Acting CISA Director Madhu Gottumukkala told House appropriators that a potential Department of Homeland Security funding lapse would materially reduce CISA’s ability to support public- and private-sector partners, warning that “when the government shuts down, cyber threats do not.” He said a shutdown would degrade timely, actionable guidance; curtail core missions such as digital response; and limit work to activities deemed essential to protecting life and property—shifting the agency from proactive efforts (including vulnerability scanning) to a more reactive posture. He also said a shutdown would force more than a third of CISA’s frontline security experts and threat hunters to work without pay and would impede progress on CISA’s long-awaited cyber incident reporting rule.
In the same congressional context, Gottumukkala also acknowledged that about 70 CISA staff were reassigned to other DHS offices over the last year (including a “handful” to ICE), while “30 plus” personnel were transferred into CISA; a December 2025 staffing chart cited in reporting reflected 27 inbound and 65 outbound reassignments. Separately, Congress reauthorized the Cybersecurity Information Sharing Act of 2015 (CISA 2015)—which provides liability protections, FOIA exemptions, and other safeguards for sharing cyber threat indicators and defensive measures—extending it from its planned January 2026 sunset to September 30, 2026. Reporting on the Senate Intelligence Committee advancing a nominee to lead U.S. Cyber Command/NSA is related to federal cyber leadership but is not part of the shutdown/CISA operational-impact story.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CISA announced a series of listening sessions related to revisions to its Cyber Incident Reporting for Critical Infrastructure Act rulemaking. The announcement came as agency leaders warned a shutdown would further slow the already delayed rulemaking process.
In separate testimony to House appropriators, Gottumukkala said about 70 CISA employees had been reassigned to other DHS offices over the previous year, with more than 30 people transferred into CISA. The disclosure contradicted his earlier January remarks and intensified concerns about the agency's staffing and readiness.
Testifying before the House Appropriations Homeland Security subcommittee, Gottumukkala said a DHS funding lapse would furlough most of CISA's workforce, leave 888 of 2,341 employees as excepted staff working without pay, and halt or limit proactive cyber work. He said CISA would focus on immediate threats, maintain its 24/7 operations center, and pause or delay work including vulnerability scanning, service deployment, and CIRCIA rulemaking.
Congress approved a two-week extension of DHS funding, setting up a new Friday deadline and the risk of a partial shutdown if lawmakers failed to reach a broader agreement. The extension framed subsequent warnings from CISA about operational impacts.
In January, Gottumukkala told the House Homeland Security Committee that the staff reassignments did not occur during his tenure. That statement later conflicted with his February testimony acknowledging about 70 reassignments over the past year.
Over the following year, roughly 70 CISA employees were management-directed to other DHS components, including some to ICE, while more than 30 employees transferred into CISA. Lawmakers later raised concerns that moving experienced cyber staff could weaken U.S. cyber defenses.
Madhu Gottumukkala joined CISA in May of the prior year and later became acting director. His tenure became relevant to later congressional scrutiny over staff reassignments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcenextgov.com
Open sourcebankinfosecurity.com
Open sourcetherecord.media
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.