Sen. Mark Warner has asked the Cybersecurity and Infrastructure Security Agency for detailed records on staffing, vacancies, attrition, and regional office capacity, warning that workforce reductions may have impaired the agency’s ability to help state and local governments defend against cyber threats. In a letter to acting CISA Director Nick Andersen, Warner requested organizational charts, explanations for employee departures, and historical service metrics since January 2023, including request volumes, fulfillment rates, and response times.
The inquiry comes amid broader concern over layoffs, early retirements, transfers, program cuts, and reduced support for the Multi-State Information Sharing and Analysis Center, as well as continued budget pressure on the agency. Warner said CISA’s plan to hire about 330 employees appears insufficient given the threat environment, particularly for smaller governments and with the November 2026 midterm elections approaching; he also pointed to leadership instability, noting that half of CISA’s 10 regional directors are serving in an acting capacity.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Sen. Mark Warner introduced the Guaranteeing Universal Access to Cybersecurity Act to restore federal funding support for the Multi-State Information Sharing and Analysis Center after he said DHS had stopped paying for the program and blocked grant funding for participation. The move accompanied his broader public warning that CISA staffing cuts and budget reductions were weakening support for state and local critical infrastructure operators.
In a letter to acting CISA Director Nick Andersen, Sen. Mark Warner requested staffing, vacancy, attrition, organizational, and service-delivery records from CISA, arguing workforce reductions may have weakened support for state and local governments against cyber threats.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcemalware.news
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.