Network cables and blinking lights on server rack equipment in a dimly lit data center
Photo via Unsplash

TL;DR: The Cybersecurity and Infrastructure Security Agency (the federal body responsible for protecting American networks from foreign hackers) is falling apart. Sean Plankey, Trump’s nominee to lead CISA, withdrew on April 22 after 13 months of Senate inaction. The agency has burned through three acting directors since January. The White House wants to slash CISA’s budget by $707 million. Roughly a third of the workforce is gone. And right now, a Chinese-made backdoor called FIRESTARTER is sitting inside at least one federal agency’s Cisco firewall, surviving patches and reboots. CISA gave agencies until April 30 to physically unplug infected hardware. That’s two days from now. The people who are supposed to defend the country from cyberattacks are being systematically dismantled while the attackers are already inside.

13 Months, Zero Confirmed Leadership

On April 22, Sean Plankey sent a letter to President Trump asking to withdraw his nomination as CISA director. “After thirteen months since my initial nomination, it has become clear the Senate will not confirm me,” Plankey wrote [1].

The reason had nothing to do with cybersecurity. Senator Rick Scott (R-FL) placed a hold on Plankey’s nomination over a dispute about Coast Guard cutter contracts. Plankey even left the Coast Guard in March 2026 trying to clear the path. Scott’s opposition didn’t budge [1].

CISA hasn’t had a Senate-confirmed director since Jen Easterly left in January 2025. In the 15 months since, the agency has cycled through three acting directors:

  • Bridget Bean: served briefly as acting director
  • Madhu Gottumukkala: departed in February 2026 amid complaints about his leadership [2]
  • Nick Andersen: current acting director, now leading an agency that’s being gutted around him

Plankey called Andersen “one of the most competent cybersecurity people in the country.” Competence may not be enough when your staff is disappearing and your budget is being shredded.

The White House hasn’t named a replacement nominee.

$707 Million Gone. One-Third of Staff Gone.

On April 7, reports confirmed the Trump administration plans to cut CISA’s budget by at least $707 million for fiscal year 2027 [3]. That comes on top of cuts already made. The administration specifically targeted CISA’s election security and misinformation programs, claiming they were used to “target the President” [3].

The workforce damage is already done. Since Trump returned to office, CISA has lost approximately one-third of its staff [4]. Key departures include:

  • The leader of federal cyber defense programs, who resigned in March 2026 [5]
  • Multiple senior officials and technical staff across the agency
  • CyberCorps summer internships cancelled due to the shutdown [4]
  • 300 “mission-critical” positions that were slated to be filled, now frozen [4]

Bipartisan lawmakers and cybersecurity industry sources told TechCrunch the agency is “unprepared to handle a crisis” [4]. That assessment was made in February. The crisis arrived in April.

Chinese Hackers Are Already Inside. The Deadline Is Wednesday.

On April 23 (the day after Plankey withdrew) CISA and the UK’s National Cyber Security Centre (NCSC) issued a joint alert about FIRESTARTER, a backdoor malware found on at least one federal civilian agency’s Cisco Firepower firewall [6].

FIRESTARTER isn’t ordinary malware. It’s a Linux executable designed to survive firmware updates, security patches, and standard reboots. It detects termination signals and relaunches itself. The only way to kill it is to physically unplug the device from its power supply [6].

The attackers (tracked by Cisco as UAT-4356, also known as Storm-1849 or ArcaneDoor) are linked to Chinese state-sponsored operations. They’ve been inside the compromised network since at least September 2025 [6].

CISA issued Emergency Directive 25-03 requiring all federal agencies to hard-reset compromised Cisco hardware by April 30, 2026 [7]. That’s two days from now. In many cases, Cisco recommends complete reimaging rather than patching, because patches alone can’t remove FIRESTARTER.

Think about that timeline. The agency responsible for coordinating the government’s response to a Chinese cyber intrusion has no confirmed director, is losing staff by the week, and is running on a budget that’s about to get cut by $707 million. The attackers had at least seven months of access before anyone noticed.

This Isn’t an Accident. It’s a Pattern.

Strip out the politics and look at the sequence:

  1. CISA’s election security work gets framed as partisan. Funding for those programs gets cut.
  2. Staff reductions hit the agency across the board, not just election security. Technical experts leave. Positions freeze.
  3. The director nomination stalls for over a year on an unrelated Coast Guard contract dispute. Nobody intervenes.
  4. Three acting directors cycle through in 15 months. Institutional continuity evaporates.
  5. A nation-state adversary plants malware inside a federal firewall. It sits there for seven months.
  6. The agency issues an emergency directive with a two-day deadline, while running on skeleton staff.

You don’t need to be a cybersecurity expert to see the problem. The people responsible for finding threats like FIRESTARTER are the same people being shown the door.

What This Means for You

CISA does more than protect federal networks. It coordinates vulnerability disclosures that protect every business and consumer in the country. It runs the Known Exploited Vulnerabilities catalog that IT departments rely on for patch prioritization. It issues alerts about threats targeting critical infrastructure: hospitals, power grids, water systems, financial networks.

When CISA shrinks, the gap doesn’t stay empty. It gets filled by attackers who know the watchtower is unmanned.

  • If you run IT infrastructure: Don’t wait for CISA alerts. Monitor Cisco’s Talos threat intelligence directly. Check your Cisco ASA and Firepower devices against CISA’s Emergency Directive 25-03 indicators of compromise.
  • If you care about election security: The programs that protected the 2024 election from foreign interference are being defunded. The 2026 midterms are six months away.
  • If you want to act: Contact your senators. Ask them why CISA has gone 15 months without a confirmed director during an active Chinese cyber campaign. Ask them to restore funding.

References

  1. Nextgov: Plankey withdraws nomination to lead CISA (April 22, 2026)
  2. CyberScoop: CISA director pick Sean Plankey withdraws his nomination (April 2026)
  3. TechCrunch: Trump administration plans to cut cybersecurity agency’s budget by $700 million (April 7, 2026)
  4. TechCrunch: US cybersecurity agency CISA reportedly in dire shape amid Trump cuts and layoffs (February 25, 2026)
  5. Federal News Network: Leader of federal cyber defense programs resigns from CISA (March 2026)
  6. Cybersecurity Dive: US, UK authorities warn that Firestarter backdoor malware survives patching (April 27, 2026)
  7. CISA. Emergency Directive 25-03: Identify and Mitigate Potential Compromise of Cisco Devices (April 2026)