Skip to main content
CybersecurityIncident Response

Democrats Push for CISA Workforce Assessment Amid Cyber Threats

Briefing room with wooden table, chairs, and open notebook, lit by daylight from a tall window.

"America’s cyber defenses are only as strong as the people behind them," Rep. James Walkinshaw said in a news release, framing a new push by House Democrats to force a top-to-bottom review of the Cybersecurity and Infrastructure Security Agency’s workforce.

What the CISA Force Structure Assessment Act would require

A group of leading House Democrats introduced legislation Monday that would require the Cybersecurity and Infrastructure Security Agency (CISA) to perform a force structure assessment — a comprehensive review typically used by military organizations — to determine whether the agency has the personnel, training and certifications needed to carry out its mission after the exit of around 1,000 employees during President Donald Trump’s second term.

The bill, named the CISA Force Structure Assessment Act, follows precedent: Congress previously ordered a force structure assessment for Cyber Command, a point the bill’s sponsors use to justify the approach for a civilian federal agency responsible for national cyber defense activities.

Specific mission areas the bill would examine

The proposed assessment lays out a wide remit. Elements spelled out in the bill include:

  • An inventory of whether CISA retains the necessary personnel, training and certifications after budget cuts and other Trump-era departures;
  • A review of the security of federal IT systems and CISA’s support for state and local governments;
  • An examination of the risks posed by artificial intelligence, quantum computing and other cutting-edge technologies;
  • An assessment of CISA’s threat-hunting and incident response capabilities;
  • Evaluation of support for critical infrastructure and operational technology, including CISA’s role as a sector risk management agency for several industry sectors;
  • A look at the operation of the Joint Cyber Defense Collaborative; and
  • An appraisal of CISA’s international cooperation efforts.

Lawmakers’ stated concerns and partisan lines

Rep. James Walkinshaw, the Virginia Democrat listed as lead sponsor, framed the legislation as a means for Congress to get “a clear accounting” of whether CISA can meet evolving threats and deliver on its mission. Co-sponsors include Bennie Thompson, the top Democrat on the House Homeland Security Committee, and Delia Ramirez, the top Democrat on its cybersecurity subcommittee.

The bill’s Democratic backers argue the assessment is necessary after workforce reductions and budget changes they say have degraded the agency’s capacity. Delia Ramirez criticized Republicans for what she described as “a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy” in going along with CISA cuts. Lawmakers on both sides have voiced concern about the scope of those cuts, the source said, though Republicans have approved some reductions while pushing back on others.

Bennie Thompson emphasized specific external pressures in his statement: “With Iran targeting our critical infrastructure and frontier AI models creating new cyber risks, we must ensure we have a cybersecurity workforce to counter these growing threats,” he said, adding that “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has [the] right personnel in place to fulfill its mission.”

CISA’s current hiring posture and budget context

The agency itself is actively recruiting: CISA is “currently seeking to hire hundreds of new personnel,” the reporting notes. That hiring push comes while the agency’s latest budget blueprint calls for further funding reductions, creating an internal tension between workforce expansion efforts and requested funding levels.

How the White House’s training plans intersect with the bill

At the same time, federal training and workforce development initiatives are being discussed at the White House. National Cyber Director Sean Cairncross has described plans to develop a cybersecurity academy meant to consolidate and enhance existing federal cyber training and education programs, and his office has reportedly drafted an executive order to establish that academy. That proposal is presented in the reporting as part of broader efforts to address federal cyber workforce shortages.

The CISA Force Structure Assessment Act aims to produce a factual baseline for Congress by cataloging personnel, capabilities and gaps across critical mission areas. It ties the internal question of staffing to pressing external concerns named by lawmakers — from foreign targeting of infrastructure to emergent risks from frontier AI and quantum computing — and places CISA’s hiring and budget choices into the legislative spotlight. The next concrete step will be the bill’s movement through committees where sponsors and opponents will weigh whether a formal, military-style assessment is the right tool to measure a civilian agency’s readiness.

Original story on CyberScoop