Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cybersecurity-regulationwidely-deployed-product-advisorystandards-framework-update

DHS Shutdown and Leadership Vacuum Deepen Concerns Over CISA Staffing and Mission Capacity

Updated 27d agoFirst seen Mar 19, 202641 sources

Senators and cybersecurity experts warned that CISA is operating under growing strain as the Department of Homeland Security shutdown and the absence of stable leadership compound earlier cuts to the agency’s workforce and budget. During his confirmation hearing, DHS secretary nominee Markwayne Mullin was pressed on whether he would restore staffing and funding after roughly one-third of CISA’s workforce was cut, but he declined to commit to rehiring personnel or reversing budget reductions, saying only that the agency would be staffed to remain mission capable.

Security professionals said CISA can still perform its core statutory functions with excepted staff, but the loss of personnel, sidelining of employees during the shutdown, and lack of a permanent director are limiting the agency’s ability to sustain non-essential programs, build new capabilities, and advocate for long-term resources. Even as CISA continues to issue operational guidance, including recent warnings tied to Microsoft Intune hardening and patching of vulnerabilities in products such as Synacor Zimbra Collaboration Suite and Microsoft Office, the broader concern is that reduced staffing and weakened leadership are eroding national cyber defense capacity at a time of elevated threat pressure.

Share:
DHS Shutdown and Leadership Vacuum Deepen Concerns Over CISA Staffing and Mission Capacity
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

27 events from the most recent confirmed update back to the earliest known activity.

27 EVENTS
May 27, 202627d ago

CISA leadership exodus leaves most top posts vacant or departing

Cybersecurity Dive reported that nearly all of CISA's top officials had departed or were scheduled to leave by the end of May 2026, according to an internal email from deputy director Madhu Gottumukkala. The departures affected five of the agency's six operational divisions and six of its 10 regional offices, prompting warnings about lost expertise, continuity, and support for critical infrastructure and government partners.

CISA loses nearly all top officials as purge continues | Cybersecurity Dive
May 22, 20261mo ago

CISA names Ryan Donaghy as its first chief operating officer

CISA announced that Ryan Donaghy returned to the agency from the Transportation Security Administration to serve as its first chief operating officer. In the new role, he will advise senior leadership on operations, business functions, financial and acquisition management, policy development, and interagency coordination during a period of restructuring and budget pressure.

Ryan Donaghy returns to CISA as first chief operating officer - Nextgov/FCW

House hearing spotlights state and local fallout from federal cyber cuts

At a House Homeland Security subcommittee hearing, Democratic lawmakers and witnesses from Tennessee, New York, and Florida warned that proposed cuts to CISA, the State and Local Cybersecurity Grant Program, and federal support for MS-ISAC were weakening state and local cyber defenses. They urged Congress to reauthorize and fully fund state and local cybersecurity assistance amid rising ransomware, AI-enabled, and nation-state threats.

Dems slam Trump cyber cuts amid ballroom, Jan. 6 'slush fund'
May 21, 20261mo ago

Bipartisan lawmakers warn CISA cuts have gone too far

Rep. Don Bacon and Rep. James Walkinshaw publicly said recent staffing and budget reductions have weakened CISA’s ability to defend domestic networks, critical infrastructure, utilities, and local governments against nation-state threats. They pointed to personnel losses, shuttered divisions, proposed FY2027 cuts, and the lack of a Senate-confirmed director as undermining CISA’s coordination and victim-support role.

Lawmakers from both parties say CISA cuts have gone too far | CyberScoop
May 18, 20261mo ago

Tom Parker emerges as leading candidate for CISA director

Tom Parker of IBM Security was reported as a leading candidate to become CISA director, reportedly favored by Homeland Security Secretary Markwayne Mullin for his private-sector experience. The development marked a potential step toward filling CISA's leadership vacancy after Sean Plankey's nomination became nonviable.

IBM executive floated for CISA director as concerns persist for agency | news | SC Media
May 8, 20262mo ago

Sen. Mark Warner presses DHS over CISA election security rollbacks

Sen. Mark Warner sent a letter to Homeland Security Secretary Markwayne Mullin warning that cuts to CISA's election security mission could leave states and localities without adequate cyber defense and threat intelligence support before the 2026 midterms. He requested details on remaining personnel, programs, assistance requests, trainings, tabletop exercises, and any internal review of election security work.

US Senator Presses CISA on Election Security Rollbacks
May 5, 20262mo ago

CISA launches CI Fortify resilience initiative

CISA announced its new CI Fortify initiative to help critical infrastructure organizations maintain essential services during cyberattacks and possible geopolitical conflict. The guidance emphasized isolation and recovery capabilities, though the rollout reportedly lacked specific objectives, timelines, funding, or new resources.

Health-ISAC Hacking Healthcare 5-11-2026
Apr 30, 20262mo ago

House vote ends 75-day DHS shutdown and restores CISA funding

A bipartisan House vote ended the record 75-day Department of Homeland Security shutdown, restoring funding for DHS components including CISA. The fiscal 2026 Homeland Security package provided $64.4 billion in discretionary DHS funding and included $20 million for critical CISA hiring focused on countering threats from China.

DHS Shutdown Ends as CISA Faces Long Recovery
Apr 17, 20262mo ago

CISA cancels summer cyber scholarship intern onboarding during shutdown

Because of the DHS funding lapse, CISA canceled onboarding for summer interns in a government cyber scholarship program, reflecting a direct hit to the agency's workforce development pipeline. The move came as Acting Director Nick Andersen said the shutdown was restricting preparatory work, outreach, and non-salary spending.

CISA resources ‘more limited than I would like’ amid shutdown, top official says - Nextgov/FCW
Apr 16, 20262mo ago

Andersen presents $2.5 billion CISA budget amid shutdown strain

CISA Acting Director Nick Andersen told the House Appropriations Subcommittee on Homeland Security that the agency's proposed $2.5 billion budget is meant to stabilize and scale CISA's mission despite the prolonged DHS shutdown. He said the shutdown had reduced CISA to about 40% staffing capacity, harming federal network defense, while the agency sought funding for cyber operations, infrastructure resilience, emergency communications, the National Risk Management Center, and hiring for 329 critical positions.

CISA Warns of 'Detrimental Capacity Impacts' Amid Shutdown
Apr 3, 20263mo ago

Trump FY2027 budget proposal seeks further cuts to CISA

The Trump administration's fiscal 2027 budget proposal called for another major reduction in CISA funding, with budget documents indicating cuts ranging from $361 million to $707 million depending on the baseline used. The proposal would reduce CISA discretionary funding to just over $2 billion and frame the cuts as a refocusing on federal network defense and critical infrastructure resilience.

Trump budget proposal would cut hundreds of millions more from CISA | CyberScoop
Mar 25, 20263mo ago

CISA acting chief warns Congress shutdown is driving resignations

CISA Acting Director Nick Andersen told Congress that the DHS shutdown is degrading the agency’s ability to manage cyber risk, with about 60% of staff furloughed, roughly 1,000 vacancies, and recent resignations among key technical personnel. He said CISA is largely limited to mission-essential functions while proactive risk-reduction work has been paused, creating exploitable gaps and longer-term recruiting and retention damage.

CISA's acting chief warns shutdown is increasing cyber risks, causing resignations | The Record from Recorded Future News
Mar 19, 20263mo ago

Experts warn DHS shutdown and leadership gap increase cyber risk

Cybersecurity experts publicly warned that CISA's lack of permanent leadership during the DHS shutdown would weaken political influence, long-term planning, threat prioritization, and public messaging. They said the prolonged gap could create exploitable openings for adversaries including China, Iran, North Korea, and Russia.

CISA urges patching of exploited Zimbra and SharePoint flaws

CISA also recently warned agencies to patch actively exploited vulnerabilities affecting Synacor Zimbra Collaboration Suite and Microsoft Office SharePoint. The guidance reflected continued focus on urgent defensive measures even as non-essential programs were curtailed.

CISA issues Microsoft Intune guidance after Iran-linked Stryker attack

Despite staffing constraints, CISA recently published guidance on securing Microsoft Intune following an Iran-linked cyberattack on medical device maker Stryker. The action showed the agency continuing core operational work during the leadership and shutdown turmoil.

Sean Plankey's nomination for CISA director becomes nonviable

The SC Media report states that Sean Plankey's nomination to lead CISA was no longer viable, leaving the agency without a confirmed permanent director. This contributed to concerns about weakened leadership, funding prospects, and strategic continuity.

Mar 18, 20263mo ago

Senators press DHS nominee Mullin on restoring CISA staffing

During a Senate Homeland Security Committee hearing, senators including Maggie Hassan and Gary Peters questioned DHS secretary nominee Markwayne Mullin about whether he would reverse cuts to CISA. Mullin did not commit to restoring previous staffing or funding levels, saying only that the agency should be adequately staffed with the right personnel.

CISA staffing and budget cuts reduce agency capacity

CISA underwent significant workforce reductions, budget cuts, and rollbacks of programs tied to election security, cyber grants, and vulnerability tracking. By the time of the reported DHS shutdown, the agency was operating with roughly one-third of its staff and only essential functions remained active.

Mar 2, 20264mo ago

Leader of CISA federal cyber defense programs resigns

Federal News Network reported that the official leading CISA's federal cyber defense programs resigned from the agency amid broader leadership turmoil and workforce disruption. The departure added to concerns about instability in one of CISA's core operational missions shortly after DHS replaced the acting director.

Leader of federal cyber defense programs resigns from CISA | Federal News Network
Feb 27, 20264mo ago

DHS removes Madhu Gottumukkala and names Nick Andersen acting CISA director

The Department of Homeland Security removed Madhu Gottumukkala as acting director of CISA and reassigned him to DHS headquarters, replacing him with Nick Andersen as acting director. The move followed controversy around Gottumukkala's tenure and was seen by some employees and officials as a chance to stabilize agency leadership.

Trump administration removes controversial acting CISA director | Cybersecurity Dive
Feb 26, 20264mo ago

DHS reassigns two senior CISA officials after attempted ouster

Politico reported that two senior CISA officials were reassigned amid internal turmoil following an earlier attempted ouster. The move signaled escalating leadership disruption at the agency immediately before DHS replaced acting director Madhu Gottumukkala.

Two senior CISA officials reassigned after earlier attempted ouster - POLITICO
Jan 13, 20265mo ago

Trump re-nominates Sean Plankey for CISA director

President Donald Trump re-nominated Sean Plankey to lead CISA after the agency had gone nearly a year without a Senate-confirmed director. The move revived a nomination that had bipartisan and industry backing, though it remained entangled in Senate holds unrelated in part to cybersecurity.

CISA director void leaves cyber agency embroiled in uncertainty | Federal News Network
Oct 23, 20258mo ago

Report blames Trump workforce cuts for weakening US cyber edge

A report published in October 2025 said Trump administration workforce reductions were dulling America's cybersecurity advantage, linking staffing cuts to reduced cyber capacity. The assessment broadened concern beyond CISA headcount losses to the wider impact on U.S. cyber readiness.

Trump's workforce cuts blamed as America's cyber edge dulls
Jul 25, 202511mo ago

JCDC support contract lapses, cutting over 100 contractor staff

A major support contract for CISA's Joint Cyber Defense Collaborative expired on July 25, causing the loss of more than 100 contractors, with only 10 temporarily retained through emergency funding. The lapse disrupted a key public-private cyber defense program responsible for incident coordination, risk assessments, exercises, and threat information sharing.

CISA’s Joint Cyber Defense Collaborative takes major personnel hit | Cybersecurity Dive
Jun 25, 20251y ago

Elimination of CIPAC disrupts critical infrastructure cyber partnerships

By June 2025, industry representatives and former officials said the Trump administration's elimination of the Critical Infrastructure Partnership Advisory Council, along with staffing cuts and canceled engagements, had frayed trusted cyber coordination between government and critical infrastructure sectors. The disruption affected information sharing and preparedness across sectors including healthcare, water, energy, and telecommunications.

‘Suspended animation’: US government upheaval has frayed partnerships with critical infrastructure | Cybersecurity Dive
Jun 4, 20251y ago

CISA workforce drops by about 1,000 amid Trump reduction efforts

By early June 2025, roughly 1,000 employees had departed CISA through buyouts, early retirements, layoffs, and DHS workforce transition measures, cutting staffing to about 2,200. Reports said the Cybersecurity Division and Cybersecurity Advisers field staff were among the hardest hit, raising concerns about reduced operational capacity.

CISA workforce cut by nearly one-third so far | Cybersecurity Dive
Feb 7, 20251y ago

Politico reports Trump purge is gutting federal cyber disinformation workers

Politico reported that the Trump administration was continuing a purge of federal cyber personnel, including workers involved in combating disinformation. The report marked an early public indication that cyber-focused staffing cuts were underway and affecting mission areas tied to information integrity and security.

Trump continues federal purge, gutting cyber workers who combat disinformation - POLITICO
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

35 LINKEDOpen in app
Threat actors
2 linked
Affected products
1 linked
Firefox
Organizations
31 linked
Nextgov/FCWLinkedinCenter for Democracy and TechnologyConduentStrykerKeeper SecurityMozillaCisco SystemsHubbleXcape IncBeyondtrustInternational Business MachinesBishop FoxRecorded FutureHealth Information Sharing and Analysis CenterMicrosoft CorporationSC MediaJamfiCounterNetSPICyberScoopSecure AnnexCyberRisk AllianceTokenDataTribeAverlonSuzu LabsSynacor, Inc.Merlin GroupPreviousSocketFairfax Water
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.