A group of Democratic lawmakers, led by Rep. Bennie Thompson (D-MS), ranking member of the House Committee on Homeland Security, has formally asked the Government Accountability Office (GAO) to investigate the impact of staffing reductions at the Cybersecurity and Infrastructure Security Agency (CISA).
Nearly 1,000 CISA employees have been fired or have resigned since the start of the Trump administration, representing roughly one-third of the agency’s workforce. Acting Director Nick Andersen has said he intends to hire 300 new employees to close the gaps left by layoffs and departures.
In their letter, the lawmakers asked GAO to “examine the impact of recent staffing reductions and programmatic cuts at CISA on the agency’s ability to carry out its mission requirements, protect critical infrastructure, and respond to evolving cyber and physical threats.” They argued that the cuts come at a moment when adversaries are accelerating attacks on critical infrastructure, raising doubts about CISA’s ability to keep pace.
Leadership turnover and knowledge loss
The letter highlights concerns about institutional knowledge lost as senior CISA officials have departed, including David Stern, who was described as the driving force behind a major ransomware notification initiative. CISA has not had a Senate-confirmed director since Jen Easterly left at the end of the Biden administration, and Andersen is currently serving in an acting capacity after Madhu Gottumukkala was removed from the role in February following a series of scandals. Reporting has named a senior Palantir official as a leading contender for the permanent director position.
GAO spokesperson Sarah Kaczmarek confirmed the agency received the congressional request and said GAO is working through its internal process to determine whether and when it will take up the review. CISA did not respond to a request for comment on the letter.
Budget uncertainty adds to concerns
Homeland Security Secretary Markwayne Mullin has previously said the department has a plan to rebuild CISA’s workforce over the next year. However, the lawmakers’ letter points to confusion created by the proposed fiscal year 2027 budget, which would eliminate nearly 900 additional CISA positions and cut more than $700 million from the agency.
Multiple states and senior members of Congress have warned that continued cuts could harm municipal cybersecurity nationwide, particularly ahead of the November election season. Industry representatives and state and local officials have reported reduced responsiveness from CISA, describing service disruptions tied to ongoing staffing turbulence.
The letter also references recent joint advisories from CISA, the FBI, and other federal agencies warning of an active threat campaign against critical infrastructure that reportedly uses AI-generated exploit scripts, which officials characterized as an evolution in attacker capabilities.
