❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity/Privacy

Dems seek top-to-bottom assessment of CISA workforce

21 September 2026 at 12:05

A group of leading House Democrats introduced legislation Monday requiring the Cybersecurity and Infrastructure Security Agency to conduct an assessment of its workforce to determine whether it’s up to the task after the exit of around 1,000 employees during President Donald Trump’s second term.

The concept of a force structure assessment is more common in military branches, including one that Congress previously ordered for Cyber Command. The CISA Force Structure Assessment Act would order the agency to carry out a review of whether the agency still has the necessary personnel, training and certifications after budget cuts and other Trump-era departures.

“America’s cyber defenses are only as strong as the people behind them,” Rep. James Walkinshaw, the Virginia Democrat serving as lead sponsor of the bill, said in a news release. “As cyber threats grow more sophisticated and technologies like artificial intelligence and quantum computing reshape the threat landscape, Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery. This legislation will identify critical gaps and give Congress concrete information to address them.”

Also sponsoring the bill are the top Democrat on the House Homeland Security Committee, Bennie Thompson of Mississippi, and the top Democrat on its cybersecurity subcommittee, Delia Ramirez, D-Ill.

Additional elements of the force structure assessmewould include a review of the security of federal IT systems and support for state and local governments; the risks posed by AI, quantum computing and other cutting edge technologies; CISA’s threat-hunting and incident response capabilities; support for critical infrastructure and operating technology, including CISA’s role as a sector risk management agency for a number of industry sectors; the operation of the Joint Cyber Defense Collaborative; and international cooperation.

Some lawmakers and other observers have worried those areas have been greatly impacted by staffing cuts, ultimately hurting CISA’s ability to carry out its core functions.

Ramirez dinged GOP lawmakers for “a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy” in going along with the CISA cuts and other developments at the Department of Homeland Security.

Lawmakers on both sides of the aisle have voiced concern about the scope of cuts at CISA, but Republicans have approved some of them while pushing back on others. CISA itself is currently seeking to hire hundreds of new personnel, even as its latest budget blueprint calls for yet more funding reductions.

“With Iran targeting our critical infrastructure and frontier AI models creating new cyber risks, we must ensure we have a cybersecurity workforce to counter these growing threats,” Thompson said. “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has [the] right personnel in place to fulfill its mission.”

National Cyber Director Sean Cairncross has discussed White House plans to develop a cybersecurity academy meant to consolidate and enhance existing federal cyber training and education programs, with the aim of addressing cyber workforce shortages. His office has reportedly drafted an executive order that would establish that academy.

The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

31 July 2026 at 16:16

President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.”

Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently cyberattacked itself. The White House referred a request for clarification back to Trump’s remarks.

“I think that Minnesota is behind it,” Trump told reporters Friday. “Because they’re grossly incompetent. I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”

The White House also didn’t clarify whom the president believed was behind similar attacks in other states, when asked for comment. Trump has repeatedly used federal power aggressively in Minnesota, a state led by Gov. Tim Walz, a Democrat who was on the ticket that ran against him in 2024 as the vice presidential nominee. Trump also has downplayed Iranian attacks amid the war he launched against the nation with Israel in February.

A number of cyber experts quickly pushed back on Trump’s comments after he made them.

“Victim blaming in cyber is so 2000 and late,” cybersecurity pioneer Chris Wysopal, Veracode co-founder and chief security evangelist, said on the Bluesky social media platform. Said Jake Williams, a member of the IANS faculty: “His own intelligence services are attributing this to Iran.”

Andy Jabbour — founder and CEO of Gate 15, a cybersecurity firm which provides support to the water sector — told CyberScoop that, “speaking candidly, I’m not even sure what he was actually saying or suggesting Minnesota’s government did or didn’t do.”

“Attribution is tricky business,” he continued, referencing recent alerts from the Cybersecurity and Infrastructure Security Agency and others. “But logically, given an ongoing war with Iran, recent statements made by Iran-aligned threat groups, with assessments that the recent activity is aligned with recent CISA warnings, given yesterday’s statements from CISA and the FBI, random unsubstantiated allegations aimed at political opponents seem reckless and are a disservice to the American people.”

Walz struck back at Trump in a Facebook post, noting steps from his Department of Government Efficiency to slash federal funding. CISA has shrunken considerably under Trump, and his administration has pushed states to defend against cyberattacks that feds once countered.

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz said. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

“DOGE took an axe to CISA and left the U.S. exposed to cyber attacks,” he continued. “Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.”

A spokesperson for Minnesota IT Services, a state agency that has been responding to the water cyberattacks, declined to address Trump’s remarks.

“We remain focused on supporting affected communities, securing critical infrastructure and coordinating with local partners and federal officials as the investigation continues,” the spokesperson, Emily Zimmer, told CyberScoop. “We will not comment on political statements or speculate about attribution.”

Other cyber professionals declined to comment directly on Trump’s remarks, but offered thoughts on who was behind the attacks and their motives.

Bryson Bort, CEO and founder of Scythe said the evidence supports the attribution with Iran, and that it looks like hackers there found something they could exploit on the internet and seized the chance.

“This was a target of opportunity,” said Bort, co-founder of the ICS Village, a non-profit advancing awareness of industrial control system security; such systems are common in the water sector. “It wasn’t that Minnesota did something as a state to raise Iran’s ire.”

Cynthia Kaiser, a former top FBI cyber official, said that when the bureau conducts attributions, it looks at technical indicators but also who has the capability, who has conducted similar attacks in the past and what the purpose of the attacks is.

“Iran ticks all these kinds of things,” Kaiser, now senior vice president at cybersecurity firm Halcyon, told CyberScoop. “My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it’s a duck. I’d be shocked if we found out it wasn’t Iran.”

Just last week, CISA updated an advisory about how Iranian hackers were targeting programmable logic controllers in the water sector and other sectors, a warning that the water industry’s information sharing and analysis center said it believed.

“WaterISAC is confident in our government partners’ assessment that the confirmed activity is aligned with the joint Cybersecurity Advisory (CSA) AA26-097A ‘Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure’ published and recently updated by CISA,” Tom Dobbins, executive director, WaterISAC, told CyberScoop. “We have evidence of earlier attacks from Iran even before this current conflict. Cyber attacks are the most viable way that Iran can directly attack our homeland, and it is logical that they would do so, especially given the challenges of absolute attribution.”

The water sector is often viewed as one of the most vulnerable critical infrastructure sectors, and Dobbins called on Congress to provide funding to provide funding for the ISAC.

Sen. Tina Smith, D-Minn., also took issue with Trump’s comments.

“The President provided an unserious response that is beneath the dignity of the office he holds. Iran’s purported cyberattack on Minnesota’s water infrastructure must be taken as a serious threat to our national security.  Smith said in a statement, adding that she’s been in touch with CISA and the FBI and was grateful to Minnesota’s IT experts. “The entire situation serves as a stark reminder of the danger this war puts us in the longer it drags on.”

Fellow Minnesota Democratic Sen. Amy Klobuchar had earlier been in touch with Sean Cairncross, the national cyber director and a Minnesota native, about the incident.

Trump has previously displayed a laissez-faire view toward other cyberattacks on the United States, such as when he’s been asked about Chinese and Russian cyberattacks and Trump shrugs them off as something America does, too.

He also has cast doubt before on his government officials’ assessments of who’s responsible for cyberattacks on the United States, such as when he asserted China rather than Russia was behind the landmark SolarWinds breach.

Updated 8/3/2026: with comments from Minnesota’s senators.

The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop.

House intel bill includes provisions on state and local threat intelligence, election security, AI

21 July 2026 at 12:25

An annual spy policy bill would authorize a cyberthreat intelligence sharing pilot program for state and local governments, and order an outside assessment of how intelligence agencies are currently sharing that information with those jurisdictions.

The House Intelligence Committee approved fiscal 2027 intelligence authorization legislation Monday that also includes provisions on election security and that are meant to boost intelligence community (IC) usage of artificial intelligence for cyber and other purposes.

The measure’s language on state and local information sharing come amid widespread frustration with Trump administration cutbacks on such aid from the federal government, with the president taking explicit action to shift more responsibility for cyber defenses to the local level.

Under the pilot program, the Office of the Director of National Intelligence (ODNI) would pick one state to receive monthly briefings from the ODNI, Department of Homeland Security, FBI and others to receive monthly briefings on “timely, specific, and actionable information regarding cyber threats” in unclassified form. After a year, the ODNI would then provide a report on the viability of a wider briefing program for state and local governments.

The bill requires the ODNI to produce a strategy on information sharing with states and local areas, and would require the Government Accountability Office to conduct an assessment of the state of such sharing now, including a summary of relevant agencies’ current efforts, how the agencies deconflict those efforts and what kind of obstacles security clearances pose to improving information sharing.

Trump’s pick to serve as DNI, Jay Clayton, emphasized his desire to focus on cyber threat information sharing as part of his Senate vetting last week, but some in the GOP are also pushing to significantly reduce the size of his office.

National Cyber Director Sean Cairncross has also talked about creating pilot programs for cyber threat information sharing with state and local governments, but there’s been little movement on that initiative.

During committee deliberation, panel Democrats won adoption of a trio of election security amendments.

An amendment from the panel’s top Democrat, Rep. Jim Himes of Connecticut, would require the intelligence community to publish an unclassified assessment of foreign intelligence threats to the 2026 midterms. Rep. Jason Crow of Colorado’s amendment would partially withhold funding for the ODNI until Congress gets overdue reports it had required on the 2024 and 2026 elections. And  Rep. Chrissy Houlahan of Pennsylvania’s amendment would “protect analysts from retribution by IC leadership for working on intelligence products related to foreign influence in US elections,” according to a news release.

The Democrats’ push arrives shortly after President Donald Trump delivered a primetime address seeking to bolster his long-debunked claims that the 2020 election was stolen from him.

According to a Republican summary of the bill, it includes provisions for “significantly increasing funding for expanded access and use of frontier AI models for intelligence and cyber missions,” to codify and expand the role of the Artificial Intelligence Security Center at the National Security Agency and strengthen information sharing on AI threats.

“This year’s [bill] balances strong transparency and accountability measures while equipping the IC with the resources needed to combat the ever-evolving threats from our adversaries around the world, with a particularly strong focus on the global AI race,” said House Intelligence Chairman Rick Crawford, R-Ark.

Another assessment that the bill orders would come from the Office of Intelligence and Counterintelligence of the Department of Energy on foreign cyberthreats to critical energy infrastructure, including their intent and risks.

The trend in Congress is for lawmakers to incorporate the annual intelligence authorization bill, or some of its provisions, into the annual National Defense Authorization Act, which often reaches the president’s desk at the end of each calendar year.

The post House intel bill includes provisions on state and local threat intelligence, election security, AI appeared first on CyberScoop.

❌
❌