said nearly 200 job offers were expected by the end of the month.
Follow-up coverage examined the depth of CISA's staffing problems and described the crisis as hampering the agency's ability to carry out its mission. The reporting expanded on the earlier disclosure by characterizing the issue as a broader operational strain on the agency.
Multiple reports said the U.S. Cybersecurity and Infrastructure Security Agency publicly admitted it was facing a major staffing shortfall while confronting mounting cyber threats linked to China. The disclosure framed the personnel gap as a significant operational problem for the agency.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcegovinfosecurity.com
Open sourcescworld.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.