Cybersecurity at a Crossroads: CISA Cuts Assessment Programs Amid Escalating Infrastructure Threats

The Cybersecurity and Infrastructure Security Agency (CISA), the nation’s lead agency for safeguarding the critical systems that keep American society functioning, is facing a period of unprecedented turbulence. Following significant budget reductions and a persistent internal staffing crisis, the agency has confirmed the discontinuation of six vital, no-cost cybersecurity assessment programs previously offered to critical infrastructure operators.

This pivot arrives at a precarious moment. As the agency prepares to finalize the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)—which will impose stringent reporting mandates on operators—industry leaders are sounding the alarm. The simultaneous withdrawal of technical support and the imposition of new regulatory burdens have sparked a heated debate regarding the government’s role in securing the nation’s most vulnerable assets.

The Erosion of Support: A Chronology of Decline

To understand the current state of CISA’s operational capacity, one must look at the last 18 months of attrition. The agency, which serves as the primary conduit between federal intelligence and private sector operators, has seen its workforce shrink by approximately one-third.

  • Early 2023: CISA continues to advocate for a "Shields Up" posture, encouraging organizations to bolster their defenses against nation-state actors. However, internal morale and retention begin to falter as the agency struggles to compete with private sector salaries.
  • Late 2023 – Early 2024: Reports emerge of a "hiring freeze" and budgetary stagnation. Despite the Department of Homeland Security (DHS) announcing plans to recruit 600 new personnel, the actual onboard numbers remain significantly lower than the stated goals.
  • Summer 2024: CISA announces the retirement of six core assessment programs, including those focused on ransomware readiness, cyber resilience, and incident management.
  • August 2024: As the deadline for CIRCIA implementation approaches, industry experts express confusion over the agency’s strategy, noting that the removal of these tools leaves small-to-medium-sized utilities with few alternatives.

Supporting Data: The Widening Security Gap

The decision to cut these programs is particularly concerning given the sheer volume of entities that rely on them. According to industry estimates, there are over 50,000 small water utilities in the United States alone—the vast majority of which lack dedicated cybersecurity staff, let alone the budget to hire commercial managed security service providers (MSSPs).

While CISA has pointed stakeholders toward the Cross-Sector Cybersecurity Performance Goals (CPGs) as a replacement, security professionals argue that the CPGs are a framework, not a tool.

"CSET (Cyber Security Evaluation Tool) is open source, and older versions on GitHub still include all six retired assessment modules," explains Denis Calderone, CTO of Suzu Labs. "CSET measures where you actually stand against specific security standards. The CPGs that CISA is pointing everyone toward are a prioritization framework that helps you figure out where to focus. They’re complementary tools, not interchangeable ones."

The data suggests a disconnect between the agency’s top-down policy approach and the ground-level reality of resource-strapped municipalities. Without the CISA regional advisers who previously helped interpret these assessment results, many smaller organizations are effectively being left to interpret complex threat landscapes in a vacuum.

Security Leaders Weigh In: A Crisis of Timing

The cybersecurity community has been largely critical of the timing and the logic behind these cuts. The prevailing sentiment among industry experts is that the government is withdrawing its "helping hand" at the exact moment that threat actors are becoming more aggressive.

The Perspective of Denis Calderone (Suzu Labs)

Calderone, who has long directed resource-constrained entities toward CISA’s free offerings, expressed deep frustration. "My apologies to those I told to leverage these free resources recently," he noted. "We’ve been pointing those who lacked the bigger budgets to the CISA assessment programs. All six programs are gone now. The replacement is a self-service questionnaire that the people who built the original tools say doesn’t do the same job."

Calderone acknowledges that the efficacy of these programs was difficult to measure, noting that there is no public data proving how many operators actually used them or the impact they had on reducing risk. However, he emphasizes that the solution to a lack of data is better outreach, not the elimination of the service.

CISA Cuts Critical Infrastructure Security Resources

The Perspective of John Strand (Black Hills Information Security)

John Strand, owner of Black Hills Information Security, was more blunt in his assessment of the policy shift. "Do the people making these decisions have any access to the news?" he asked, pointing to the constant stream of reports regarding infrastructure attacks.

"Right now, our critical infrastructure is under attack at a level we simply have not seen before," Strand noted. "Water systems, energy, telecommunications, municipalities, and other critical infrastructure are actively being targeted. CISA itself warned in July about ongoing Iranian-affiliated attacks against operational technology (OT) and PLCs across multiple U.S. sectors. And this is the moment we decide to start cutting the programs designed to help these organizations defend themselves? This is crazy."

Implications for Critical Infrastructure

The removal of these programs carries significant, long-term implications for national security.

1. The "Regulatory Gap"

By finalizing CIRCIA—which requires incident reporting within 72 hours—without providing the means for entities to improve their security posture, the government may be setting up small utilities for failure. If an entity cannot afford an assessment, they are less likely to discover a vulnerability, which in turn leads to a reportable incident. The government is essentially mandating performance without providing the infrastructure to support it.

2. The Rise of Private and Local Initiatives

As the federal government retracts its support, the void is being filled by a patchwork of state and private initiatives. Programs like "Project Watershed 250," which recently launched in Texas to provide free vulnerability assessments and red-teaming for water utilities, may become the new model for regional security. However, this creates a "security lottery," where the quality of an entity’s protection depends entirely on their state of residence rather than a national standard.

3. Increased Vulnerability of Rural and Small-Scale Assets

Small municipalities are the "soft underbelly" of the American critical infrastructure. These entities are frequently the target of ransomware groups who know that a localized disruption to a water or electrical grid can cause significant societal panic. By pulling away resources, the government is effectively signaling that these smaller entities are on their own, potentially leading to a cascade of localized failures that could aggregate into a larger national crisis.

Looking Forward: Is Rebuilding Possible?

The path forward remains murky. While the agency has signaled a transition toward more scalable, automated tools like the CPGs, the consensus among experts is that human-led, hands-on assessments are irreplaceable for organizations that lack technical maturity.

For critical infrastructure operators, the advice from industry leaders is clear: do not wait for federal assistance. Use the open-source versions of CSET available on platforms like GitHub to perform your own diagnostic assessments. Map your findings against the CPGs to prioritize remediation efforts, and seek out state-level partnerships or regional cybersecurity coalitions that are stepping up to fill the void left by the agency.

As the geopolitical landscape becomes increasingly unstable, the reliance on CISA to provide a "safety net" for the nation’s infrastructure has been severely shaken. Whether the agency can regain its footing and restore these essential programs—or if this represents a permanent shift toward a "self-service" model of national security—remains the most pressing question for security professionals across the country.

The threat is not decreasing, and the clock is ticking. As John Strand succinctly put it: "We should be dramatically increasing the resources available to critical infrastructure organizations right now. Instead, we’re pulling resources away from them while the attacks are increasing."