Senators and cybersecurity experts warned that CISA is operating under growing strain as the Department of Homeland Security shutdown and the absence of stable leadership compound earlier cuts to the agency’s workforce and budget. During his confirmation hearing, DHS secretary nominee Markwayne Mullin was pressed on whether he would restore staffing and funding after roughly one-third of CISA’s workforce was cut, but he declined to commit to rehiring personnel or reversing budget reductions, saying only that the agency would be staffed to remain mission capable.
Security professionals said CISA can still perform its core statutory functions with excepted staff, but the loss of personnel, sidelining of employees during the shutdown, and lack of a permanent director are limiting the agency’s ability to sustain non-essential programs, build new capabilities, and advocate for long-term resources. Even as CISA continues to issue operational guidance, including recent warnings tied to Microsoft Intune hardening and patching of vulnerabilities in products such as Synacor Zimbra Collaboration Suite and Microsoft Office, the broader concern is that reduced staffing and weakened leadership are eroding national cyber defense capacity at a time of elevated threat pressure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
27 events from the most recent confirmed update back to the earliest known activity.
Cybersecurity Dive reported that nearly all of CISA's top officials had departed or were scheduled to leave by the end of May 2026, according to an internal email from deputy director Madhu Gottumukkala. The departures affected five of the agency's six operational divisions and six of its 10 regional offices, prompting warnings about lost expertise, continuity, and support for critical infrastructure and government partners.
CISA announced that Ryan Donaghy returned to the agency from the Transportation Security Administration to serve as its first chief operating officer. In the new role, he will advise senior leadership on operations, business functions, financial and acquisition management, policy development, and interagency coordination during a period of restructuring and budget pressure.
At a House Homeland Security subcommittee hearing, Democratic lawmakers and witnesses from Tennessee, New York, and Florida warned that proposed cuts to CISA, the State and Local Cybersecurity Grant Program, and federal support for MS-ISAC were weakening state and local cyber defenses. They urged Congress to reauthorize and fully fund state and local cybersecurity assistance amid rising ransomware, AI-enabled, and nation-state threats.
Rep. Don Bacon and Rep. James Walkinshaw publicly said recent staffing and budget reductions have weakened CISA’s ability to defend domestic networks, critical infrastructure, utilities, and local governments against nation-state threats. They pointed to personnel losses, shuttered divisions, proposed FY2027 cuts, and the lack of a Senate-confirmed director as undermining CISA’s coordination and victim-support role.
Tom Parker of IBM Security was reported as a leading candidate to become CISA director, reportedly favored by Homeland Security Secretary Markwayne Mullin for his private-sector experience. The development marked a potential step toward filling CISA's leadership vacancy after Sean Plankey's nomination became nonviable.
Sen. Mark Warner sent a letter to Homeland Security Secretary Markwayne Mullin warning that cuts to CISA's election security mission could leave states and localities without adequate cyber defense and threat intelligence support before the 2026 midterms. He requested details on remaining personnel, programs, assistance requests, trainings, tabletop exercises, and any internal review of election security work.
CISA announced its new CI Fortify initiative to help critical infrastructure organizations maintain essential services during cyberattacks and possible geopolitical conflict. The guidance emphasized isolation and recovery capabilities, though the rollout reportedly lacked specific objectives, timelines, funding, or new resources.
A bipartisan House vote ended the record 75-day Department of Homeland Security shutdown, restoring funding for DHS components including CISA. The fiscal 2026 Homeland Security package provided $64.4 billion in discretionary DHS funding and included $20 million for critical CISA hiring focused on countering threats from China.
Because of the DHS funding lapse, CISA canceled onboarding for summer interns in a government cyber scholarship program, reflecting a direct hit to the agency's workforce development pipeline. The move came as Acting Director Nick Andersen said the shutdown was restricting preparatory work, outreach, and non-salary spending.
CISA Acting Director Nick Andersen told the House Appropriations Subcommittee on Homeland Security that the agency's proposed $2.5 billion budget is meant to stabilize and scale CISA's mission despite the prolonged DHS shutdown. He said the shutdown had reduced CISA to about 40% staffing capacity, harming federal network defense, while the agency sought funding for cyber operations, infrastructure resilience, emergency communications, the National Risk Management Center, and hiring for 329 critical positions.
The Trump administration's fiscal 2027 budget proposal called for another major reduction in CISA funding, with budget documents indicating cuts ranging from $361 million to $707 million depending on the baseline used. The proposal would reduce CISA discretionary funding to just over $2 billion and frame the cuts as a refocusing on federal network defense and critical infrastructure resilience.
CISA Acting Director Nick Andersen told Congress that the DHS shutdown is degrading the agency’s ability to manage cyber risk, with about 60% of staff furloughed, roughly 1,000 vacancies, and recent resignations among key technical personnel. He said CISA is largely limited to mission-essential functions while proactive risk-reduction work has been paused, creating exploitable gaps and longer-term recruiting and retention damage.
Cybersecurity experts publicly warned that CISA's lack of permanent leadership during the DHS shutdown would weaken political influence, long-term planning, threat prioritization, and public messaging. They said the prolonged gap could create exploitable openings for adversaries including China, Iran, North Korea, and Russia.
CISA also recently warned agencies to patch actively exploited vulnerabilities affecting Synacor Zimbra Collaboration Suite and Microsoft Office SharePoint. The guidance reflected continued focus on urgent defensive measures even as non-essential programs were curtailed.
Despite staffing constraints, CISA recently published guidance on securing Microsoft Intune following an Iran-linked cyberattack on medical device maker Stryker. The action showed the agency continuing core operational work during the leadership and shutdown turmoil.
The SC Media report states that Sean Plankey's nomination to lead CISA was no longer viable, leaving the agency without a confirmed permanent director. This contributed to concerns about weakened leadership, funding prospects, and strategic continuity.
During a Senate Homeland Security Committee hearing, senators including Maggie Hassan and Gary Peters questioned DHS secretary nominee Markwayne Mullin about whether he would reverse cuts to CISA. Mullin did not commit to restoring previous staffing or funding levels, saying only that the agency should be adequately staffed with the right personnel.
CISA underwent significant workforce reductions, budget cuts, and rollbacks of programs tied to election security, cyber grants, and vulnerability tracking. By the time of the reported DHS shutdown, the agency was operating with roughly one-third of its staff and only essential functions remained active.
Federal News Network reported that the official leading CISA's federal cyber defense programs resigned from the agency amid broader leadership turmoil and workforce disruption. The departure added to concerns about instability in one of CISA's core operational missions shortly after DHS replaced the acting director.
The Department of Homeland Security removed Madhu Gottumukkala as acting director of CISA and reassigned him to DHS headquarters, replacing him with Nick Andersen as acting director. The move followed controversy around Gottumukkala's tenure and was seen by some employees and officials as a chance to stabilize agency leadership.
Politico reported that two senior CISA officials were reassigned amid internal turmoil following an earlier attempted ouster. The move signaled escalating leadership disruption at the agency immediately before DHS replaced acting director Madhu Gottumukkala.
President Donald Trump re-nominated Sean Plankey to lead CISA after the agency had gone nearly a year without a Senate-confirmed director. The move revived a nomination that had bipartisan and industry backing, though it remained entangled in Senate holds unrelated in part to cybersecurity.
A report published in October 2025 said Trump administration workforce reductions were dulling America's cybersecurity advantage, linking staffing cuts to reduced cyber capacity. The assessment broadened concern beyond CISA headcount losses to the wider impact on U.S. cyber readiness.
A major support contract for CISA's Joint Cyber Defense Collaborative expired on July 25, causing the loss of more than 100 contractors, with only 10 temporarily retained through emergency funding. The lapse disrupted a key public-private cyber defense program responsible for incident coordination, risk assessments, exercises, and threat information sharing.
By June 2025, industry representatives and former officials said the Trump administration's elimination of the Critical Infrastructure Partnership Advisory Council, along with staffing cuts and canceled engagements, had frayed trusted cyber coordination between government and critical infrastructure sectors. The disruption affected information sharing and preparedness across sectors including healthcare, water, energy, and telecommunications.
By early June 2025, roughly 1,000 employees had departed CISA through buyouts, early retirements, layoffs, and DHS workforce transition measures, cutting staffing to about 2,200. Reports said the Cybersecurity Division and Cybersecurity Advisers field staff were among the hardest hit, raising concerns about reduced operational capacity.
Politico reported that the Trump administration was continuing a purge of federal cyber personnel, including workers involved in combating disinformation. The report marked an early public indication that cyber-focused staffing cuts were underway and affecting mission areas tied to information integrity and security.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
41 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcetheregister.com
Open sourcecyberscoop.com
Open sourcegovinfosecurity.com
Open sourceaxios.com
Open sourcecybersecuritydive.com
Open sourcepolitico.com
Open sourcedhs.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.