The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has retired six cybersecurity assessment and support programs for critical-infrastructure operators following budget reductions and a workforce decline of roughly one-third. Discontinued services include Cyber Resilience Reviews, Ransomware Readiness Assessments, Incident Management Reviews, and Cyber Infrastructure Surveys, leaving organizations to use a self-service questionnaire, Cybersecurity Performance Goals, and potentially older open-source CSET assessment modules. The reductions are expected to weigh most heavily on under-resourced water utilities, municipalities, hospitals, and other operators that relied on CISA regional-adviser support.
Acting Director Nick Andersen said CISA must rapidly address aging technology, accumulated technical debt, and AI-driven risks that could overwhelm infrastructure operators with vulnerabilities. About 250 selected candidates are awaiting security clearances as the agency seeks to fill operational, cybersecurity, infrastructure-security, emergency-communications, and regional roles; Homeland Security has identified roughly 600 positions for refilling. No timeline was provided, and the administration's fiscal 2027 budget request separately proposes eliminating approximately 867 CISA positions, including funded vacancies.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
CISA issued a July warning about ongoing Iranian-affiliated attacks targeting operational technology and programmable logic controllers across multiple U.S. critical-infrastructure sectors.
In late June 2026, Homeland Security Secretary Markwayne Mullin said CISA likely needed approximately 600 additional employees and pledged to refill those positions; he said hiring could take a year.
The administration's fiscal year 2027 budget request proposes eliminating approximately 867 CISA positions, including funded vacant roles, with some reductions to be offset through transfers and targeted hiring.
Nick Andersen warned that accumulated technical debt, aging technology, past government decisions, and AI have created potentially devastating cybersecurity risks. He said rapid, significant changes are necessary to prevent foreseeable worst-case consequences.
Acting CISA Director Nick Andersen said roughly 250 screened and selected prospective employees with tentative offers were awaiting security clearances. The agency is prioritizing operational, cybersecurity, infrastructure-security, emergency-communications, regional, and onboarding-support roles.
CISA retired six cybersecurity assessment and support offerings, including Cyber Resilience Reviews, Ransomware Readiness Assessments, Incident Management Reviews, and Cyber Infrastructure Surveys, citing budget reductions and workforce declines. Organizations are being directed to a self-service questionnaire and Cybersecurity Performance Goals instead.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcenextgov.com
Open sourcesecuritymagazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.