MSSP, Critical Infrastructure Security, Government Regulations, Threat Intelligence

DHS Head Noem Puts Focus on CISA as Trump Targets Krebs Again

(Adobe Stock)

The Trump Administration is continuing its efforts to reshape and narrow the government’s cybersecurity agency duties, with Homeland Security Secretary Kristi Noem promising to realign its mission while the president ramped up his attack on it former director.

Noem told an audience at the RSA Conference this week in San Francisco that CISA, which was created during Trump’s first term in 2018, would get back to focusing on protecting the country against adversaries’ cyberattacks and stay away from issues of disinformation and election security.

“CISA is not the Ministry of Truth,” the former South Dakota governor said. “It is the job of CISA to be a cybersecurity agency that works to protect this country.”

While Noem did not directly address the issue, Trump has, for years, been highly critical of CISA for its work in protecting U.S. elections from foreign influences, including attempts at countering disinformation. CISA and ex-director Chris Krebs in 2020 disputed Trump’s assertions the he lost the presidential election to Joe Biden because votes were tampered with, with Krebs at the time saying it was the most secure election in U.S. history.

During the keynote, Noel also confirmed that the Department of Homeland Security is investigating CISA’s operations, saying that the agency is “not eliminating CISA, but we are making sure it does what it was created to do: hunt and harden systems. That’s what the American people need.” Her talk came amid reports of budget and workforce cuts, reflecting broader trends across the federal government.

Cybersecurity Programs Under Fire

Some worry that the administration's actions toward CISA could weaken the country’s cybersecurity posture, and that it is politics that’s driving them.

Before the RSA Conference, Jen Easterly, who succeeded Krebs as CISA director before leaving in January, warned that the steps taken against Krebs – including stripping him of security clearances – the firing of National Security Agency Director and Commander of U.S. Cyber Command and his deputy, and other steps put the country at greater risk.

“They’re part of a larger drift, one that risks hollowing out – and worse, politicizing – the U.S. federal cyber ecosystem when we can least afford it, undermining the capability of our country's most important cybersecurity agencies at the same time that Chinese state-sponsored hackers are holding our nation at risk, positioned to launch disruptive attacks on our most sensitive critical infrastructure,” Easterly wrote.

Trump Boots Krebs’ from Global Entry Program

This was before Trump revoked Krebs’ membership in the U.S. Custom and Border Control’s Global Entry traveler program this week.

Easterly also criticized what she described as an initially muted response from cybersecurity leaders, warning that “what’s happening now is not a policy disagreement, but something dark: the targeting and removal of nonpartisan public servants and the normalization of loyalty oaths to something other than our Constitution. And if we – who aim to protect critical systems – can’t defend the humans who manage and maintain them, what exactly are we securing?”

During a panel at the conference, Easterly also stated the community is under fire because “there is a mandate for loyalty to a person over loyalty to the Constitution of the United States of America." 

'It's Mostly About Politics’

Jack Gold, principal analyst with J. Gold Associates, echoed Easterly’s concerns, and told MSSP Alert that Trump’s and Noem’s actions regarding CISA “is mostly about politics,” and that “CISA should be above political considerations, just like police, fire, and other necessary safety services.”

Gold noted that CISA battles pushes back on disinformation from adversaries like China, Russia, North Korea, and Iran, and is aimed at swaying public opinion and effect elections.

“Of course, it also means that the administration would have less free range to do their own disinformation, like the elections were stolen in 2020 – and for which the CISA leader Krebs has now been ‘persecuted’ for telling the truth. So clearly that is a political decision.”

The Need to Adapt

Some security professionals have also raised concerns about the changes at CISA, warning that organizations will need to adapt to a shifting cybersecurity landscape. Bugcrowd CEO Dave Gerry told MSSP Alert that fewer resources and reduced staffing at CISA could delay initiatives like vulnerability disclosure and the Secure By Design program. He also warned that government-based centralized guidance is weakened, as seen with the recent case of the funding controversy MITRE’s CVE program.

“A just-in-time approach to vulnerability management is no longer sustainable, especially when the integrity of a single system can affect thousands,” Gerry said.

John Bambenek, president of Bambenek Consulting, told MSSP Alert that disinformation is a “radically more pressing issue now that we have generative AI, where propaganda-friendly regimes are actively trying to figure out how to use it to affect an entire society’s understanding the world around them. Someone is going to have to come to grips with this; whether or not its CISA is a politically loaded question. Ignored problems don’t go away, though.”

The Lightning Rod

Krebs has borne much of the president’s wrath regarding CISA. Along with revoking his security clearances, he also suspended security clearances of others at SentinelOne, the cybersecurity firm he worked for as chief intelligence and public policy officer.

Along the way, there has been some growing support for the ex-CISA chief. The Electronic Frontier Foundation this week posted an open letter to Trump on its website signed by 40 people in the cybersecurity field and academia asking for the security clearances to be returned and to terminate the investigation into Krebs and his work at the White House.

“By placing Krebs and SentinelOne in the crosshairs, the President is signaling that cybersecurity professionals whose findings do not align with his narrative, risk having their businesses and livelihoods subjected to spurious and retaliatory targeting, the same bullying tactic he has recently used against law firms,” the letter says.

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds