The agency responsible for defending American critical infrastructure from cyberattacks is operating at roughly 38 percent of its workforce. A partial government shutdown that started February 14 furloughed the majority of the staff that was left. Before the shutdown even began, CISA had already lost a third of its people to cuts and layoffs under the Trump administration.
There is no permanent director. The proposed 2026 budget slashes $495 million from the agency. And the programs being eliminated aren’t obscure bureaucratic line items. They’re the specific capabilities the US built to fight ransomware, protect elections, and coordinate defense of power grids, water systems, and hospitals.
Where the Cuts Land
The numbers tell a story the administration’s talking points don’t.
The Cybersecurity Division loses $216 million, an 18 percent cut. That’s the division that runs threat detection, incident response, and vulnerability coordination across federal networks and critical infrastructure. The counter-ransomware initiative, the program specifically designed to combat the fastest-growing cyber threat to American businesses and hospitals, is eliminated entirely.
The National Risk Management Center gets cut 73 percent, a $97.4 million reduction. This was the office that worked with private sector operators of critical infrastructure to identify and manage systemic risks. Power companies, water utilities, telecom providers. The partnerships that made coordinated cyber defense possible.
Election security is zeroed out. All 14 positions eliminated. The full $36.7 million budget, gone. The Stakeholder Engagement Division, CISA’s main interface with state and local governments and private industry, loses 62 percent of its budget ($62.2 million).
The “Censorship” Framing
The administration frames these cuts as removing “censorship infrastructure.” That framing deserves scrutiny, and it also deserves some context.
CISA did get involved in flagging online content to social media platforms during the 2020 election cycle. Congressional investigations documented this, and legitimate concerns were raised about government agencies influencing speech. That’s a real debate worth having.
But counter-ransomware coordination has nothing to do with content moderation. Working with water utilities to patch vulnerable SCADA systems has nothing to do with speech. Helping hospitals defend against the ransomware gangs that locked up patient records across dozens of facilities last year has nothing to do with censorship.
The programs being killed served operational cybersecurity functions. If the goal was to remove content moderation activity, targeted reforms could have done that while preserving the cyber defense apparatus. Instead, the entire agency’s operational capacity got hollowed out. The censorship argument is being used to justify capability destruction that goes far beyond any content moderation concern.
The Threat Environment Right Now
This is happening while nation-state cyber operations are accelerating. Chinese hacking groups have been caught pre-positioning inside US critical infrastructure networks. Russian intelligence has tripled resources targeting Western critical infrastructure. Ransomware attacks hit record levels in 2025.
CISA was the coordination point. When a water utility in a mid-size city got hit, CISA was who they called. When a hospital system locked up, CISA provided the technical response team. When intelligence agencies detected a Chinese intrusion in telecom networks, CISA coordinated the cross-sector response.
This is also happening weeks after the Cybersecurity Information Sharing Act expired during the same government shutdown. That law gave companies legal liability protections for sharing threat intelligence with federal agencies. Without it, and without the CISA staff who managed those relationships, the information-sharing pipeline between private industry and government defense is breaking down from both ends.
I keep coming back to the same word: self-sabotage. I genuinely cannot construct a rational explanation for gutting your own cyber defense agency while nation-state hackers are inside your infrastructure. Either this administration is clearing out the people who might blow the whistle on something, or they are deliberately leaving the country unprotected. I don’t know which one it is. Both explanations are worse than the other.
What This Means for Regular People
Hospitals, school districts, water treatment plants, and local governments are the most frequent ransomware targets in the US. They also have the thinnest cybersecurity budgets. CISA was the backstop. The agency provided free vulnerability scanning, incident response support, and security assessments to organizations that couldn’t afford to hire their own security teams.
That backstop is now running at 38 percent capacity with no permanent leadership and a budget proposal that eliminates its most critical programs. The question nobody in Washington is answering: who fills that vacuum? Private cybersecurity firms charge six figures for incident response. State governments don’t have the technical expertise. Small utilities and rural hospitals were never going to defend themselves against Russian military intelligence or Chinese state hackers on their own.
The programs being cut were built because that gap existed. Eliminating them doesn’t make the gap go away. It just means nobody’s standing in it anymore.