Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cybersecurity-regulationstandards-framework-updatecritical-infrastructure-threat

U.S. Federal Cyber Leadership Turmoil and CISA Policy Disruptions

Updated 3mo agoFirst seen Mar 2, 20266 sources

U.S. federal cyber operations faced heightened uncertainty amid leadership turnover and staffing reductions at CISA, raising concerns about the agency’s capacity to execute its mission. Reporting indicated acting director Madhu Gottumukkala was replaced by Nick Andersen following controversies including alleged mishandling of sensitive information, while CISA also lost its CIO and reportedly saw staffing reduced by roughly one-third. Separately, Senate confirmation dynamics continued to affect cyber leadership, with Sen. Ron Wyden opposing the nomination of Lt. Gen. Joshua Rudd to lead U.S. Cyber Command and the NSA, citing concerns about experience and constitutional-rights familiarity as the agencies remained without a permanent chief.

CISA’s policy and guidance output continued but faced headwinds from broader federal disruptions. CISA published new insider-threat program guidance centered on the POEM framework (Plan, Organize, Execute, Maintain) to help organizations build multi-disciplinary insider threat management teams spanning physical security, cybersecurity, HR/personnel, and reporting/analysis functions. At the same time, a partial DHS shutdown was reported to be stalling progress on the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rulemaking, complicating compliance planning for critical infrastructure entities awaiting clarity on incident reporting requirements and enforcement expectations.

Share:
U.S. Federal Cyber Leadership Turmoil and CISA Policy Disruptions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Apr 3, 20263mo ago

Trump proposes $707 million cut to CISA's FY2027 budget

On April 3, 2026, President Trump proposed cutting $707 million from CISA's fiscal year 2027 budget, framing the reduction as a refocus on the agency's core cybersecurity mission. The proposal would eliminate or reduce programs tied to misinformation, stakeholder engagement, international affairs, and other functions, raising concerns about weakened coordination with government and private-sector partners.

Trump wants to slash $707M from CISA's budget • The Register
Mar 2, 20264mo ago

Sean Plankey nominated as permanent CISA director

Sean Plankey was nominated to serve as CISA's permanent director, but his Senate confirmation remained pending and was reportedly delayed by demands to release a report on telecom cybersecurity flaws tied to Salt Typhoon activity.

CISA staffing cut by roughly one-third amid leadership turnover

Over the past year, CISA reportedly lost about one-third of its staff and also saw the departure of Chief Information Officer Bob Costello, prompting concerns about the agency's operational capacity and security posture.

Nick Andersen becomes CISA acting director after Madhu Gottumukkala

Nick Andersen replaced Madhu Gottumukkala as CISA's acting director following controversies during Gottumukkala's tenure, including reports involving sensitive document handling and a failed counterintelligence polygraph.

Partial DHS shutdown delays CIRCIA rulemaking progress

A partial U.S. government shutdown affecting the Department of Homeland Security stalled progress on CISA's cyber incident reporting rule, complicating compliance planning for critical infrastructure organizations.

Feb 27, 20264mo ago

Sen. Ron Wyden opposes Joshua Rudd's NSA/Cybercom nomination

Sen. Ron Wyden entered a letter into the Congressional Record opposing Army Lt. Gen. Joshua Rudd's nomination to lead the NSA and U.S. Cyber Command, arguing that Rudd lacks sufficient experience and understanding of constitutional rights for the role.

Feb 1, 20265mo ago

CISA seeks additional feedback on draft CIRCIA rule

In February 2026, CISA announced it was seeking additional feedback on its draft CIRCIA incident reporting rule, its first major update since industry comments were submitted in 2024.

Jan 28, 20265mo ago

CISA publishes insider threat management team guidance

On January 28, 2026, CISA released guidance titled "Assembling a Multi-Disciplinary Insider Threat Management Team" to help organizations build insider threat programs using its four-phase POEM framework.

Jan 26, 20265mo ago

CISA, FBI, and NSA withdraw from RSAC after Jen Easterly's hiring

Eight days after RSAC appointed former CISA Director Jen Easterly as CEO, CISA, the FBI, and the NSA withdrew from participation in the conference and their officials were removed from the event schedule. The move disrupted planned panels on public-private partnerships, incident response, and nation-state threats, marking a break from years of federal participation in RSAC.

Federal agencies abruptly pull out of RSAC after organizer hires Easterly | Cybersecurity Dive
Apr 1, 20251y ago

Gen. Timothy Haugh removed from NSA and Cyber Command leadership

Gen. Timothy Haugh was removed from leadership of the National Security Agency and U.S. Cyber Command in April 2025, leaving both organizations without a permanent chief for months.

Jun 1, 20242y ago

CISA receives industry comments on draft CIRCIA reporting rule

Industry comments on CISA's draft Cyber Incident Reporting for Critical Infrastructure Act rule were submitted in June 2024, marking a key step in the agency's incident reporting rulemaking process.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Affected products
2 linked
ChatgptChatgpt
Organizations
9 linked
GoogleThe RegisterCenter for Internet SecurityTechCrunchOpenaiRSA ConferenceNextgov/FCWCovington and BurlingBloomberg Law
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.