U.S. federal cyber operations faced heightened uncertainty amid leadership turnover and staffing reductions at CISA, raising concerns about the agency’s capacity to execute its mission. Reporting indicated acting director Madhu Gottumukkala was replaced by Nick Andersen following controversies including alleged mishandling of sensitive information, while CISA also lost its CIO and reportedly saw staffing reduced by roughly one-third. Separately, Senate confirmation dynamics continued to affect cyber leadership, with Sen. Ron Wyden opposing the nomination of Lt. Gen. Joshua Rudd to lead U.S. Cyber Command and the NSA, citing concerns about experience and constitutional-rights familiarity as the agencies remained without a permanent chief.
CISA’s policy and guidance output continued but faced headwinds from broader federal disruptions. CISA published new insider-threat program guidance centered on the POEM framework (Plan, Organize, Execute, Maintain) to help organizations build multi-disciplinary insider threat management teams spanning physical security, cybersecurity, HR/personnel, and reporting/analysis functions. At the same time, a partial DHS shutdown was reported to be stalling progress on the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rulemaking, complicating compliance planning for critical infrastructure entities awaiting clarity on incident reporting requirements and enforcement expectations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On April 3, 2026, President Trump proposed cutting $707 million from CISA's fiscal year 2027 budget, framing the reduction as a refocus on the agency's core cybersecurity mission. The proposal would eliminate or reduce programs tied to misinformation, stakeholder engagement, international affairs, and other functions, raising concerns about weakened coordination with government and private-sector partners.
Sean Plankey was nominated to serve as CISA's permanent director, but his Senate confirmation remained pending and was reportedly delayed by demands to release a report on telecom cybersecurity flaws tied to Salt Typhoon activity.
Over the past year, CISA reportedly lost about one-third of its staff and also saw the departure of Chief Information Officer Bob Costello, prompting concerns about the agency's operational capacity and security posture.
Nick Andersen replaced Madhu Gottumukkala as CISA's acting director following controversies during Gottumukkala's tenure, including reports involving sensitive document handling and a failed counterintelligence polygraph.
A partial U.S. government shutdown affecting the Department of Homeland Security stalled progress on CISA's cyber incident reporting rule, complicating compliance planning for critical infrastructure organizations.
Sen. Ron Wyden entered a letter into the Congressional Record opposing Army Lt. Gen. Joshua Rudd's nomination to lead the NSA and U.S. Cyber Command, arguing that Rudd lacks sufficient experience and understanding of constitutional rights for the role.
In February 2026, CISA announced it was seeking additional feedback on its draft CIRCIA incident reporting rule, its first major update since industry comments were submitted in 2024.
On January 28, 2026, CISA released guidance titled "Assembling a Multi-Disciplinary Insider Threat Management Team" to help organizations build insider threat programs using its four-phase POEM framework.
Eight days after RSAC appointed former CISA Director Jen Easterly as CEO, CISA, the FBI, and the NSA withdrew from participation in the conference and their officials were removed from the event schedule. The move disrupted planned panels on public-private partnerships, incident response, and nation-state threats, marking a break from years of federal participation in RSAC.
Gen. Timothy Haugh was removed from leadership of the National Security Agency and U.S. Cyber Command in April 2025, leaving both organizations without a permanent chief for months.
Industry comments on CISA's draft Cyber Incident Reporting for Critical Infrastructure Act rule were submitted in June 2024, marking a key step in the agency's incident reporting rulemaking process.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcescworld.com
Open sourcedatabreaches.net
Open sourcedatabreaches.net
Open sourcescworld.com
Open sourcecybersecuritydive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.