logo
‘People Are Scared': Inside CISA as It Reels From Trump's Purge

‘People Are Scared': Inside CISA as It Reels From Trump's Purge

WIRED13-03-2025
Mar 13, 2025 5:30 AM Employees at the Cybersecurity and Infrastructure Security Agency tell WIRED they're struggling to protect the US while the administration dismisses their colleagues and poisons their partnerships. Photo-illustration: WIRED Staff; Getty Images
Mass layoffs and weak leadership are taking a severe toll on the US government's cyber defense agency, undermining its ability to protect America from foreign adversaries bent on crippling infrastructure and ransomware gangs that are bleeding small businesses dry.
Inside the Cybersecurity and Infrastructure Security Agency, vital support staff are gone, international partnerships have been strained, and workers are afraid to discuss threats to democracy that they're now prohibited from countering. Employees are even more overworked than usual, and new assignments from the administration are interfering with important tasks. Meanwhile, CISA's temporary leader is doing everything she can to appease President Donald Trump, infuriating employees who say she's out of touch and refusing to protect them.
'You've got a lot of people who … are looking over their shoulder as opposed to looking at the enemy right now,' says one CISA employee.
As the Trump administration's war on the federal bureaucracy throws key agencies into chaos, CISA's turmoil could have underappreciated consequences for national security and economic prospects. The agency, part of the Department of Homeland Security, has steadily built a reputation as a nonpartisan source of funding, guidance, and even direct defensive support for cities, businesses, and nonprofits reeling from cyberattacks. That mission is now under threat, according to interviews with seven CISA employees and another person familiar with the matter, all of whom requested anonymity to avoid reprisals.
'Our enemies are not slowing their continuous assaults on our systems,' says Suzanne Spaulding, who led CISA's predecessor during the Obama administration. 'We need all hands on deck and focused, not traumatized and distracted.' Talent Exodus
CISA's mission has grown significantly since its creation in 2018. Established mainly to defend government networks, the agency increasingly embraced new roles supporting private companies and state governments, advocating for secure software, and cooperating with foreign partners. This helped CISA raise its profile and gain credibility. But now, following several rounds of layoffs and new restrictions from the Trump administration, the agency is struggling to sustain its momentum.
The extent of the cuts at CISA is still unclear—employees are only learning about the loss of colleagues through word of mouth—but multiple employees estimate that, between the layoffs and the Office of Personnel Management's deferred-resignation program, CISA has lost between 300 and 400 staffers—roughly 10 percent of its 3,200-person workforce. Many of those people were hired through DHS's Cybersecurity Talent Management System (CTMS), a program designed to recruit experts by competing with private-sector salaries. As a result, they were classified as probationary employees for three years, making them vulnerable to layoffs. These layoffs at CISA also hit longtime government workers who had become probationary by transferring into CTMS roles.
Key employees who have left include Kelly Shaw, who oversaw one of CISA's marquee programs, a voluntary threat-detection service for critical infrastructure operators; David Carroll, who led the Mission Engineering Division, the agency's technological backbone; and Carroll's technical director, Duncan McCaskill. 'We've had a very large brain drain,' an employee says.
The departures have strained a workforce that was already stretched thin. 'We were running into [a] critical skills shortage previously,' says a second employee. 'Most people are and have been doing the work of two or more full-time [staffers].'
The CISA team that helps critical infrastructure operators respond to hacks has been understaffed for years. The agency added support positions for that team after a Government Accountability Office audit, but 'most of those people got terminated,' a third employee says.
CISA's flagship programs have been mostly unscathed so far. That includes the threat-hunting branch, which analyzes threats, searches government networks for intruders, and responds to breaches. But some of the laid-off staffers provided crucial 'backend' support for threat hunters and other analysts. 'There's enhancements that could be made to the tools that they're using,' the first employee says. But with fewer people developing those improvements, 'we're going to start having antiquated systems.'
In a statement, DHS spokesperson Tricia McLaughlin says CISA remains 'committed to the safety and security of the nation's critical infrastructure' and touted 'the critical skills that CISA experts bring to the fight every day.'
National Security Council spokesperson James Hewitt says the reporting in this story is 'nonsense,' adding that 'there have been no widespread layoffs at CISA and its mission remains fully intact.'
'We continue to strengthen cybersecurity partnerships, advance AI and open-source security, and protect election integrity,' Hewitt says. 'Under President Trump's leadership, our administration will make significant strides in enhancing national cybersecurity.' Partnership Problems
CISA's external partnerships—the cornerstone of its effort to understand and counter evolving threats—have been especially hard-hit.
International travel has been frozen, two employees say, with trips—and even online communications with foreign partners—requiring high-level approvals. That has hampered CISA's collaboration with other cyber agencies, including those of 'Five Eyes' allies Canada, Australia, New Zealand, and the UK, staffers say.
CISA employees can't even communicate with people at other federal agencies the way they used to. Previously routine conversations between CISA staffers and high-level officials elsewhere now need special permissions, slowing down important work. 'I can't reach out to a CISO about an emergency situation without approval,' a fourth employee says.
Meanwhile, companies have expressed fears about sharing information with CISA and even using the agency's free attack-monitoring services due to DOGE's ransacking of agency computers, according to two employees. 'There is advanced concern about all of our services that collect sensitive data,' the third employee says. 'Partners [are] asking questions about what DOGE can get access to and expressing concern that their sensitive information is in their hands.'
'The wrecking of preestablished relationships will be something that will have long-lasting effects,' the fourth employee says.
CISA's Joint Cyber Defense Collaborative, a high-profile hub of government-industry cooperation, is also struggling. The JCDC currently works with more than 300 private companies to exchange threat information, draft defensive playbooks, discuss geopolitical challenges, and publish advisories. The unit wants to add hundreds more partners, but it has 'had difficulty scaling this,' the first employee says, and recent layoffs have only made things worse. Contractors might be able to help, but the JCDC's 'vendor support contracts run out in less than a year,' the employee says, and as processes across the government have been frozen or paused in recent weeks, CISA doesn't know if it can pursue new agreements. The JCDC doesn't have enough federal workers to pick up the slack, the fourth CISA employee says.
With fewer staffers to manage its relationships, the JCDC confronts a perilous question: How should it focus its resources without jeopardizing important visibility into the threat landscape? Emphasizing ties with major companies might be more economical, but that would risk overlooking mid-sized firms whose technology is quietly essential to vital US industries.
'CISA continuously evaluates how it works with partners,' McLaughlin says, 'and has taken decisive action to maximize impact while being good stewards of taxpayer dollars and aligning with Administration priorities and our authorities.' Gutting Security Advocacy
Other parts of CISA's mission have also begun to atrophy.
During the Biden administration, CISA vowed to help the tech industry understand and mitigate the risks of open-source software, which is often poorly maintained and has repeatedly been exploited by hackers. But since Trump took office, CISA has lost the three technical luminaries who oversaw that work: Jack Cable, Aeva Black, and Tim Pepper. Open-source security remains a major challenge, but CISA's efforts to address that challenge are now rudderless.
The new administration has also frozen CISA's work on artificial intelligence. The agency had been researching ways to use AI for vulnerability detection and networking monitoring, as well as partnering with the private sector to study AI risks. 'About 50 percent of [CISA's] AI expert headcount has been let go,' says a person familiar with the matter, which is 'severely limiting' CISA's ability to help the US Artificial Intelligence Safety Institute test AI models before deployment.
The administration also pushed out CISA's chief AI officer, Lisa Einstein, and closed down her office, the person familiar with the matter says. Einstein's team oversaw CISA's use of AI and worked with private companies and foreign governments on AI security.
A large team of DHS and CISA AI staffers was set to accompany Vice President JD Vance to Paris in February for an AI summit, but those experts 'were all pulled back' from attending, according to a person familiar with the matter.
'Nefarious' Retribution
CISA staffers are still reeling from the agency's suspension of its election security program and the layoffs of most people who worked on that mission. The election security initiative, through which CISA provided free services and guidance to state and local officials and worked with tech companies to track online misinformation, became a target of right-wing conspiracy theories in 2020, which marked it for death after Trump's return to the White House.
The program—on hold pending CISA's review of a recently completed internal assessment—was a tiny part of CISA's budget and operations, but the campaign against it has alarmed agency employees. 'This is definitely in the freak-out zone,' says the first employee, who adds that CISA staffers across the political spectrum support the agency's efforts to track online misinformation campaigns. 'All of us recognize that this is a common deception tactic of the enemy.'
The election security purge rippled across the agency, because some of the laid-off staffers had moved from elections to other assignments or were simultaneously working on both missions. Geoff Hale, who led the elections team between 2018 and 2024, was serving as the chief of partnerships at the JCDC when he was placed on administrative leave, setting off a scramble to replace him.
The removal of Hale and his colleagues 'was the start to a decline in morale' at CISA, according to the second employee. Now, staffers are afraid to discuss certain topics in public forums: 'No one's going to talk about election security right now,' the first employee says.
'The fact that there's retribution from the president … is kind of frightening,' this employee adds. 'A very nefarious place to be.' Abandoned and Demoralized
The layoffs, operational changes, and other disruptions at CISA have severely depleted morale and undermined the agency's effectiveness. 'Even simple tasks feel hard to accomplish because you don't know if your teammates won't be here tomorrow,' says the fourth employee.
The biggest source of stress and frustration is acting CISA director Bridget Bean, a former Trump appointee who, employees say, appears eager to please the president even if it means not defending her agency. Bean 'just takes whatever comes down and implements [it] without thought of how it will affect [CISA's] mission,' the fifth employee says. Employees describe her as a poor leader and ineffective communicator who has zealously enacted Trump's agenda. In town-hall meetings with employees, Bean has said CISA must carefully review its its authorities and urged staffers to 'assume noble intent' when dealing with Trump officials. While discussing Elon Musk's mass-buyout program, she allegedly said, 'I like to say 'Fork in the Road' because it's kind of fun,.' according to the fourth employee. She was so eager to comply with Musk's 'What did you do last week?' email that she instructed staffers to respond to it before DHS had finalized its department-wide approach. DHS later told staff not to respond, and Bean had to walk back her directive.
'Bean feels like she's against the workforce just to please the current administration,' the second employee says. The fourth employee describes her as 'not authentic, tone-deaf, spineless, [and] devoid of leadership.'
McLaughlin, the DHS spokesperson, says CISA 'is not interested in ad hominem attacks against its leadership,' which she says 'has doubled down on openness and transparency with the workforce.'
The return-to-office mandate has also caused problems. With all employees on-site, there isn't enough room in CISA's offices for the contractors who support the agency's staff. That has made it 'very difficult' to collaborate on projects and hold technical discussions, according to the first employee. 'There wasn't much thought about [RTO's] impact to operations,' says the fourth employee. According to a fifth employee, 'executing some of our sensitive operations is now harder.' ('CISA has worked tirelessly to make the return to office as smooth as possible from space to technology,' McLaughlin says.)
Employees are dealing with other stressors, too. They have no idea who's reading their Musk-mandated performance reports, how they're being evaluated, or whether AI is analyzing them for future layoffs. And there's a lot of new paperwork. 'The amount of extra shit we have to do to comply with the 'efficiency measures' … [takes] a lot of time away from doing our job,' says the fifth employee. Bracing for More
When Trump signed the bill creating CISA in November 2018, he said the agency's workforce would be 'on the front lines of our cyber defense' and 'make us, I think, much more effective.' Six and a half years later, many CISA employees see Trump as the biggest thing holding them back.
'This administration has declared psychological warfare on this workforce,' the fourth employee says.
With CISA drawing up plans for even larger cuts, staffers know the chaos is far from over.
'A lot of people are scared,' says the first employee. 'We're waiting for that other shoe to drop. We don't know what's coming.'
Entire wings of CISA—like National Risk Management Center and the Stakeholder Engagement Division—could be on the chopping block. Even in offices that survive, some of the government's most talented cyber experts—people who chose public service over huge sums of money and craved the lifestyle of CISA's now-eliminated remote-work environment—are starting to see their employment calculus differently. Some of them will likely leave for stabler jobs, further jeopardizing CISA's mission. 'What is the organization going to be capable of doing in the future?' the first employee asks.
If Trump's confrontational foreign-policy strategy escalates tensions with Russia, China, Iran, or North Korea, it's likely those nations could step up their use of cyberattacks to exact revenge. In that environment, warns Nitin Natarajan, CISA's deputy director during the Biden administration, weakening the agency could prove very dangerous.
'Cuts to CISA's cyber mission,' Natarajan says, 'will only negatively impact our ability to not only protect federal government networks, but those around the nation that Americans depend on every day.'
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Why Cleveland-Cliffs Stock Is Red-Hot Today
Why Cleveland-Cliffs Stock Is Red-Hot Today

Yahoo

time12 minutes ago

  • Yahoo

Why Cleveland-Cliffs Stock Is Red-Hot Today

Key Points Cleveland-Cliffs reported smaller-than-expected losses this morning. Steel prices fell in Q2, but management is cutting costs to mitigate the damage. With a little help from President Trump's tariffs, Cleveland-Cliffs could turn profitable again. 10 stocks we like better than Cleveland-Cliffs › Shares of Cleveland-Cliffs (NYSE: CLF), one of the nation's biggest steelmakers, soared 13.7% through 1:20 p.m. ET Monday after beating on earnings this morning. Analysts had forecast a rough quarter for Cleveland-Cliffs, with $0.63 per share in losses expected on sales of $4.9 billion. The company nailed the revenue target, and beat on earnings with a loss of "only" $0.50 per share. Cleveland-Cliffs' Q2 earnings Cleveland-Cliffs set a new record for steel shipped in the quarter: 4.3 million net tons, up 7.5% from a year ago. Average selling prices on that steel, however, slid 10%, turning what should have been a revenue improvement into a decline -- and turning its gross profit margin negative. On the bottom line, Cleveland-Cliffs ended up with $470 million in net losses, or $0.97 per share, reversing the tiny profit it earned in Q2 2024. Is Cleveland-Cliffs stock a buy? But if Cleveland-Cliff's news was so bad, why are investors buying the stock? Partly because management said $323 million of its net loss -- about 69% -- came from "previously disclosed non-recurring charges related to idled facilities." And partly, because management says it's making progress cutting both costs and inventories. Turning to guidance, Cleveland-Cliffs notes that it's on track to cut its 2025 cost of production by about $50 a ton in comparison to 2024 -- enough to offset about half the decline in steel prices seen in Q2. Combined with reductions in capital spending and in selling, general, and administrative expenses, plus the absence of the "non-recurring charges" that hurt Q2 results, and of course the benefits Cleveland-Cliffs might enjoy from Trump administration tariffs on imported steel, there's every chance profits will perk back up soon. Management didn't quite promise this, mind you. But investors seem to be betting on it. Should you buy stock in Cleveland-Cliffs right now? Before you buy stock in Cleveland-Cliffs, consider this: The Motley Fool Stock Advisor analyst team just identified what they believe are the for investors to buy now… and Cleveland-Cliffs wasn't one of them. The 10 stocks that made the cut could produce monster returns in the coming years. Consider when Netflix made this list on December 17, 2004... if you invested $1,000 at the time of our recommendation, you'd have $652,133!* Or when Nvidia made this list on April 15, 2005... if you invested $1,000 at the time of our recommendation, you'd have $1,056,790!* Now, it's worth noting Stock Advisor's total average return is 1,048% — a market-crushing outperformance compared to 180% for the S&P 500. Don't miss out on the latest top 10 list, available when you join Stock Advisor. See the 10 stocks » *Stock Advisor returns as of July 21, 2025 Rich Smith has no position in any of the stocks mentioned. The Motley Fool has no position in any of the stocks mentioned. The Motley Fool has a disclosure policy. Why Cleveland-Cliffs Stock Is Red-Hot Today was originally published by The Motley Fool

World Cup Windfall: $3.3 Billion Jackpot Coming to New York and New Jersey
World Cup Windfall: $3.3 Billion Jackpot Coming to New York and New Jersey

Yahoo

time12 minutes ago

  • Yahoo

World Cup Windfall: $3.3 Billion Jackpot Coming to New York and New Jersey

New York and New Jersey could be on the verge of a multi-billion-dollar economic lift from hosting the FIFA World Cup in 2026. The region is set to host eight matches, including the final on July 19 at MetLife Stadium, with more than 1.2 million fans expected to pour into the area. According to the NYNJ Host Committee, total spending across the region could reach $1.7 billion, driving $1.3 billion in projected labor income. Investors looking at hospitality, infrastructure, and consumer-facing sectors may want to start connecting the dots. The job creation potential is also noteworthy. The committee projects over 26,000 jobs will be added across both states to support the event, spanning everything from stadium operations and tourism to food, transit, and event logistics. Meanwhile, state and local governments are expected to see a combined $432 million in tax revenue. With matches spread across 11 other U.S. citiesBoston, Dallas, Los Angeles, and Philadelphia among themthis could turn into a nationwide economic moment. Companies like Tesla (NASDAQ:TSLA), Uber (NYSE:UBER), Marriott (NASDAQ:MAR), and major streaming platforms could see indirect tailwinds depending on how the tournament footprint expands. Political dynamics are already mixing into the narrative. President Donald Trump, speaking during a FIFA task force session earlier this year, didn't shy away from the tension his trade policies might create. Tensions are a good thing, he said, suggesting the geopolitical backdrop could make the tournament even more electric. For investors, this isn't just about soccerit's a potential demand wave across labor, travel, and consumption that could ripple through public markets. The magnitude remains to be seen, but the setup is worth tracking. This article first appeared on GuruFocus. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

The history of Native American sports name changes, from the Obama era to Trump's latest comments
The history of Native American sports name changes, from the Obama era to Trump's latest comments

Yahoo

time12 minutes ago

  • Yahoo

The history of Native American sports name changes, from the Obama era to Trump's latest comments

President Donald Trump's social media posts calling for the NFL's Washington Commanders and Major League Baseball's Cleveland Guardians to revert to their old names has revived the conversation about Native American imagery in sports. Each team has indicated it has no plans to go back to names that were abandoned years ago in the aftermath of a reckoning over racial injustice, iconography and racism in the U.S. following the death of George Floyd. Other professional teams have maintained names and logos through criticism and calls from activists who say they are offensive. Here is a look at how the issue has unfolded: October 2013 Then-President Barack Obama told The Associated Press he would 'think about changing' the name of the Washington Redskins if he owned the team. 'I don't know whether our attachment to a particular name should override the real legitimate concerns that people have about these things,' Obama said. Donald Trump soon after posted to Twitter: 'President should not be telling the Washington Redskins to change their name-our country has far bigger problems! FOCUS on them,not nonsense.' January 2018 The Cleveland Indians announced they would remove the Chief Wahoo logo from their uniforms the following year after decades of protests and complaints that the grinning, red-faced caricature used in one version or another since 1947 is racist. 'Major League Baseball is committed to building a culture of diversity and inclusion throughout the game,' Commissioner Rob Manfred said in a statement. He said the logo 'is no longer appropriate for on-field use.' The team said it would continue to sell merchandise with the logo in the Cleveland area. Summer 2020 After several sponsors publicly voiced their opposition to the name Redskins, longtime owner Dan Snyder said in early July the organization would undergo a 'thorough review." Snyder had said multiple times since buying the team in 1999 that he had no intent of changing it. Cleveland hours later said it was considering going away from Indians, the baseball team's name since 1915. Manager Terry Francona said he was in favor of a change. On July 13, Snyder announced the Redskins moniker was being retired after 87 years, dating to the team's time in Boston. Later in the month, the organization unveiled plans to be known as the Washington Football Team for at least one season, and that name remained through 2021. MLB's Atlanta Braves and the NHL's Chicago Blackhawks doubled down on their names. The Braves wrote in a letter to season-ticket holders they will 'always be' known as that, while the Blackhawks said they would continue to use their name and logo because it honors Native American leader Black Hawk of Illinois' Sac & Fox Nation. The Braves said they were reviewing the use of the tomahawk chop and chant, a discussion they started with Native American leaders in 2019. The Blackhawks banned headdresses at home games. In August, the NFL's Kansas City Chiefs followed suit, prohibiting the use of Native American headdresses, face paint and clothing at their stadium. They faced increased scrutiny over the tomahawk chop and chant around winning their first Super Bowl title that February. December 2020 Cleveland owner Paul Dolan announced the team would no longer be called the Indians following the 2021 season. 'It was a learning process for me and I think when fair-minded, open-minded people really look at it, think about it and maybe even spend some time studying it, I like to think they would come to the same conclusion: It's a name that had its time, but this is not the time now, and certainly going forward, the name is no longer acceptable in our world,' Dolan told the AP, adding he did not want an interim moniker like Washington's. Trump quote-tweeted a story about the change with the message: 'Oh no! What is going on? This is not good news, even for 'Indians'. Cancel culture at work!' July 2021 Seemingly out of the blue, Cleveland unveiled its new name, Guardians, in a video posted to social media. They completed the season as the Indians before becoming the Guardians in November. Cleveland's new name was inspired by the large landmark stone edifices — referred to as traffic guardians — that flank both ends of the Hope Memorial Bridge, which connects downtown to Ohio City. October 2021 The tomahawk chop was front and center as the Braves reached — and won — the World Series, with MLB Commissioner Rob Manfred endorsing the fan behavior, citing the support of the Eastern Band of Cherokee Indians, based in North Carolina about three hours from Atlanta. 'The Native American community in that region is wholly supportive of the Braves program, including the chop,' Manfred said. 'For me, that's kind of the end of the story. In that market, we're taking into account the Native American community.' February 2022 After a lengthy process, Washington rebranded as the Commanders. Snyder said the change pays 'homage to our local roots and what it means to represent the nation's capital.' 'As we kick off our 90th season, it is important for our organization and fans to pay tribute to our past traditions, history, legacy and the greats that came before us,' Snyder said. 'We continue to honor and represent the burgundy and gold while forging a pathway to a new era in Washington.' President Joe Biden welcomed the name change by posting a picture on Twitter of Commander, his recently acquired German shepherd puppy, in front of the White House. 'I suppose there's room for two Commanders in this town,' Biden wrote. Summer 2023 A group led by Josh Harris, which included Basketball Hall of Famer Magic Johnson, finalized the purchase of the Commanders from Snyder for a North American pro sports record $6.05 billion. Harris and co-owner Mitch Rales, who grew up in the area of the team, used the word Redskins at their introductory news conference, sparking renewed chatter about the subject. Before the season started, Harris said ownership would not be going back to the old name. Summer 2024 Sen. Steve Daines, a Montana Republican, threatened to block a congressional bill to transfer land to potentially be used for a new football stadium in Washington unless the Commanders and the NFL honored the former Indian head logo in some way. The original logo was designed by a member of the Blackfeet Nation in Montana. After lobbying on Capitol Hill by Harris and Commissioner Roger Goodell, the bill passed in December at the eleventh hour, and Biden signed it into law in January. It gave control of the RFK Stadium site from the federal government to the District of Columbia, which agreed to a deal with the team in April to build there, pending city council approval. February 3, 2025 After Washington made the playoffs and went on an improbable run to the NFC championship game with Offensive Rookie of the Year quarterback Jayden Daniels, Harris said at his season-ending news conference that the Commanders name was here to stay, quieting speculation about another rebrand. 'I think it's now being embraced by our team, by our culture, by our coaching staff, so, we're going with that,' Harris said. 'Now, in this building, the name Commanders means something. It's about players who love football, are great at football, hit hard, mentally tough, great teammates. It's really meaningful that that name is growing in meaning.' July 20, 2025 With the stadium deal not yet done, Trump threatened to block it if Washington did not go back to the name Redskins. Trump on his social media site posted: 'I won't make a deal for them to build a Stadium in Washington." Asked about ways Trump could block the construction of a stadium where the team played during its glory days until moving to Maryland, Washington Mayor Muriel Bowser shifted the focus to hammering out a deal voted on by the council. 'What I'm concerned about is we haven't done our part, and so we need to complete our part so that the team can get to work, so that local businesses can get hired, so that we can start earning the tax revenue that will come when we deliver the Commanders stadium," Bowser said. ___ AP sports:

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store