CISA Eliminates Six Free Cybersecurity Assessments for Critical Infrastructure

CISA infrastructure cybersecurity https://www.pexels.com/photo/futuristic-digital-circuit-board-art-30547569/

The Cybersecurity and Infrastructure Security Agency has ended six free assessment programs that helped critical infrastructure operators find weaknesses in their cyber defenses, according to Cybersecurity Dive. The programs paired CISA’s Cyber Security Evaluation Tool, or CSET, with hands-on support from regional advisers — a service that smaller and resource-constrained organizations may struggle to replace.

According to Cybersecurity Dive’s report, the retired programs assessed cyber resilience, ransomware readiness, incident management, supply-chain risk, and infrastructure security. CISA regional advisers were told during an Aug. 25 meeting to stop performing the assessments, the report said.

CISA described the programs as “legacy questionnaire assessments” that duplicated other agency resources. It is directing operators to its Cross-Sector Cybersecurity Performance Goals, a set of recommended practices for reducing common risks.

CISA said the CPGs share the same “objectives and outcomes” as the retired assessments and would allow the agency to improve nationwide data collection and comparisons. But former CISA officials and security practitioners say those goals do not replace an adviser who can walk an organization through an assessment, explain the findings, and help identify what to address.

Why CISA Ended the Assessments

The cuts came as CISA was struggling to support critical infrastructure partners after losing roughly one-third of its workforce, according to Cybersecurity Dive. The outlet also reported that the administration had been pushing out regional advisers who served as important contacts for utilities and state and local officials.

Budget pressure has compounded those staffing losses. Tatyana Bolton, executive director of the OT Cyber Coalition, told Cybersecurity Dive that “severe budget cuts” had limited CISA’s ability to provide the hands-on support it once offered critical infrastructure operators.

Michael Daniel, president and CEO of the Cyber Threat Alliance and a former White House cybersecurity coordinator, told Cybersecurity Dive the decision reflected what he described as the Trump administration’s pattern of “reducing the federal government’s role in cybersecurity.”

The decision also exposed friction inside CISA. The agency’s Integrated Operations Division houses the regional staff who conducted the assessments, while its Cybersecurity Division supports CSET and the analysis behind it. Cybersecurity Dive reported that the Cybersecurity Division no longer wanted to devote resources to that work.

Agency leaders ultimately concluded that the assessments did not provide enough value to justify their cost, according to the report.

How Significant Is the Loss?

The nationwide impact of eliminating the assessments is difficult to quantify. An organization without in-house security expertise or money for a commercial assessment may have lost access to guidance it cannot readily replace.

The cuts also come as CISA prepares to finalize new cyber incident-reporting requirements for critical infrastructure operators under CIRCIA. The rule will require covered entities to report certain cyber incidents within 72 hours and ransomware payments within 24 hours.

Denis Calderone, CTO of Suzu Labs, questioned the timing, but cautioned against overstating the impact of eliminating the assessment programs.

“To be fair, we don't really know how widely adopted these programs were in the first place,” he said. “The scope is huge with 50,000 small water utilities alone, we doubt that CISA's regional staff was ever going to reach all of them, and there's no public data showing how many operators actually used the assessments or what the measurable impact was.”

Without those figures, it is difficult to measure how much the programs improved security nationwide or how quickly their absence will be felt.

Who Fills the Gap?

Finding comparable help may be difficult for organizations with limited budgets. Daniel told Cybersecurity Dive that it was unclear who could provide a similar service “at a price they could afford.” He said the result would likely be an increase in the nation’s overall cyber risk.

John Strand, owner of Black Hills Information Security, also questioned the timing of the cuts given the current threat environment.

“Right now, our critical infrastructure is under attack at a level we simply have not seen before,” he said. “Water systems, energy, telecommunications, municipalities, and other critical infrastructure are actively being targeted. CISA itself warned in July about ongoing Iranian-affiliated attacks against operational technology and PLCs across multiple U.S. critical infrastructure sectors.”

The underlying assessment tool remains available. CSET is open source, and older versions on GitHub still include the six retired assessment modules. Organizations can therefore continue conducting those assessments on their own.

The CPGs, by contrast, are intended to help organizations prioritize security improvements rather than assess their current posture.

Calderone said the two resources can still be used together, even though they serve different purposes.

“They’re complementary tools, not interchangeable ones,” he said. “Use CSET to diagnose your current state, then use the CPGs to prioritize what to fix first.”

Some organizations may be able to find help elsewhere. Calderone said several states are increasing cybersecurity support for local operators. He also pointed water utilities to Project Watershed 250, a Texas initiative offering free vulnerability assessments and red-team exercises that is expected to expand nationally.

Whether state programs, industry initiatives, or commercial providers can replace the hands-on assistance CISA had been providing — particularly for operators with limited budgets — remains unclear.

Author
  • Contributing Writer, Security Buzz
    Michael Ansaldo is a veteran technology and business journalist with experience covering cybersecurity and a range of IT topics. His work has appeared in numerous publications including Wired, Enterprise.nxt, PCWorld, Computerworld, TechHive, GreenBiz, Mac|Life, and Executive Travel.