Mixed signals out of Washington are leaving private-sector firms unsure about the status of the federal government's key cybersecurity agency, which has long struggled to win over their confidence and share vital attack intelligence.
That hesitancy may already be a national-security risk, cybersecurity experts say.
Without clarity from the federal government, corporate cyber chiefs still need to make crucial decisions about threat priorities, incident response and resilience, "but with fewer shared signals and less confidence that everyone is operating from the same playbook," said Dana Simberkoff, chief risk, privacy and information security officer at cybersecurity firm AvePoint.
This summer, Homeland Security Secretary Markwayne Mullin told Congress that the Cybersecurity and Infrastructure Security Agency was "half-staffed" and pledged to hire some 600 new workers, filling crucial gaps left by deep cuts over the past year. Since early 2025, CISA has lost more than 1,000 employees, or roughly a third of its workforce, many at the hands of the Trump administration's Department of Government Efficiency.
Yet the White House has said it is committed to eliminating hundreds more jobs at the agency, while cutting its overall budget.
Whether the agency goes on a hiring spree, or continues slashing its workforce, remains an open question until Congress ratifies a 2027 federal budget. Lawmakers on both sides of the aisle-who generally support rebuilding the agency-are caught in the middle, with bipartisan efforts aimed at carving out tens of millions of dollars from the proposed budget to rehire critical specialists.
"I've been clear about my concerns with some previous personnel reductions at CISA," Rep. Andrew Garbarino, a New York Republican who chairs the House Homeland Security Committee, said. "I will continue to advocate to the administration and my colleagues in Congress on the importance of CISA's core mission," Garbarino said.
The agency recently identified key areas where "additional capabilities are essential to our nation's security," according to a spokesperson. Homeland Security has approved hiring for "mission critical positions that directly support national security and ensure CISA remains agile in the face of emerging cyber and physical risks," the spokesperson said, without providing a timeline.
Some agency job postings have appeared online in recent weeks, including a cybersecurity state coordinator and a supervisory IT cybersecurity project manager.
Rep. Bennie Thompson, a Mississippi Democrat who serves as the ranking member on the House Homeland Security Committee, said those efforts might be too little, too late. "I worry it will take a long time to undo the damage," Thompson said.
"Congress and Secretary Mullin are on the same page when it comes to restoring CISA's critical workforce. The president needs to heed the call and join," said Sen. Mark Warner (D., Va.). "These jobs should have never been eliminated in the first place," he said.
Louis Eichenbaum, federal chief technology officer at cybersecurity firm ColorTokens, said it is possible that the agency is both hiring and firing at the same time.
"The administration is proposing a smaller long-term staffing footprint for CISA, while the agency is also trying to fill critical operational gaps that exist today," Eichenbaum said. The numbers can appear contradictory, he said, because they include a future budget proposal, current workforce levels and immediate hiring requirements.
"The goal should be to make sure CISA has the expertise and operational capacity necessary to execute its core cybersecurity and critical infrastructure mission," Eichenbaum said.