❌

Reading view

There are new articles available, click to refresh the page.

Dems seek top-to-bottom assessment of CISA workforce

A group of leading House Democrats introduced legislation Monday requiring the Cybersecurity and Infrastructure Security Agency to conduct an assessment of its workforce to determine whether it’s up to the task after the exit of around 1,000 employees during President Donald Trump’s second term.

The concept of a force structure assessment is more common in military branches, including one that Congress previously ordered for Cyber Command. The CISA Force Structure Assessment Act would order the agency to carry out a review of whether the agency still has the necessary personnel, training and certifications after budget cuts and other Trump-era departures.

“America’s cyber defenses are only as strong as the people behind them,” Rep. James Walkinshaw, the Virginia Democrat serving as lead sponsor of the bill, said in a news release. “As cyber threats grow more sophisticated and technologies like artificial intelligence and quantum computing reshape the threat landscape, Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery. This legislation will identify critical gaps and give Congress concrete information to address them.”

Also sponsoring the bill are the top Democrat on the House Homeland Security Committee, Bennie Thompson of Mississippi, and the top Democrat on its cybersecurity subcommittee, Delia Ramirez, D-Ill.

Additional elements of the force structure assessmewould include a review of the security of federal IT systems and support for state and local governments; the risks posed by AI, quantum computing and other cutting edge technologies; CISA’s threat-hunting and incident response capabilities; support for critical infrastructure and operating technology, including CISA’s role as a sector risk management agency for a number of industry sectors; the operation of the Joint Cyber Defense Collaborative; and international cooperation.

Some lawmakers and other observers have worried those areas have been greatly impacted by staffing cuts, ultimately hurting CISA’s ability to carry out its core functions.

Ramirez dinged GOP lawmakers for “a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy” in going along with the CISA cuts and other developments at the Department of Homeland Security.

Lawmakers on both sides of the aisle have voiced concern about the scope of cuts at CISA, but Republicans have approved some of them while pushing back on others. CISA itself is currently seeking to hire hundreds of new personnel, even as its latest budget blueprint calls for yet more funding reductions.

“With Iran targeting our critical infrastructure and frontier AI models creating new cyber risks, we must ensure we have a cybersecurity workforce to counter these growing threats,” Thompson said. “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has [the] right personnel in place to fulfill its mission.”

National Cyber Director Sean Cairncross has discussed White House plans to develop a cybersecurity academy meant to consolidate and enhance existing federal cyber training and education programs, with the aim of addressing cyber workforce shortages. His office has reportedly drafted an executive order that would establish that academy.

The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.

Why judgment is emerging as cybersecurity’s defining skill

AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on.

Reaching a technically sound recommendation is also getting easier, which puts more weight on the judgment about what to do with it. A recommendation can make complete sense from a security perspective and still carry consequences for the systems, people and business around it that change what the right decision is.

Experienced practitioners bring context an AI system usually lacks: how systems are actually used, which parts of the business depend on them, what happened during previous incidents, and what an action is likely to set off. That context often changes what a team decides to do next.

This matters for security leaders as they hand AI a larger role in operations. They are the ones deciding where it can act with more freedom and where human judgment stays in the loop. Some of the hardest calls start with analysis that is technically sound, because the information available to the AI may not include enough context about that particular environment.

Security teams face this daily. For example, a critical vulnerability with a public exploit may need to be patched immediately. But if it affects a line controller or a medical device running under vendor certification, an unscheduled reboot could stop production or create a regulatory issue. The environment determines how and when the team should respond.

The same applies to suspicious infrastructure. An IP address tied to malicious activity may also belong to shared cloud infrastructure or a content delivery network that business services depend on, and blocking it would take those services down with it.

Context changes the decision

Experienced practitioners know things about their environments that never made it into an asset inventory, a runbook, or any dataset AI can reach. They know the unimportant server still supports a critical business process. They remember that isolating one network segment during a previous incident took down another service. They can also tell that activity which looks hostile is really an authorized red team, a security test, or scheduled vendor work.

In one case, for instance, a service account showed authentication activity far above its baseline, baseline was connecting from an unfamiliar host at 3 a.m. The recommendation was to disable it pending investigation. An experienced analyst checked the account’s activity and noticed the same spike, host and timing four times a year, during the quarterly close. The activity was statistically unusual and completely normal for that particular business process. Disabling the account would have stopped financial settlement mid-run and cost the team days of manual reconciliation.

This is one of the decisions CISOs now face as they expand AI’s role. How much autonomy to grant a system should not rest mainly on model confidence or threat severity, since neither tells you what happens once the recommended action is taken. Reversibility and blast radius are the better test, and they need to be assessed separately. Isolating a domain controller is reversible by reconnecting it and doing it at the wrong moment can cause an organization-wide outage.

Low-impact, reversible actions are better candidates for greater autonomy, with safeguards in place. More scrutiny makes sense when actions are difficult to reverse. They have a broad potential impact, cross legal or trust boundaries, affect systems beyond the evidence available, or reduce the organization’s ability to investigate what happened.

AI models and their capabilities will keep changing. Security leaders still need to understand the potential impact of the actions they allow them to take.

Look at what people actually do

AI can leave an analyst with dozens of recommendations to review in the time they once spent investigating a handful of cases. Each analyst now has more decisions to make. Organizations need to measure what happens to those decisions.

The KPI you choose determines the behavior you get. Make automation rate the focus, people have an incentive to approve more. Make mean time to resolution the focus and people close cases faster. Neither measures whether the decisions improved. A 90 percent automation rate tells a CISO very little on its own. What matters is what happened in the 10 percent of cases where someone stepped in.

Leaders should look at what happens when a recommendation reaches a person. Whether the analyst approves, edits, or rejects it can tell you more than the automation rate alone. The time spent on the review matters too, along with whether the analyst’s intervention changed the outcome.

AI recommendations can be harder to review because they may arrive already looking well supported. The explanation is fluent, uses the right terminology, and points to evidence that looks credible, even when it does not fully support the conclusion. The signals experienced practitioners relied on to spot weak analysis can become much harder to see.

Under-reliance deserves attention, too. An analyst who second-guesses correct recommendations without adding anything reduces the efficiency AI was meant to provide. Approval latency is a useful signal here. A long queue of recommendations approved almost instantly, especially when people are under pressure, should prompt leaders to check how much review is actually happening.

AI recommendations can be harder to review because they can look convincing. They may use the right language and point to real evidence. The reviewer still needs to check whether the evidence actually supports the recommendation.

For CISOs expanding AI in security operations, a human approval step in front of every automated action is not enough. Leaders need to know what happened during the review, not just that someone approved the recommendation.

Build autonomy policies around reversibility and blast radius. Track what people actually do with AI recommendations, and test whether oversight works by deliberately introducing known-wrong recommendations into controlled workflows.

False negatives need particular attention. A false positive generates something the team can investigate. A confident false negative generates nothing, and the absence of a finding can feel reassuring. An AI-generated all-clear should be treated as a claim requiring evidence, particularly when the consequences of missing something are significant.

As AI takes on more of the initial analysis, practitioners will face more decisions that require context and experience. Security leaders need to make sure that judgment remains part of how their teams work. Getting to a technically sound recommendation faster only helps if the action that follows makes sense for the environment.

The post Why judgment is emerging as cybersecurity’s defining skill appeared first on CyberScoop.

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Colorado police arrested a man last week over charges that he impersonated both Supreme Court Chief Justice John Roberts and head of the National Security Agency’s famed Tailored Access Operations hacking unit.

Joshua Culver, also known as “Maverick Young,” appeared in a Colorado court Tuesday after his arrest stemming from an indictment in Indiana in July on four counts of falsely impersonating an officer of the court and one count of using a forged signature of a judge.

Culver allegedly pretended to be an officer of the NSA in September of last year and said in that capacity he “could take adverse action” against the Tippecanoe County sheriff’s office in Lafayette, Ind. if it didn’t provide him information he sought, including the location of his biological daughter.

He also allegedly pretended to be an NSA officer again that month, then produced a document purportedly from the head of the Tailored Access Operations (TAO) elite hacking unit in February to the Clerk of the Lake County, Ind. Superior Court.

“The document, which purported to bear official letterhead, falsely stated that it was a directive issued by the ‘Director of TAO’ and that Culver was a ‘federal asset’ active in multiple investigations,” the indictment reads. “The document commanded that certain actions be taken as required by ‘federal directive,’ including that the case pending against Culver be dismissed with prejudice, that warrants be quashed, and that Lake County officials cooperate with a ‘federal audit’ of individuals identified in the document.”

TAO has gone by the name of Office of Computer Network Operations since 2017, although in July it indicated that it was resuming its old name. TAO garnered unflattering attention in 2017 after the global WannaCry ransomware outbreak used an exploit that the NSA developed.

The indictment also alleges that Culver used a forged signature of Roberts in September for an “Order of Dismissal With Prejudice” in a case against Culver in Grant County, Indiana.

A defender appointed to Culver did not immediately respond to a request for comment Tuesday.

You can read the indictment below.

The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.

Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming

With identity protection services for millions of victims of the 2015 Office of Personnel Management breach set to expire, a group of lawmakers is making a push to extend them forever.

Sen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., introduced legislation to give lifetime identity protection coverage to around 4.2 million federal employees exposed in the historic breach by alleged Chinese hackers, which affected 22.1 million people. Warner said “the threat remains,” necessitating lifetime coverage.

That coverage is due to end at the end of September, as set by a 10-year authorization from Congress. That prompted the pair of lawmakers to introduce Reducing the Effects of the Cyberattack on OPM Victims Enduring Response and Protecting Identifiable Information Act, or  RECOVER PII Act.

“The data stolen included workers’ most sensitive and personal information – from Social Security numbers to security clearance records – and once that information is in the hands of a bad actor, you don’t get it back,” Warner said in a news release Monday. “We have a responsibility to stand by the federal workers who were put at risk through no fault of their own. This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.”

But the bill could have an uphill climb, given the makeup of Congress and stance of the Trump administration.

The Democratic co-sponsors in the Senate are Tim Kaine of Virginia, with Angela Alsobrooks of Chris Van Hollen, both of Maryland. The Democratic House cosponsors are Reps. Don Beyer and James Walkinshaw of Virginia, with Steny Hoyer of Maryland.

Warner and Norton listed no co-sponsors from the GOP, which controls both chambers of Congress and the White House.  And OPM has declared the program too expensive based on the cost relative to the number of claims.

Similar legislation to extend the coverage, including from Norton, has fallen short in recent years.

“Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,” Norton said Monday. “Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity.”

Some watchdog scrutiny of the OPM program has been critical, and while consumer advocates say identity theft protections are helpful, they nonetheless say they aren’t adequate.

The Warner-Norton legislation also would offer reimbursements to federal employees and contractors for privacy services.

The post Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming appeared first on CyberScoop.

Program to rotate cyber personnel through federal agencies saw little use

A total of eight cyber personnel have served in a program that began in 2022 to rotate workers between federal agencies to bolster the workforce, a watchdog report said Thursday.

Over the life of the Federal Rotational Cyber Workforce program that effectively went away last year, 13 agencies offered 106 positions and received 634 applications, according to the Government Accountability Office. Eight workers won approval to participate.

The goal of the Office of Personnel Management-led program, established by bipartisan legislation, was that “participating employees develop knowledge and skills that they can bring back to their home agencies,” as the GAO noted.

A couple major factors account for the low participation, the study found. One was the sharp decline in eligible advertised positions: 75 in 2023, 31 in 2024 and none in 2025 or 2026.

As of December of last year, OPM said it planned to advertise positions on Connect.gov, but this year OPM said it didn’t do so and wouldn’t be advertising positions due to “budgetary constraints,” according to the report.

“OPM officials stated that they do not anticipate any agencies offering positions in 2026, and that OPM does not intend to invest resources in advertising and managing the program going forward,” the report reads. “As a result, OPM officials stated that the agency does not intend to post advertised positions in 2026.”

The other major factor was that even though there were 634 applications, OPM said there were issues with many of the applicants, including that they were underqualified, didn’t obtain necessary approval in advance of applying or were contractors who weren’t eligible.

Additionally, “It was often easier for agencies to allow employees to serve cyber rotations within their own agency,” OPM reported.

OPM evaluated possible shortcomings in implementing the program in late 2024 and developed plans for improving it, but never followed up on them, the GAO said. As of next summer the program will officially end, OPM said.

The program isn’t the only one that feds have tried to implement to address the persistent gap in cybersecurity skills and experience. Nor is it the only one to fall on hard times in President Donald Trump’s second term, as the administration slashed budgets at agencies and forced out cyber personnel.

The post Program to rotate cyber personnel through federal agencies saw little use appeared first on CyberScoop.

Trump budget boss Russell Vought open to re-staffing CISA

Trump administration budget chief Russell Vought told lawmakers Tuesday that he’s willing to work with Department of Homeland Security Secretary Markwayne Mullin on re-staffing up the Cybersecurity and Infrastructure Security Agency, following deep personnel cuts and further proposed reductions in the fiscal 2027 budget blueprint.

Mullin said last week at a House Appropriations Subcommittee on Homeland Security hearing that he would like to hire 600 more people at CISA, similar to remarks he made earlier this month at another House hearing. President Donald Trump has cut or lost more than 1,000 from an agency that stood around 3,400-strong at the end of the Biden administration — cuts criticized by lawmakers in both parties.

At a House Appropriations Subcommittee on Financial Services and General Government   hearing Tuesday, Rep. Mark Amodei, R-Nev., asked Vought about Mullin’s CISA remarks.

“You don’t just flip a light switch on, and you got 600 folks over in CISA now. What’s the plan for getting CISA fully operational?” Amodei, who chairs the panel’s Subcommittee on Homeland Security, asked. “How do we make sure we have a robust, effective, cost-effective CISA force? Because I don’t think anybody thinks we have it now.”

Vought, director of the Office of Management and Budget, said he hasn’t received a formal request from Mullin to increase CISA’s number of full-time employees, but knows that hiring isn’t instantaneous.

“He was not here when we developed this budget, so if he feels the need to have additional resources, we will work through that internally, and at the appropriate time, come up and brief you,” he answered Amodei. “I do think he’s in the process still of getting his arms wrapped around the department,” he said. Mullen became DHS secretary in late March.

“This is probably one of those things, particularly in the cyber world, you now have a year and a half of a new administration,” Vought continued, and referred to conservative complaints about how CISA handled election security and disinformation under Biden. “We saw this agency had major concerns with it in our four years outside of government and with new management, I think it’s now an agency, or could be an agency, that plays a very valuable part for DHS’s portfolio.”

Bringing hundreds of new CISA personnel on board could prove challenging for reasons beyond the usual bureaucratic hurdles and security clearance processes that slow any federal hires in the national security space. Past CISA employees and agency observers have said the way the Trump administration has purged personnel and treated those who have stayed could prove a further disincentive to future hires.

Acting CISA director Nick Andersen recently said that the agency has begun the process of hiring new CISA staffers, and expected to have nearly 200 job offers out by the end of this month.

The post Trump budget boss Russell Vought open to re-staffing CISA appeared first on CyberScoop.

❌