The US Senate Committee on Appropriations has advanced a draft bill that sharply reduces funding for federal cybersecurity and information technology modernization initiatives. The proposed legislation allocates only $5 million to the Technology Modernization Fund (TMF), a dramatic decrease from the $75 million requested by the Biden administration and far below previous bipartisan efforts to expand the fund. The Office of the National Cyber Director would also see its budget cut by nearly 7%, receiving $20 million in line with the White House's request. These reductions follow calls from the Trump administration to significantly scale back federal investments in cybersecurity and IT modernization for 2026.
The steep funding cuts raise concerns about the ability of federal agencies to replace outdated legacy systems and undertake critical technology upgrades, as many departments rely on multi-year capital support or cross-agency investment vehicles like the TMF. The future of the fund is further complicated by a White House proposal to change its financing model, potentially allowing agencies to contribute a portion of their own budgets rather than depending solely on annual appropriations. The proposed reductions mark one of the smallest appropriations for the TMF since its creation under the Modernizing Government Technology Act of 2017, potentially impacting the federal government's overall cybersecurity posture and modernization efforts.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
A Senate bill reported on December 1, 2025 would slash funding for U.S. federal modernization efforts. The available references do not provide further detail on the bill's provisions or prior related events.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.