Security1 publisher2 min readPublished
House Democrats would make CISA audit its own workforce after about 1,000 departures
House Democrats introduced a bill ordering CISA to measure its threat hunting, incident response and Joint Cyber Defense Collaborative staffing against its mission, and to report the gaps to Congress.
The Watch · Security desk
What happened
- A group of leading House Democrats introduced legislation Monday requiring CISA to assess whether its workforce is still up to the task after about 1,000 employees left during Trump's second term.
- Rep. James Walkinshaw, a Virginia Democrat, is lead sponsor, joined by Bennie Thompson of Mississippi and Delia Ramirez of Illinois.
- CISA is trying to hire hundreds of new personnel at the same time its latest budget blueprint asks for further funding reductions.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Defenders whose runbooks name a federal escalation path, or who sit in the Joint Cyber Defense Collaborative, are relying on an assumption about which CISA functions kept their staff. No published figure backs it up.
- constraint The sponsors are all minority members, so the count gets produced only if Republicans who approved part of the cuts move the bill.
- decision A review that names gaps hands appropriators a specific list to fund; one that reports adequacy makes the case for restoring CISA money harder to argue.
- contradiction Hiring hundreds while requesting deeper cuts means the staffing trend cannot be read off either document on its own.
Force structure assessments belong to the military branches, and Congress has ordered one before, for Cyber Command [4]. The version in this bill would ask whether CISA still has the necessary personnel, training and certifications after budget cuts and Trump-era departures [3]. Six further areas are written into the review: the security of federal IT systems and support for state and local governments; the risks posed by AI, quantum computing and other cutting-edge technologies; threat hunting and incident response; support for critical infrastructure and operating technology, including CISA's role as a sector risk management agency; the operation of the Joint Cyber Defense Collaborative; and international cooperation [8][9].
The figure driving the bill is a headcount. Around 1,000 employees left during President Trump's second term [2]. The CyberScoop account does not break those exits out by function, so which of the six areas lost people, and at what grade, is unknown.
Walkinshaw said: "Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery" [6]. The bill would produce that accounting. It does not show that CISA's advisories, its scanning support or its incident response have slowed. The concern is that the staffing cuts hit those areas hard enough to hurt the agency's core functions [15].
Thompson said that after Trump has spent the past two years targeting and slashing CISA's workforce, the agency needs to assess whether it has the right personnel in place to fulfill its mission [11]. Ramirez faulted Republican lawmakers for "a lack of interest in safeguarding our nation's cybersecurity and our residents' civil rights and privacy" in going along with the cuts [10]. Thompson and Ramirez are the ranking Democrats on the committee and subcommittee that would handle the bill [7]. Republicans have voiced concern about the scope of the cuts, approved some of them and pushed back on others [12].
CISA is meanwhile seeking to hire hundreds of new personnel, while its latest budget blueprint calls for further funding reductions [13].
On a separate track, National Cyber Director Sean Cairncross has discussed White House plans for a cybersecurity academy to consolidate and enhance existing federal cyber training and education programs, aimed at workforce shortages; his office has reportedly drafted an executive order establishing it [14]. CyberScoop says the order is still waiting on a signature.
What to watch
- Whether the Republican-led House Homeland Security Committee gives the bill a hearing or markup.
- Whether the executive order establishing the federal cybersecurity academy is signed and published.
- Whether CISA's hiring of hundreds closes before the reductions in its latest budget blueprint take effect.