The agency’s decision, spurred by workload concerns, could leave organizations without valuable insights into their vulnerabilities.
Eric Geller/Cybersecurity Dive
The Cybersecurity and Infrastructure Security Agency (CISA) is scaling back the free assessments it offers to critical infrastructure organizations, a move that marks a significant retreat from the agency’s core mission of helping secure the nation’s infrastructure.
CISA’s regional staff will no longer perform its Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Risk Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys, the agency confirmed to Cybersecurity Dive.
“CISA routinely evaluates our services and tools to make necessary changes to improve,” Chris Butera, the acting executive assistant director of CISA’s Cybersecurity Division, said in a statement. “To reduce redundancy for CISA and organizations requesting an assessment, CISA is retiring some legacy questionnaire assessments.”
James Harrell, the acting assistant director of CISA’s Integrated Operations Division, which houses the agency’s field staff, told division employees during an Aug. 25 meeting that they were expected to stop performing the assessments, a person familiar with the matter told Cybersecurity Dive. The person spoke on the condition of anonymity to discuss a sensitive matter.
The changes, first come as CISAstruggles to supportits partners in the critical infrastructure community after losingroughly one-third of its workforcesince the beginning of the second Trump administration
The curtailed cybersecurity services
The six assessments were some of the important services that CISA offered to infrastructure operators across the country. All of them involved CISA regional advisers meeting with infrastructure operators, asking them questions and helping them use the agency’sCyber Security Evaluation Tool(CSET) to generate reports with recommended security improvements. CISAregularly advertisedthe serviceswhile meetingwith state and local officials and infrastructure operators.
Cyber Resilience Reviewsaddress organizations’ ability to continue providing services during crises.External Dependencies Management Assessmentscover organizations’ practices for mitigating supply chain risks.Cyber Infrastructure Surveyscheck whether organizations have implemented the right security controls in several areas.Ransomware Risk Assessmentsevaluate organizations’ ability to contain an infection and keep operating during incident response.Incident Management Reviewsevaluate organizations’ ability to detect, analyze and contain intrusions.
CISA said it would point infrastructure operators to itsCross-Sector Cybersecurity Performance Goals(CPGs), which include a questionnaire that helps organizations identify resilience improvements. In his statement, CISA’s Butera said the CPGs shared the same “objectives and outcomes” as the “legacy assessments” and would lead to better nationwide data collection and comparison.
But the CPGs are not equivalent to the kind of interactive guidance that the assessments provided. The CPG structure “truly doesn’t add value,” the person familiar with the matter said. “It just identifies areas to assess with more advanced assessments.”
Jeff Greene, a former head of CISA’s Cybersecurity Division, said he didn’t understand the rationale for trying to replace the CSET-based assessments with the CPGs.
“CSET’s standards-focused [assessments] measure where you are,” he said. “You use the CPGs more to figure out where to focus your efforts. They work together.”
CSET is an open-erform the now-shuttered assessments, older versions can still walk organizations through those assessments and generate reports. Some organizations might choose to use old versions of CSET on their own, without CISA’s help interpreting the results
Overwhelmed CISA scales back
CISA’s relationships with many of its critical infrastructure partnershave significantly deterioratedsince the Trump administration beganslashing the agencyand pushing out the regional advisers who served as vital resources for utility operators and state and local officials. The elimination of CISA’s assessments could deepen those rifts and prompt more organizations to question the agency’s value.
“It’s just so damn depressing when people making decisions don’t have a clue how hard it is to help stakeholders without any tools,” said the person familiar with the matter.
Michael Daniel, who served as President Barack Obama’s White House cybersecurity coordinator, said the termination of the assessments reflected the Trump administration’s pattern of “reducing the federal government’s role in cybersecurity.”
“Since CISA provided these assessments at no charge, it’s not clear who can provide a similar service to this set of critical infrastructure owners and operators at a price they could afford,” said Daniel, now the president of the Cyber Threat Alliance, an industry coordination group. “The end result will likely be an increase in the nation’s overall cyber risk.”
Tatyana Bolton, the executive director of the OT Cyber Coalition, acknowledged that “severe budget cuts have forced CISA into a corner where they can no longer provide the level of hands-on, operational support to critical infrastructure that they once did.”
But with nation-state cybersecurity threats against infrastructure systems proliferating, Bolton added, “this is a deeply dangerous time to be scaling back direct assistance.”
Internal tensions hamstring CISA
CISA is eliminating the assessments because agency leaders have determined that they don’t provide enough value to justify their cost. The Integrated Operations Division (IOD) is the part of CISA that uses CSET during field engagements, but the agency’s Cybersecurity Division (CSD) develops the tool and updates it to incorporate new security best practices. CSD also processes the vast amount of data that CSET generates and provides comparative analyses to IOD, helping the regional staff understand broad trends in infrastructure resilience.
The person familiar with the matter said that CSD no longer wanted to do any of this work.
“Everyone is frustrated, because these are the ways we truly add value to our stakeholders,” the person said. “We have issues with one division telling us what we can and can’t do.”
“I don’t know if [acting CISA Director] Nick Andersen truly understands what the fallout will be if he truly decides to prevent us from doing these assessments,” the person added. “He may only understand from the CSD side, since that is where he came from.”
Filed Under:Strategy,Leadership & Careers,Policy & Regulation
