Members of Congress have formally requested that the Government Accountability Office (GAO) investigate the impact of significant staffing reductions at the Cybersecurity and Infrastructure Security Agency (CISA) on its operational capabilities and mission fulfillment. The request, spearheaded by Representative Bennie Thompson (D-MS), ranking member of the House Committee on Homeland Security, and several other Democratic representatives, highlights concerns that CISA's ability to protect critical infrastructure and respond to evolving cyber and physical threats has been compromised.
The congressional letter states that CISA has lost nearly one-third of its workforce since the beginning of the Trump administration, with approximately 1,000 employees having either been fired or voluntarily departed. This reduction raises serious questions about the agency's capacity at a time when adversaries are reportedly escalating attacks against critical infrastructure.
Despite acting director Nick Andersen's earlier announcement of plans to hire 300 new employees to address staffing gaps, the lawmakers expressed confusion regarding the administration's strategy. They noted that the fiscal year 2027 budget proposal includes the elimination of nearly 900 additional positions and a budget cut of over $700 million for CISA.
The letter also points out that little information is available on how the staffing cuts have affected CISA's operations and how the lost institutional knowledge has been replaced. Several key CISA leaders have departed in the past year, including David Stern, who was instrumental in a significant ransomware notification initiative.
Industry leaders and state and local officials have reportedly communicated to at least one Senator that they have experienced "reduced responsiveness and support" from CISA, indicating that "staffing turbulence at CISA has disrupted its service delivery and operations." These concerns are particularly salient ahead of the November election season, given the potential impact on municipal cybersecurity nationwide.
The congressional request references recent advisories from CISA, the FBI, and other federal agencies that underscore the increasing cyber threats targeting critical infrastructure organizations. These advisories have highlighted an "active threat" utilizing AI-generated exploit scripts, described as an "evolution" in attacker capabilities.
A GAO spokesperson, Sarah Kaczmarek, confirmed receipt of the congressional request, stating that the office is currently following its process to determine whether and when to undertake the requested work.
CISA has not had a confirmed director since Jen Easterly's departure at the end of the Biden administration. Nick Andersen recently assumed the acting director role after Madhu Gottumukkala was removed from the position in February following a series of undisclosed scandals. Shyam Sankar, a senior official at Palantir, has been identified as a leading contender for the permanent director role.






