❌

Reading view

There are new articles available, click to refresh the page.

Dems seek top-to-bottom assessment of CISA workforce

A group of leading House Democrats introduced legislation Monday requiring the Cybersecurity and Infrastructure Security Agency to conduct an assessment of its workforce to determine whether it’s up to the task after the exit of around 1,000 employees during President Donald Trump’s second term.

The concept of a force structure assessment is more common in military branches, including one that Congress previously ordered for Cyber Command. The CISA Force Structure Assessment Act would order the agency to carry out a review of whether the agency still has the necessary personnel, training and certifications after budget cuts and other Trump-era departures.

“America’s cyber defenses are only as strong as the people behind them,” Rep. James Walkinshaw, the Virginia Democrat serving as lead sponsor of the bill, said in a news release. “As cyber threats grow more sophisticated and technologies like artificial intelligence and quantum computing reshape the threat landscape, Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery. This legislation will identify critical gaps and give Congress concrete information to address them.”

Also sponsoring the bill are the top Democrat on the House Homeland Security Committee, Bennie Thompson of Mississippi, and the top Democrat on its cybersecurity subcommittee, Delia Ramirez, D-Ill.

Additional elements of the force structure assessmewould include a review of the security of federal IT systems and support for state and local governments; the risks posed by AI, quantum computing and other cutting edge technologies; CISA’s threat-hunting and incident response capabilities; support for critical infrastructure and operating technology, including CISA’s role as a sector risk management agency for a number of industry sectors; the operation of the Joint Cyber Defense Collaborative; and international cooperation.

Some lawmakers and other observers have worried those areas have been greatly impacted by staffing cuts, ultimately hurting CISA’s ability to carry out its core functions.

Ramirez dinged GOP lawmakers for “a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy” in going along with the CISA cuts and other developments at the Department of Homeland Security.

Lawmakers on both sides of the aisle have voiced concern about the scope of cuts at CISA, but Republicans have approved some of them while pushing back on others. CISA itself is currently seeking to hire hundreds of new personnel, even as its latest budget blueprint calls for yet more funding reductions.

“With Iran targeting our critical infrastructure and frontier AI models creating new cyber risks, we must ensure we have a cybersecurity workforce to counter these growing threats,” Thompson said. “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has [the] right personnel in place to fulfill its mission.”

National Cyber Director Sean Cairncross has discussed White House plans to develop a cybersecurity academy meant to consolidate and enhance existing federal cyber training and education programs, with the aim of addressing cyber workforce shortages. His office has reportedly drafted an executive order that would establish that academy.

The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

Sen. Ron Wyden implored a trio of federal leaders Monday to lead a comprehensive campaign to purge older, insecure virtual private networks that are directly accessible via the public internet from federal agencies.

“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden, D-Ore., wrote in his missive to top officials at the Office of Management and Budget, Cybersecurity and Infrastructure Security Agency and National Institute of Standards and Technology. They should coordinate “require the adoption of modern, secure remote-access technology across the federal government,” he said.

Such VPNs serve as a digital “front door” accessible via the public internet that allows mobile devices and remote employees to log in, Wyden said in a letter first reported by CyberScoop.

Wyden referenced several attacks that have affected federal agencies, including the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures across Fortinet gateways and vulnerabilities that hackers exploited across Ivanti and Check Point VPN appliances.

“Modern remote-access solutions eliminate this vulnerability entirely. Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence,” he said. “This effectively makes these servers invisible, ensuring that hackers cannot attack an entry point they cannot see.”

Agencies should move away from what a Congressional Research Service report to Wyden called a “castle-and-moat” approach of assuming anyone inside the network is authorized to access an organization’s resources that VPNs rely upon by extending virtual bridges to a more remote workforce, he said. They should instead focus on zero-trust architecture that uses a never-trust, always-verify approach, he said.

Furthermore, CISA, the OMB and NIST need to fundamentally change how the federal government approaches agency vulnerabilities, Wyden wrote. 

“The federal government has become trapped in an endless game of ‘whack-a-mole’ in responding to widespread compromises of legacy remote access technologies,” he said. “To keep federal networks online, CISA has been forced to repeatedly issue extraordinary Emergency Directives and hyper-accelerated patch mandates. These reactive emergency mandates are unsustainable for federal cybersecurity teams, and fail to address the fundamental issue that these flaws are inherent in the use of legacy remote-access appliances.”

CISA needs to issue a binding operational directive that gives agencies two years to fully expunge legacy, public-facing remote access systems, he said. NIST needs to issue implementation standards for transitioning to zero-trust architectures.

OMB needs to issue a memo directing agencies to prioritize zero-trust architecture spending. And OMB needs to team with CISA and the Defense Department to update procurement rules to block agencies and defense contractors from buying network edge, VPN or other remote access solutions unless a vendor supplies an attestation that it complies with NIST zero-trust standards, Wyden wrote.

The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.

Program to rotate cyber personnel through federal agencies saw little use

A total of eight cyber personnel have served in a program that began in 2022 to rotate workers between federal agencies to bolster the workforce, a watchdog report said Thursday.

Over the life of the Federal Rotational Cyber Workforce program that effectively went away last year, 13 agencies offered 106 positions and received 634 applications, according to the Government Accountability Office. Eight workers won approval to participate.

The goal of the Office of Personnel Management-led program, established by bipartisan legislation, was that “participating employees develop knowledge and skills that they can bring back to their home agencies,” as the GAO noted.

A couple major factors account for the low participation, the study found. One was the sharp decline in eligible advertised positions: 75 in 2023, 31 in 2024 and none in 2025 or 2026.

As of December of last year, OPM said it planned to advertise positions on Connect.gov, but this year OPM said it didn’t do so and wouldn’t be advertising positions due to “budgetary constraints,” according to the report.

“OPM officials stated that they do not anticipate any agencies offering positions in 2026, and that OPM does not intend to invest resources in advertising and managing the program going forward,” the report reads. “As a result, OPM officials stated that the agency does not intend to post advertised positions in 2026.”

The other major factor was that even though there were 634 applications, OPM said there were issues with many of the applicants, including that they were underqualified, didn’t obtain necessary approval in advance of applying or were contractors who weren’t eligible.

Additionally, “It was often easier for agencies to allow employees to serve cyber rotations within their own agency,” OPM reported.

OPM evaluated possible shortcomings in implementing the program in late 2024 and developed plans for improving it, but never followed up on them, the GAO said. As of next summer the program will officially end, OPM said.

The program isn’t the only one that feds have tried to implement to address the persistent gap in cybersecurity skills and experience. Nor is it the only one to fall on hard times in President Donald Trump’s second term, as the administration slashed budgets at agencies and forced out cyber personnel.

The post Program to rotate cyber personnel through federal agencies saw little use appeared first on CyberScoop.

Trump budget boss Russell Vought open to re-staffing CISA

Trump administration budget chief Russell Vought told lawmakers Tuesday that he’s willing to work with Department of Homeland Security Secretary Markwayne Mullin on re-staffing up the Cybersecurity and Infrastructure Security Agency, following deep personnel cuts and further proposed reductions in the fiscal 2027 budget blueprint.

Mullin said last week at a House Appropriations Subcommittee on Homeland Security hearing that he would like to hire 600 more people at CISA, similar to remarks he made earlier this month at another House hearing. President Donald Trump has cut or lost more than 1,000 from an agency that stood around 3,400-strong at the end of the Biden administration — cuts criticized by lawmakers in both parties.

At a House Appropriations Subcommittee on Financial Services and General Government   hearing Tuesday, Rep. Mark Amodei, R-Nev., asked Vought about Mullin’s CISA remarks.

“You don’t just flip a light switch on, and you got 600 folks over in CISA now. What’s the plan for getting CISA fully operational?” Amodei, who chairs the panel’s Subcommittee on Homeland Security, asked. “How do we make sure we have a robust, effective, cost-effective CISA force? Because I don’t think anybody thinks we have it now.”

Vought, director of the Office of Management and Budget, said he hasn’t received a formal request from Mullin to increase CISA’s number of full-time employees, but knows that hiring isn’t instantaneous.

“He was not here when we developed this budget, so if he feels the need to have additional resources, we will work through that internally, and at the appropriate time, come up and brief you,” he answered Amodei. “I do think he’s in the process still of getting his arms wrapped around the department,” he said. Mullen became DHS secretary in late March.

“This is probably one of those things, particularly in the cyber world, you now have a year and a half of a new administration,” Vought continued, and referred to conservative complaints about how CISA handled election security and disinformation under Biden. “We saw this agency had major concerns with it in our four years outside of government and with new management, I think it’s now an agency, or could be an agency, that plays a very valuable part for DHS’s portfolio.”

Bringing hundreds of new CISA personnel on board could prove challenging for reasons beyond the usual bureaucratic hurdles and security clearance processes that slow any federal hires in the national security space. Past CISA employees and agency observers have said the way the Trump administration has purged personnel and treated those who have stayed could prove a further disincentive to future hires.

Acting CISA director Nick Andersen recently said that the agency has begun the process of hiring new CISA staffers, and expected to have nearly 200 job offers out by the end of this month.

The post Trump budget boss Russell Vought open to re-staffing CISA appeared first on CyberScoop.

❌