The Cybersecurity and Infrastructure Security Agency (CISA) is scaling back the free assessments it offers to critical infrastructure organizations, a move that marks a significant retreat from the agency’s core mission of helping secure the nation’s infrastructure.
CISA’s regional staff will no longer perform its Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Risk Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys, the agency confirmed to Cybersecurity Dive.
“CISA routinely evaluates our services and tools to make necessary changes to improve,” Chris Butera, the acting executive assistant director of CISA’s Cybersecurity Division, said in a statement. “To reduce redundancy for CISA and organizations requesting an assessment, CISA is retiring some legacy questionnaire assessments.”
James Harrell, the acting assistant director of CISA’s Integrated Operations Division, which houses the agency’s field staff, told division employees during an Aug. 25 meeting that they were expected to stop performing the assessments, a person familiar with the matter told Cybersecurity Dive. The person spoke on the condition of anonymity to discuss a sensitive matter.
The changes, first reported by Cybersecurity Dive, come as CISA struggles to support its partners in the critical infrastructure community after losing roughly one-third of its workforce since the beginning of the second Trump administration.
The curtailed cybersecurity services
The six assessments were some of the important services that CISA offered to infrastructure operators across the country. All of them involved CISA regional advisers meeting with infrastructure operators, asking them questions and helping them use the agency’s Cyber Security Evaluation Tool (CSET) to generate reports with recommended security improvements. CISA regularly advertised the services while meeting with state and local officials and infrastructure operators.
Cyber Resilience Reviews address organizations’ ability to continue providing services during crises. External Dependencies Management Assessments cover organizations’ practices for mitigating supply chain risks. Cyber Infrastructure Surveys check whether organizations have implemented the right security controls in several areas. Ransomware Risk Assessments evaluate organizations’ ability to contain an infection and keep operating during incident response. Incident Management Reviews evaluate organizations’ ability to detect, analyze and contain intrusions.
CISA said it would point infrastructure operators to its Cross-Sector Cybersecurity Performance Goals (CPGs), which include a questionnaire that helps organizations identify resilience improvements. In his statement, CISA’s Butera said the CPGs shared the same “objectives and outcomes” as the “legacy assessments” and would lead to better nationwide data collection and comparison.
But the CPGs are not equivalent to the kind of interactive guidance that the assessments provided. The CPG structure “truly doesn’t add value,” the person familiar with the matter said. “It just identifies areas to assess with more advanced assessments.”
Jeff Greene, a former head of CISA’s Cybersecurity Division, said he didn’t understand the rationale for trying to replace the CSET-based assessments with the CPGs.
“CSET’s standards-focused [assessments] measure where you are,” he said. “You use the CPGs more to figure out where to focus your efforts. They work together.”
CSET is an open-source tool, and while the latest version disables the ability to perform the now-shuttered assessments, older versions can still walk organizations through those assessments and generate reports. Some organizations might choose to use old versions of CSET on their own, without CISA’s help interpreting the results.
Overwhelmed CISA scales back
CISA’s relationships with many of its critical infrastructure partners have significantly deteriorated since the Trump administration began slashing the agency and pushing out the regional advisers who served as vital resources for utility operators and state and local officials. The elimination of CISA’s assessments could deepen those rifts and prompt more organizations to question the agency’s value.
“It's just so damn depressing when people making decisions don't have a clue how hard it is to help stakeholders without any tools,” said the person familiar with the matter.
Michael Daniel, who served as President Barack Obama’s White House cybersecurity coordinator, said the termination of the assessments reflected the Trump administration’s pattern of “reducing the federal government’s role in cybersecurity.”
“Since CISA provided these assessments at no charge, it’s not clear who can provide a similar service to this set of critical infrastructure owners and operators at a price they could afford,” said Daniel, now the president of the Cyber Threat Alliance, an industry coordination group. “The end result will likely be an increase in the nation’s overall cyber risk.”
Tatyana Bolton, the executive director of the OT Cyber Coalition, acknowledged that “severe budget cuts have forced CISA into a corner where they can no longer provide the level of hands-on, operational support to critical infrastructure that they once did.”
But with nation-state cybersecurity threats against infrastructure systems proliferating, Bolton added, “this is a deeply dangerous time to be scaling back direct assistance.”
Internal tensions hamstring CISA
CISA is eliminating the assessments because agency leaders have determined that they don’t provide enough value to justify their cost. The Integrated Operations Division (IOD) is the part of CISA that uses CSET during field engagements, but the agency’s Cybersecurity Division (CSD) develops the tool and updates it to incorporate new security best practices. CSD also processes the vast amount of data that CSET generates and provides comparative analyses to IOD, helping the regional staff understand broad trends in infrastructure resilience.
The person familiar with the matter said that CSD no longer wanted to do any of this work.
“Everyone is frustrated, because these are the ways we truly add value to our stakeholders,” the person said. “We have issues with one division telling us what we can and can't do.”
“I don't know if [acting CISA Director] Nick Andersen truly understands what the fallout will be if he truly decides to prevent us from doing these assessments,” the person added. “He may only understand from the CSD side, since that is where he came from.”