Back to Blog

When Trump 2.0 Goes Cyber: Why We Need a New CISA and a Bigger Cyber Playbook

By: Casey Cannady : cybersecurity veteran & policy advocate

December 22, 2025
10 min read
Casey Michael Cannady
Updated September 13, 2026
CybersecurityPolicy AnalysisTechnology

TL;DR

On December 19, Brian Krebs published a year-in-review of what the second Trump administration did to America's cyber defenses. It is not a story about hackers breaking in. It is a story about the defenders being dismantled from the inside. CISA lost roughly a third of its workforce. The Cyber Safety Review Board was dismissed mid-investigation. Cyber specialists were reassigned to deportation work. States were barred from spending cyber grants on the shared service that protects local governments. NSA and U.S. Cyber Command went months without confirmed leaders. After nearly 30 years defending real networks, I can tell you what that looks like from the ground, and what putting it back would take.


What Krebs Actually Documented

Read the whole thing: “Dismantling Defenses: Trump 2.0 Cyber Year in Review”. It covers free speech, corruption enforcement, consumer protection, and DOGE too. I am pulling out only the parts that land directly on national cyber defense, because that is the part I have spent a career inside.

AreaWhat Krebs reportsWhy it matters
CISA staffingRoughly one-third of the workforce gone through layoffs and resignations. During the October shutdown, 65 percent of the remainder was furloughed, leaving about 900 people working without pay.Advisories, vulnerability coordination, and incident support are people, not software. Fewer people means slower warnings for everyone downstream.
Cyber Safety Review BoardAll 15 members dismissed mid-investigation.The one body built to do blameless post-mortems on major incidents stopped doing them. Lessons that are not written down get relearned the expensive way.
ReassignmentCISA cyber specialists reassigned to deportation enforcement; a quarter of FBI agents moved from national security work to immigration enforcement.Skilled defenders are the scarcest resource in this field. Pointing them at something else is a choice to leave the watch post empty.
BudgetA proposed additional $491 million cut to CISA; ODNI planning to cut more than $700 million a year.Cuts on top of attrition compound. You do not rebuild institutional knowledge with next year's appropriation.
State and localDHS barred states from using federal cyber grants on MS-ISAC services.County election offices, school districts, and water utilities are the organizations least able to buy that protection on their own.
LeadershipNSA and U.S. Cyber Command without confirmed leadership since April.Acting leaders keep the lights on. They rarely make the long bets.
TelecomThe FCC rolled back cybersecurity rules for telecom carriers.Carriers are the backbone every other network rides on. Fewer obligations there raise the risk for everyone.
Government dataDOGE staff accessed sensitive data at SSA, DHS, OPM, and Treasury by circumventing security protocols; an NLRB whistleblower alleged gigabytes of case files were downloaded. Krebs also reports Chinese intelligence recruiting laid-off U.S. government employees.Every bypassed control is a control an attacker no longer has to beat. And every laid-off cleared employee is someone a foreign service now wants to talk to.

Bottom line: nobody had to hack America's cyber defenses in 2025. They were thinned out, reassigned, and defunded in public, on the record. Complacency is still the most expensive vulnerability, and this year it was a policy.


Why This Lands Differently When You Have Done the Work

I have spent nearly 30 years in IT and cybersecurity, most of the last decade and a half in endpoint management and security. I was the BigFix subject matter expert at Kroger Technology and a featured speaker at IBM InterConnect. I was a BigFix architect at CBI, and then an enterprise architect at HCL Software delivering endpoint security and compliance programs for Fortune 500 clients. I have worked environments from a nationwide grocery chain to a U.S. federal agency running north of 300,000 endpoints that I am not permitted to name.

Here is what that taught me about national cyber defense: almost nobody defends alone. The patch team decides what goes first by watching CISA's Known Exploited Vulnerabilities catalog. The small county IT shop leans on MS-ISAC for monitoring it could never staff itself. The incident responder reads the post-mortem somebody else wrote. Take the federal layer out and the Fortune 500 companies will mostly be fine. The school district will not.

This is not abstract for me either. The DOGE cuts gutted the contract economy I earned my living in, and on October 15, 2025, Karen and I filed Chapter 7. I have watched this policy from the server room and from the bankruptcy court.


The Policy Prescription: Restore CISA and Raise the Bar

Every fix below maps to a specific failure in Krebs's reporting. None of them is exotic. Most of them are just undoing the damage.

ProblemWhat we should do
A hollowed-out CISARebuild the workforce, and protect cyber staff from reassignment to unrelated missions by statute, not by the goodwill of whoever runs DHS.
No independent post-mortemsReconstitute the Cyber Safety Review Board with fixed terms and statutory independence, so it cannot be dismissed mid-investigation again.
Local governments cut offRestore states' ability to spend cyber grants on MS-ISAC, and fund it directly for the jurisdictions that cannot.
Leaderless cyber agenciesNominate and confirm permanent leaders for NSA and U.S. Cyber Command.
Weaker telecom obligationsReinstate baseline cybersecurity requirements for carriers.
Bypassed data controlsCommission an independent audit of every system DOGE touched: what was accessed, what was copied, where it went, and whether those copies still exist.

Why This Matters to You

  • If you're a CIO or CTO: assume the federal early-warning layer is thinner than it was a year ago. Your threat intelligence, your vulnerability prioritization, and your incident response retainer all need a fresh look.
  • If you're a policymaker: you are the lever that can reshape the national posture. Think of CISA as the glue that holds the federal cyber ecosystem together, and the MS-ISAC as the glue for everyone below the federal line.
  • If you're a citizen: your county election office, your school district, and your water utility just lost help they cannot replace on their own. The more you understand that, the louder you can be about it.

“The cyber-battlefield is not a battlefield for heroes alone; it is a collective effort that starts with the policies we put in place.”

Casey Cannady


Sources & Further Reading

Sourcing note: the facts in the first table are Brian Krebs's reporting, summarized; read his piece for the underlying citations. The “why it matters” column and the policy prescriptions are my own analysis. Revised September 2026: an earlier version of this post misstated my career history, described attacks that do not appear in the Krebs article, and attributed a quote to Krebs that he did not write. All three were removed, and the post's date was corrected to follow the article it responds to.


Connect with Casey

Have a story, a question, or want Casey to write about a specific topic? DM me and tell me which story you want next.

Casey writes about cybersecurity, policy, nomadic life, and navigating the world as a late-diagnosed AuDHD adult. New posts drop on my professional website.