The agency responsible for defending American critical infrastructure from cyberattacks is operating at roughly 38 percent of its workforce. A partial government shutdown that started February 14 furloughed the majority of the staff that was left. Before the shutdown even began, CISA had already lost a third of its people to cuts and layoffs under the Trump administration.

There is no permanent director. The proposed 2026 budget slashes $495 million from the agency. And the programs being eliminated aren’t obscure bureaucratic line items. They’re the specific capabilities the US built to fight ransomware, protect elections, and coordinate defense of power grids, water systems, and hospitals.

Where the Cuts Land

The numbers tell a story the administration’s talking points don’t.

The Cybersecurity Division loses $216 million, an 18 percent cut. That’s the division that runs threat detection, incident response, and vulnerability coordination across federal networks and critical infrastructure. The counter-ransomware initiative, the program specifically designed to combat the fastest-growing cyber threat to American businesses and hospitals, is eliminated entirely.

The National Risk Management Center gets cut 73 percent, a $97.4 million reduction. This was the office that worked with private sector operators of critical infrastructure to identify and manage systemic risks. Power companies, water utilities, telecom providers. The partnerships that made coordinated cyber defense possible.

Election security is zeroed out. All 14 positions eliminated. The full $36.7 million budget, gone. The Stakeholder Engagement Division, CISA’s main interface with state and local governments and private industry, loses 62 percent of its budget ($62.2 million).

The “Censorship” Framing

The administration frames these cuts as removing “censorship infrastructure.” That framing deserves scrutiny, and it also deserves some context.

CISA did get involved in flagging online content to social media platforms during the 2020 election cycle. Congressional investigations documented this, and legitimate concerns were raised about government agencies influencing speech. That’s a real debate worth having.

But counter-ransomware coordination has nothing to do with content moderation. Working with water utilities to patch vulnerable SCADA systems has nothing to do with speech. Helping hospitals defend against the ransomware gangs that locked up patient records across dozens of facilities last year has nothing to do with censorship.

The programs being killed served operational cybersecurity functions. If the goal was to remove content moderation activity, targeted reforms could have done that while preserving the cyber defense apparatus. Instead, the entire agency’s operational capacity got hollowed out. The censorship argument is being used to justify capability destruction that goes far beyond any content moderation concern.

The Threat Environment Right Now

This is happening while nation-state cyber operations are accelerating. Chinese hacking groups have been caught pre-positioning inside US critical infrastructure networks. Russian intelligence has tripled resources targeting Western critical infrastructure. Ransomware attacks hit record levels in 2025.

CISA was the coordination point. When a water utility in a mid-size city got hit, CISA was who they called. When a hospital system locked up, CISA provided the technical response team. When intelligence agencies detected a Chinese intrusion in telecom networks, CISA coordinated the cross-sector response.

This is also happening weeks after the Cybersecurity Information Sharing Act expired during the same government shutdown. That law gave companies legal liability protections for sharing threat intelligence with federal agencies. Without it, and without the CISA staff who managed those relationships, the information-sharing pipeline between private industry and government defense is breaking down from both ends.

I keep coming back to the same word: self-sabotage. I genuinely cannot construct a rational explanation for gutting your own cyber defense agency while nation-state hackers are inside your infrastructure. Either this administration is clearing out the people who might blow the whistle on something, or they are deliberately leaving the country unprotected. I don’t know which one it is. Both explanations are worse than the other.

What This Means for Regular People

Hospitals, school districts, water treatment plants, and local governments are the most frequent ransomware targets in the US. They also have the thinnest cybersecurity budgets. CISA was the backstop. The agency provided free vulnerability scanning, incident response support, and security assessments to organizations that couldn’t afford to hire their own security teams.

That backstop is now running at 38 percent capacity with no permanent leadership and a budget proposal that eliminates its most critical programs. The question nobody in Washington is answering: who fills that vacuum? Private cybersecurity firms charge six figures for incident response. State governments don’t have the technical expertise. Small utilities and rural hospitals were never going to defend themselves against Russian military intelligence or Chinese state hackers on their own.

The programs being cut were built because that gap existed. Eliminating them doesn’t make the gap go away. It just means nobody’s standing in it anymore.

President Donald Trump signed an executive order on Thursday, aiming to centralize AI regulation at the federal level and challenge state laws that impose varying rules on artificial intelligence. Titled “Ensuring a National Policy Framework for Artificial Intelligence,” the order directs federal agencies to set up task forces to identify and potentially contest state AI laws, with the Commerce Department given 90 days to evaluate rules considered “onerous.”

While the administration frames the order as a solution to the patchwork of state laws, legal experts warn it could leave startups in legal limbo. Companies navigating differing state and federal regulations may face extended court battles, creating uncertainty for small and mid-sized innovators who lack the resources to absorb legal risks.

The order instructs the Department of Justice to challenge state laws on the grounds that AI falls under interstate commerce. The Federal Trade Commission and Federal Communications Commission are tasked with exploring standards that could preempt state rules, while the administration encourages Congress to craft a uniform AI law.

Critics say the executive order may favor large tech firms, which have the funding to weather legal uncertainty, while startups and emerging AI companies face delays and compliance costs. Arul Nigam, co-founder of Circuit Breaker Labs, warned that smaller AI firms must navigate conflicting rules without clear guidance, slowing innovation.

“Big Tech and the big AI startups have the funds to hire lawyers or hedge their bets. The uncertainty hurts startups the most,” said Andrew Gamino-Cheong, CTO of AI governance company Trustible. He added that legal ambiguity could reduce adoption among risk-sensitive customers such as financial and healthcare institutions.

Supporters of a federal framework argue a single national standard could reduce complexity, but Gary Kibel, partner at Davis + Gilbert, cautioned that an executive order is not the proper vehicle to override state laws, potentially creating a regulatory “Wild West.” Meanwhile, organizations like The App Association urge Congress to act quickly to pass a comprehensive AI framework to avoid prolonged legal battles.

As state enforcement continues until courts intervene or Congress legislates, startups face a precarious balance between innovation and compliance, navigating a landscape where AI law remains uncertain.


Related Laterstack Tech Stories

Exposed AI Image Database Raises Serious Privacy and Security Concerns
Immigration Judge John P. Burns Employs AI in Court
Bitcoin Miner Bitfarm Shifts from Crypto to AI Data Centers

For inquiries, tips, or submissions: hello@laterstack.com