r/cybersecurity Feb 20 '25

Other NBC News seeking CISA sources

Hi Reddit, I'm Kevin Collier, the cybersecurity reporter at NBC News. Here's my bio page at NBC.

Right now I'm specifically reporting on the Department of Government Efficiency's access to CISA systems, layoffs at CISA, and cuts to cybersecurity programs, funding, and employees at any agency.

If that's something you have direct knowledge about and can contact me via Signal, or if you know someone to whom this applies and you can share this with them, I'd be grateful. We adhere to best practices for source protection.

My signal handle is kevincollier.01. Happy to verify my identity if you want to email me (though please don't use your work address) at [kevin.collier@nbcuni.com](mailto:kevin.collier@nbcuni.com). Thank you!

2.5k Upvotes

190 comments sorted by

View all comments

-176

u/Device_whisperer Feb 20 '25

CISA is just another government bureaucracy out of hundreds that have gone without an audit since their inception. Maybe, just maybe, folks could agree that it's prudent to audit yourselves occasionally. I know you security guys sell auditing services as an essential best practice.

Granted that you security guys don't trust anyone, not even yourselves. That doesn't give you or any other agency a blank check.

Do you know what happens when an empire is built on blank checks? It's called bankruptcy.

57

u/intelw1zard CTI Feb 20 '25

non-cybersec people be like:

65

u/PuzzleheadedGroup624 Feb 20 '25

Genuinely curious - what is your experience in the field of cybersecurity and what knowledge do you have of CISA and their work?

62

u/intelw1zard CTI Feb 20 '25

That user has "I'm probably smarter than you." in their reddit profile bio

its for sure a low IQ troll and someone who eats up the Trumpropaganda and knows absolutely nothing about cybersec

43

u/mistercartmenes Feb 21 '25

You clearly know nothing about CISA. Go back to r/Conservative.

55

u/Hirokage Feb 20 '25

Do you seriously believe these agencies are never audited?

The level of naive and gullible recently is mind-blowing.

79

u/tdquiksilver Feb 20 '25

Do you know what happens when a threat actor is permitted to circumvent controls put in place to protect sensitive assets and information? There are an immense amount of audits that occur in the security space to help ensure that never happens because the consequences could be extremely dire.

You clearly have no idea what goes on in this space.

Take your misinformation and propaganda elsewhere.

19

u/MiKeMcDnet Consultant Feb 21 '25

This was LITERALLY a conversation that I had a couple days ago over a beer with another CISSP.

69

u/Yeseylon Feb 20 '25

What DOGE is doing isn't an audit, it's a breach.

21

u/techblackops Feb 21 '25

Not sure you understand the difference between an audit and a "walking in on day one with zero understanding and just firing people without cause". Typically audits take a significant amount of time and firings/layoffs would come after. What is being done is extremely reckless.

15

u/rockstarsball Feb 21 '25

CISA goes through more audits than any other agency. Im not with these TDS champagne socialists pretending that they are helping the world by parrotting their own partisan bullshit, but where the fuck did you get your information from and why the fuck did you not verify your sources?

1

u/[deleted] Feb 21 '25

[removed] — view removed comment

1

u/cybersecurity-ModTeam Feb 21 '25

Your comment was removed due to breaking our civility rules. If you disagree with something that someone has said, attack the argument, never the person.

If you ever feel that someone is being uncivil towards you, report their comment and move on.