Skip to main content
CybersecurityInfrastructure

CISA Slashes Cybersecurity Resources for Critical Infrastructure

Empty conference room with laptop and papers on a wooden table by a window.

"My apologies to those I told to leverage these free resources recently," said Denis Calderone, CTO of Suzu Labs, summing up the concern echoed across the security community after the Cybersecurity Infrastructure and Security Agency announced it will roll back several services that directly supported critical infrastructure operators.

CISA's rollback and the six retired assessment programs

The agency is eliminating six free cybersecurity assessment programs used by critical infrastructure organizations. The programs named in the announcement are Cyber Resilience Reviews; Cyber Resilience Essentials surveys; Ransomware Readiness Assessments; Incident Management Reviews; and External Dependencies Management Assessments or Cyber Infrastructure Surveys. CISA will replace them with a self‑service questionnaire, according to the statements cited in the announcement.

Budget cuts, a shrinking workforce, and hiring uncertainty at CISA

The decision to curtail those services follows both budget cuts and a declining workforce within the agency. The agency reportedly lost roughly a third of its workforce over the last 18 months. Department of Homeland Security plans to hire 600 new staff and CISA extended offers for 329 mission‑critical positions, but as of late August it remained "unclear how many of those hires have actually come on board," the source material reports. Those personnel constraints were cited directly as part of the rationale for scaling back assessment programs.

Denis Calderone and John Strand: industry reactions

Two security leaders offered sharply critical reactions. Denis Calderone described the replacement tool as insufficient: "The replacement is a self‑service questionnaire that the people who built the original tools say doesn’t do the same job." He also warned about timing: CISA is "weeks away from finalizing CIRCIA," which will require critical infrastructure operators to report cyber incidents within 72 hours and ransomware payments within 24 hours, and the cuts come "just as they take away the testing tools."

John Strand, owner of Black Hills Information Security, framed the move as counter‑intuitive at a moment of heightened targeting. "Do the people making these decisions have any access to the news?" he asked, and added bluntly, "This is crazy." Strand argued many organizations that relied on the free CISA programs lack the budget or personnel to replace them with commercial services and called for an expansion — not a reduction — of free assessments, threat intelligence, training, and technical assistance for small municipalities, rural hospitals, water systems, and utilities.

CSET, CPGs, and the replacement self‑service questionnaire

Industry voices explained what tools remain and how they differ. Older versions of the Cybersecurity Evaluation Tool (CSET) are open source and still available on GitHub with the six retired assessment modules, according to the reporting. Calderone described CSET as a diagnostic tool that "measures where you actually stand against specific security standards." By contrast, CISA's Cybersecurity Performance Goals (CPGs) are framed as a prioritization framework that "helps you figure out where to focus." Calderone said the two are complementary: "Use CSET to diagnose your current state, then use the CPGs to prioritize what to fix first."

What will change, he noted, is availability of in‑person or regional assistance: "What you won’t get anymore is a CISA regional adviser helping you interpret the results." The announced replacement — a self‑service questionnaire — was criticized as not equivalent to the retired assessments by the people who helped build the original tools, per the source.

How water utilities, state programs, and local operators are responding

Concern about scale and reach featured prominently. Calderone pointed to "50,000 small water utilities alone," noting skepticism that CISA's regional staff could have reached all of them and observing there is "no public data showing how many operators actually used the assessments or what the measurable impact was." The reporting also noted that several states are "stepping up direct cybersecurity support for local operators" to fill gaps left by CISA's reductions.

One named initiative that may provide a partial backstop for the water sector is Project Watershed 250, which "just launched in Texas with free vulnerability assessments and red‑teaming" and "is supposed to expand nationally," the source reports. Still, both Calderone and Strand warned small municipalities, rural hospitals, and utilities — groups they identified by name — are likely to feel immediate effects because many cannot afford commercial replacements for the free federal assessments.

The timing of the cuts — weeks before finalization of CIRCIA's reporting deadlines and amid an acknowledged workforce shortfall at the agency — leaves clear, specific questions in the record: how many of CISA’s 329 mission‑critical offers have been accepted and onboarded, and how will operators be supported to meet incident‑reporting deadlines when the agency's regional assessment capacity is being scaled back?

Original story: CISA Cuts Critical Infrastructure Security Resources — Security Magazine