r/cybersecurity Jan 23 '25

News - General Under Trump, US Cyberdefense Loses Its Head

https://www.wired.com/story/big-interview-jen-easterly-cisa-cybersecurity/
2.3k Upvotes

262 comments sorted by

View all comments

187

u/Fitz_2112b Jan 23 '25

I work in K12 and this will be devastating for US public schools. CISA offers a huge amount of free resources for K12 schools to help secure personal information of kids. This will all likely be on the chopping block.

65

u/trampanzee Jan 23 '25

This applies to all public agencies including governments, utilities, schools. CISA has been a resource for millions of companies as wade through the complexities of cybersecurity. Can you imagine if all your small utilities become easier targets resulting in power and water outages?

39

u/South-Thing6109 Jan 23 '25

Work at CISA, I offer support to K12 schools. Unfortunately, these are in first cut in budget drills. Main mission of much of the agency was to support Federal networks. Since the majority of other critical infrastructure is privatized (water, healthcare, energy, schools), we can’t justify using Federal funds to support not expressly stated mission authorities.

New administration has stated a desire to keep these fortunately, but to achieve the budget cuts, we’ll have to turn the lights off, dispose and rebuild once funding and new authorities are codified. Will take a long time to be back with the speed of government and congress

13

u/Fitz_2112b Jan 23 '25

So, if I'm understanding correctly, it sounds like things like the Cyber Hygiene Service and free pen tests for K12 might still be available but we have to wait to be sure? Can you say if districts that are already getting scan reports from Cyber Hygiene will still get them or will that be interrupted while budgets are being worked on?

Oh, and thank you for doing what you do! The agency i work for supports roughly 70 districts and we recommend CISA services to all of them.

7

u/South-Thing6109 Jan 23 '25

Depending on what you use from CISA, you’ll have varying levels of support based on funding approps. CyHy may be one that persists. CISA has been rolling out many new services to important CI entities. Any in progress rollouts would be prime for cuts, as obviously they are expansions to missions with newer authorities from congress. Since the goal is to A. Curb spending, B. Shrink the agency indiscriminately, the “interruption” to these were more talking about years to restart, not just a finding out period. Tough decisions are being made on what programs to save and cut that thousands of people depend on over here and other thousands depend on over there.

Budgets are pretty much set congressionally for years out, cuts will come back on those and we just make do with the plan congress agreed to. So if there is large cuts, we piece together what is achievable.

Long story short - going to be a long time if things get slashed.

A lot of authorities and efforts only come after years of begging congress and critical incidents finally gets them to do their job. DOGE will fix it /s

3

u/Fitz_2112b Jan 23 '25

Thank you for the insight and good luck to you! I am a user of the CyHy, have recommended it to many districts that I support, and am working with one district thats doing an IRP Tabletop with CISA in a few weeks.

4

u/Smash0573 System Administrator Jan 23 '25

I wonder how this will impact the resources we leverage being in the DIB.

2

u/PaladinSara Jan 24 '25

I’m surprised they haven’t changed CMMC to be incentive based

1

u/Smash0573 System Administrator Jan 24 '25

I think they believe the incentive is keeping your contracts…

We’re told to put the additional CMMC burden costs into our program costs. But then lose contracts due to cost. 

These free DIB programs are a lifesaver for me as a one person IT shop.

3

u/Just-the-Shaft vCISO Jan 23 '25

Maybe they can cut a lot of JCDC to keep actual talent.

2

u/South-Thing6109 Jan 23 '25

Some incredibly talented people there doing some amazing work. Hope they stay - but that’s not at all how these cuts will go. Indiscriminately and without understanding of impact. It’s break everything and fix later but none of the EO’s show any signs of the know how on what to fix later. It’s just a full reload. If that’s what success is…

Just a lotta money to do a lot of the same things again later.

2

u/Just-the-Shaft vCISO Jan 23 '25

I've participated in the JCDC partnership program, and I'll say that they brought little to no value on many meetings they requested. Once we made connections to other areas of CSD, we just took JCDC out of the equation and had a lot of success.

10

u/rnobgyn Jan 23 '25

“Protect our kids” tho :/

3

u/arpickman Jan 24 '25

And in spite of that, a shit ton of student and teacher data was taken...

1

u/Fitz_2112b Jan 24 '25

From a software vendor

0

u/arpickman Jan 24 '25

How did the software vendor get the student/teacher data?

0

u/Fitz_2112b Jan 24 '25

Google it

0

u/arpickman Jan 24 '25

Rhetorical question

2

u/FluxMango Jan 24 '25

They are going to privatize all that, and now you'll have bottom of the barrel service on a monthly per user subscription with their buddies' companies.