On August 24, 2026, five prominent Democratic members of the U.S. House Homeland Security Committee formally requested that the Government Accountability Office (GAO) launch a study into the effects of substantial workforce reductions at the Cybersecurity and Infrastructure Security Agency (CISA). The request, led by ranking member Bennie Thompson, highlights concerns that the loss of approximately one-third of CISA's staff since the start of the second Trump administration could be jeopardizing U.S. national security. The lawmakers are seeking clarity on how these cuts have impacted CISA's ability to protect critical infrastructure and respond to cyber threats.
The letter to the GAO is a formal congressional oversight action. It does not create new regulations but initiates an independent, non-partisan investigation by the GAO, which serves as the investigative arm of Congress. The lawmakers have asked the GAO to assess the full scope of the workforce cuts and changes to CISA's mission priorities. Key areas of concern cited in the letter include:
Cybersecurity experts and the lawmakers themselves warn that the hollowing out of CISA poses a direct threat to national security. A weakened CISA may have a reduced capacity to:
The letter notes that while the Department of Homeland Security approved hiring 329 'critical' positions in March, the status of these hires is unclear, leaving a significant gap in the nation's cyber defense posture.
There is no set timeline for the GAO to begin or complete its study. Typically, such comprehensive reviews can take several months to a year. The findings will be delivered in a report to Congress, which could then inform future legislation or funding decisions related to CISA.
This is not an enforcement action. The GAO's role is to provide facts and analysis. However, the findings of its report could lead to political pressure on the administration and form the basis for future congressional hearings and potential legislative action to restore CISA's funding and personnel levels.
Five House Democrats formally request a GAO study into CISA's workforce reductions.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.