Key Takeaways
- Kristi Noem testified that she would make CISA “smaller” and “more nimble,” contrasting with the agency’s original purpose of giving cybersecurity institutional weight.
- CISA was created under Trump’s first term, grew rapidly with bipartisan support, but became a political flashpoint after its director, Christopher Krebs, affirmed the 2020 election’s security.
- The Trump administration slashed CISA’s budget by one‑third during the DOGE fervor, left the director position vacant, and later proposed deeper cuts despite warnings about vulnerable infrastructure.
- Acting Director Nicholas Andersen announced a reversal under Deputy Secretary Markwayne Mullin, planning to add 600 positions and prioritize critical cyberdefense roles.
- Iran‑linked hackers have already targeted water and wastewater systems in over a dozen states, with attacks described as the most extensive seen by state officials; the administration has not confirmed Iran’s role or disclosed the full scope.
- Election‑integrity efforts have shifted toward promoting hand‑counted votes, halting federal briefings for state officials, ending funding for information‑sharing networks, and appointing partisan figures to oversee election security.
- State and local election officials—especially Democrats—have lost trust in CISA, fearing that shared threat intelligence could be used against them, and are turning to private contractors, state homeland‑security offices, and ad‑hoc networks for protection.
- Experts warn that AI‑driven tools are accelerating the discovery of vulnerabilities in utilities and election‑related online systems, heightening the risk that cyberattacks could erode public confidence even if they cannot change vote tallies.
Noem’s Confirmation Vision for CISA
During her January 2025 confirmation hearing to become Secretary of Homeland Security, Kristi Noem was asked how she would bolster the nation’s cyberdefenses. She responded that she would make the Cybersecurity and Infrastructure Security Agency (CISA) “smaller” and “more nimble.” This stance directly contrasts with the original rationale for creating CISA as a stand‑alone agency within DHS: to give cybersecurity a permanent, high‑profile institutional home capable of coordinating across government and with private partners.
CISA’s Founding and Rapid Expansion
President Trump established CISA during his first term to elevate cybersecurity within the federal bureaucracy. The agency quickly grew, bolstered by bipartisan congressional support, and took on a broad mission that included protecting critical infrastructure, sharing threat intelligence, and assisting state and local election officials. By the time of the 2020 election, CISA had become a trusted source of nonpartisan technical expertise for many jurisdictions.
The 2020 Election Fallout and Krebs’s Dismissal
CISA’s declaration that the 2020 presidential election was “the most secure in American history” placed it at odds with President Trump, who falsely claimed the vote had been stolen. When CISA Director Christopher Krebs refused to endorse those claims, he became a target of the president’s ire. The White House later issued a presidential memorandum accusing Krebs of “falsely and baselessly denying” election rigging, marking the beginning of a sustained effort to undermine the agency’s credibility.
Budget Cuts and Staffing Reductions Under the DOGE Fervor
In the early months of Trump’s returned presidency, the so‑called DOGE movement drove a sharp reduction in CISA’s resources. The agency’s budget was cut, and its workforce was trimmed by roughly one‑third. Consequently, CISA has lacked a permanent, Senate‑confirmed director since Trump retook office. In April, the White House proposed even deeper cuts, prompting alarm among Republican lawmakers who warned that U.S. infrastructure remained dangerously exposed.
Mullin’s Reversal and Renewed Hiring Push
By June, Deputy Secretary Markwayne Mullin signaled a shift in direction. During a DHS budget hearing he announced plans to add 600 positions to CISA, framing the move as a “ruthless prioritization” of critical cyberdefense roles. The agency has begun scheduling hiring expos, and Acting Director Nicholas Andersen stated that the new staff would focus on the most urgent threats. This reversal suggests an acknowledgment that the earlier downsizing had weakened the nation’s cyber posture.
Iran‑Linked Cyberattacks on Water Systems
Despite the personnel rebound, the United States is now roughly six months into a heightened conflict with Iran, a nation possessing notable cyber capabilities. In late May, hackers with suspected ties to Iran targeted water and wastewater systems in more than a dozen states. In Braham, Minnesota, the attack temporarily shut down the municipal water supply; state officials described the campaign as the most extensive they have ever witnessed. The Trump administration has not publicly confirmed Iran’s involvement, disclosed the number of affected states, or revealed whether other breaches have occurred.
Gaps in Intelligence Sharing and Confirmation
CISA’s current leadership void and the ongoing budget uncertainty have hampered its ability to deliver timely intelligence to state and local partners. While the FBI, EPA, and CISA issued a joint warning that Iran‑affiliated actors are probing U.S. utilities, the administration has not clarified the scope of the threat. This lack of transparency leaves utility operators without the actionable data needed to preempt or mitigate attacks, especially as the midterm elections approach and hostilities with Tehran are expected to evolve into a more covert, economically focused phase.
Election‑Integrity Focus Undermines Cybersecurity
Parallel to the cyber threats, the Trump administration has intensified its focus on questioning the integrity of U.S. elections. President Trump and Andersen have met with election deniers who advocate hand‑counting ballots, halted federal intelligence briefings for state election officials, and ended funding for an information‑sharing network designed to combat foreign disinformation. Federal employees who worked on disinformation within CISA were placed on leave, and the agency hired Heather Honey—a conservative activist who sought to overturn Trump’s 2020 loss—to oversee election integrity. The administration is also investigating the 2020 elections in Georgia and Arizona and demanding voter data, with Mullin threatening to jail officials who refuse to comply.
Erosion of Trust Among State and Local Officials
These actions have deepened distrust, particularly among Democratic secretaries of state. Half a dozen Democratic officials and their staff told reporters they no longer view CISA as a reliable partner for safeguarding election‑related systems. Many have begun to replace CISA’s role by sharing threat data amongst themselves, hiring private contractors, leveraging state homeland‑security and National Guard units, and turning to nonprofit groups staffed by former CISA employees. However, experts caution that no state‑level effort can replicate the federal government’s expansive intelligence‑gathering network, which draws on multiple agencies and cyber units to produce the strategic threat analysis essential for effective defense.
Expert Warnings About Vulnerabilities and AI‑Enhanced Threats
Former CISA Director Christopher Krebs emphasized that many small water systems, lacking dedicated cybersecurity staff, rely on remote‑operation tools that connect to the internet, making them attractive targets. He noted that past attacks often succeeded due to weak password policies—a symptom of a broader, lackluster approach to cyber risk. Krebs argued that it is unfair to place the entire burden of defense on local governments when a geopolitical conflict with a capable adversary like Iran demands federal coordination. Jen Easterly, who led CISA under the Biden administration, added that U.S. utilities were engineered for efficiency and reliability, not security, and that AI‑driven tools are now enabling hackers to discover and exploit vulnerabilities faster than ever, heightening the danger to both infrastructure and election‑related online components such as voter‑registration systems and result‑reporting websites.
Implications for the Upcoming Midterms and Beyond
Most voting equipment in the United States remains offline and produces paper ballots, providing a resilient backup against vote‑tampering. Nevertheless, the online facets of the election process—registration databases, state election websites, and nightly result‑reporting portals—remain vulnerable. If hackers can cause outages or manipulate those sites, they can undermine public confidence even if they cannot alter actual vote totals. State officials fear that any real cyber incident would be exploited by the administration to justify greater federal control over elections, further eroding the delicate balance between state autonomy and federal oversight.
Conclusion: The Need for a Re‑Empowered, Nonpartisan CISA
The trajectory described—initial expansion, politicization after 2020, drastic cuts, a tentative hiring rebound, and persistent external threats—highlights a critical juncture for U.S. cybersecurity. For CISA to fulfill its original mission of delivering nonpartisan, technical expertise and to rebuild trust with state and local partners, it must retain sufficient resources, stable leadership, and a clear mandate to operate above partisan fray. Only then can the agency provide the intelligence, threat analysis, and direct assistance necessary to defend both critical infrastructure and the democratic process against increasingly sophisticated adversaries.

