Policy & Regulation
CISA faces operational strain amid staff cuts and government shutdown
CISA is reportedly in dire shape, operating at around 38% staff levels following significant personnel losses and ongoing U.S. federal government shutdown pressures.
The Cybersecurity and Infrastructure Security Agency (CISA), a U.S. federal agency, is reportedly in dire shape. According to reporting from news publication Cyberscoop, the agency is currently operating at around 38% staff levels. This operational decline has raised significant concerns among bipartisan lawmakers and industry leaders, who fear that the agency’s ability to perform its core mission has been diminished, leaving it unprepared to manage a major cybersecurity crisis.
Cyberscoop reporter Tim Starks spoke with sources across Congress and the private cybersecurity industry, revealing a consensus that CISA has suffered heavily from cuts and layoffs. Since the Trump administration entered office in 2025, CISA has lost around one-third of its staff. These losses have stripped the agency of key programs, personnel, and expertise. Among the affected areas are CISA’s counter-ransomware initiative and its efforts to promote secure software development. Additionally, several members of the agency’s election security team have been lost, despite CISA being the federal agency responsible for election security. Some sources warned that the Trump administration has deprioritized CISA, pointing to an ongoing focus on false claims regarding the 2020 election. The staffing strain was further exacerbated when CISA reassigned hundreds of other staffers to assist other agencies within the Department of Homeland Security, the parent department of CISA.
The agency’s leadership structure has also drawn attention, as CISA has been without a permanent director since Trump entered office in 2025. Madhu Gottumukkala serves as the acting director of CISA. Despite the ongoing operational challenges, Gottumukkala defended the agency’s resilience. In a statement to TechCrunch, Gottumukkala stated that CISA “remains unwavering in its commitment to protect our federal networks from malicious cyber threat actors despite the multi-week government shutdown” of the Department of Homeland Security.
These operational challenges are compounded by the ongoing partial U.S. federal government shutdown, which began on February 14. The shutdown has dragged on as lawmakers decline to continue funding federal immigration authorities. This funding dispute follows widespread public criticism and scrutiny surrounding the killing of two U.S. citizens by federal agents.
Why it matters
CISA’s reduced capacity raises significant concerns about the U.S. government’s ability to manage cybersecurity crises and protect federal networks during a period of heightened instability. With key initiatives like counter-ransomware programs degraded, both public and private digital infrastructure face increased exposure to systemic threats.