HackMyIP
← Back to News
2026-08-21 The Record

Lawmakers Demand GAO Probe CISA Staffing Cuts Impact on Critical Infrastructure

RegulationIncident ResponseThreat Intel

Senior Democratic members of Congress, led by House Homeland Security Committee ranking member Bennie Thompson (D-MS), have formally requested the Government Accountability Office (GAO) to investigate how sweeping staffing reductions at the Cybersecurity and Infrastructure Security Agency (CISA) have compromised the agency's ability to defend U.S. critical infrastructure. Since the Trump administration took office, nearly 1,000 CISA employees have been fired or have voluntarily departed, representing roughly one-third of the agency's workforce. Acting CISA Director Nick Andersen has announced plans to hire 300 new staff to address gaps left by the layoffs, but lawmakers warn the loss of institutional knowledge and senior leadership—including David Stern, the architect behind a key ransomware notification initiative—may already be undermining core mission capabilities.

In their letter, the lawmakers expressed alarm that the staffing reductions coincide with an accelerating threat landscape targeting critical infrastructure sectors. "At precisely the moment when our adversaries are accelerating attacks against critical infrastructure, [CISA]... has lost nearly one-third of its workforce, raising serious concerns about the agency's ability to fulfill its mission," the representatives wrote. The letter also highlighted confusion surrounding the administration's long-term strategy, noting that the proposed fiscal year 2027 budget seeks to eliminate nearly 900 additional CISA positions and cut more than $700 million from the agency—a plan that contradicts Department of Homeland Security Secretary Markwayne Mullin's stated commitment to rebuild CISA over the next year. Industry leaders and state officials have corroborated these concerns, reporting "reduced responsiveness and support" from CISA and "staffing turbulence" that has disrupted service delivery and operations. Organizations can audit their own external attack surfaces using tools like a port scanner to identify exposed services while federal agencies work to restore capacity.

GAO spokesperson Sarah Kaczmarek confirmed receipt of the congressional request, stating that the agency is currently working through its internal process to determine whether and when to initiate the review. CISA declined to comment on the letter. The congressional intervention comes amid recent joint advisories from CISA, the FBI, and other federal partners warning of an "active threat" targeting critical infrastructure organizations, intensifying pressure on the agency ahead of the November election season. With dozens of state officials and senior congressional leaders warning that the cuts could dangerously weaken municipal cybersecurity defenses, the GAO investigation could determine whether legislative action is needed to stabilize the nation's lead cyber defense agency. Security teams responsible for safeguarding infrastructure assets should proactively validate their network configurations and credential hygiene with resources such as a DNS leak test and a password checker to reduce exposure during this period of reduced federal support.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →