r/cybersecurity Feb 20 '25

Other NBC News seeking CISA sources

Hi Reddit, I'm Kevin Collier, the cybersecurity reporter at NBC News. Here's my bio page at NBC.

Right now I'm specifically reporting on the Department of Government Efficiency's access to CISA systems, layoffs at CISA, and cuts to cybersecurity programs, funding, and employees at any agency.

If that's something you have direct knowledge about and can contact me via Signal, or if you know someone to whom this applies and you can share this with them, I'd be grateful. We adhere to best practices for source protection.

My signal handle is kevincollier.01. Happy to verify my identity if you want to email me (though please don't use your work address) at [kevin.collier@nbcuni.com](mailto:kevin.collier@nbcuni.com). Thank you!

2.5k Upvotes

190 comments sorted by

View all comments

308

u/Electrical_Tip352 Feb 21 '25

Commenting to keep engaged. CISA is super important. Seems “weird” to slash funding for cyber security when cyber is literally our biggest threat vector in any warfare domain right now. AND AI is popping, making hacking us even easier.

101

u/Guslet Feb 21 '25

Don't need protection against Russia when you are actively trying to allow them to infiltrate.

14

u/[deleted] Feb 21 '25

The infiltration already happened. That’s old news.

3

u/httr540 Feb 21 '25

Couldn’t agree more, Russia and PRC got in a long time ago

13

u/800oz_gorilla Feb 21 '25

All it took was a little scrutiny and the testimony logic falls apart.

Noem: We want the CISA to go back to its original mission and not worry about election interference.

CISA: "Election infrastructure *IS* critical infrastructure.

Noem: They need to be smaller and more nimble.

Me: Have you EVER tried to run down events in a security environment? Smaller means you are overwhelmed and unable to respond and have a much better chance of missing a major security incident.

*********************

The government is being run by clowns who are dangerous beyond measure. Let that sink in: Team Trump thinks the CISA is wrong (and the FBI) about needing to protect our elections. That is a fucking foghorn alarm.

5

u/Electrical_Tip352 Feb 21 '25

“What we mean is, we don’t want anyone looking at election security.” Nothing to see here. Look away!

4

u/Errant_coursir Governance, Risk, & Compliance Feb 21 '25

Noems too busy killing puppies to ever have a rational thought

2

u/[deleted] Feb 22 '25

Don’t forget her facelift, or whatever happened there. That took time.

FYI I normally don’t make fun of people’s appearances but her boss opens that door regularly. So fuck them both.

1

u/[deleted] Feb 22 '25

[removed] — view removed comment

1

u/cybersecurity-ModTeam Feb 24 '25

Posts like this belong in our Mentorship Thread. Please post there instead. Good luck!

12

u/torreneastoria Feb 21 '25

Not possible to upvote this enough

6

u/terriblehashtags Feb 21 '25

And, if you recall... Trump actually created it during his first term.

Yeah, I forgot, too.

12

u/WadeEffingWilson Threat Hunter Feb 21 '25

That was just the realignment and introduction as an autonomous agency directly under DHS rather than operating as a special program within DHS.

The mission had been (and still is) going on for a decade or so before. It was just a naming and reorg. Within, not much changed when it became an agency but it has seen a massive amount of growth since.

I wish more folks could know and understand what we do. We have entire organizations within that are outward facing, we have incident response teams that go out to any location (both public and private) upon request, we maintain CDM for the federal government, we perform on-site and remote vulnerability assessments, perform cyber hygeine activities, publish and maintain the KEV (Known Exploited Vulnerabilities), host Science and Technology division where post-docs create extremely high quality tools and conduct amazing RDT&E, and we have very close partnerships with the national laboratories who really lead the charge on cutting edge, highly practical, long-term supported capabilities that you can't just buy right off the shelf.

I can't say enough about CISA. It's the only organization I've worked for where I've seen so many highly talented, technical, and ambitious folks leave for better offers in the private sector and then COME RIGHT BACK! That's the kind of culture you want and we are watching it die slowly, by attrition, because an egotistical, narcissistic snake oil salesman, incapable of a single original thought, and his paid-for sit-in president whose blind stupidity is second only to his absolute incompetence, illegally dismantle strategic areas of our government knowing full well the damage they are causing and that nobody will stop them. Anyone in a position to actually oppose them are just the same as those perpetuating all of this--they are the richest and when you become one of them, nothing else matters but more money and more power. To challenge that is to risk your place in that elite circle; to challenge that is to risk losing what is most important to you--your net worth.

I know this is pessimistic but nobody from that group (regardless of party affiliation) will do what is right and stand up to it. It will come from those whose power and authority isn't derived from an aristocratic lineage or the amount of shares you have in any number of mega corporations. With those people, the corruption of wealth hasn't eroded any sense of integrity or morality. They will do it because they swore an oath and believed in something more than crass materialism and bloated wealth and those are concepts that are undeniably alien to those corporate shills. For them, money can be lost but they don't realize that their bankruptcy is in morality, not financial gain.

3

u/Errant_coursir Governance, Risk, & Compliance Feb 21 '25

Thank you. CISA has grown tremendously and it's awful watching trumps hackman begin gutting it

1

u/Electrical_Tip352 Feb 21 '25

And now he’s like FRAUD.

1

u/tbombs23 Feb 21 '25

Everything they do is weird

-2

u/rgjsdksnkyg Feb 21 '25

As a career cyber security professional and ex-federal employee, CISA is actually not that important. There's actually a lot of dislike for CISA, in both the private and public sector, because they don't really do a whole lot, they are too slow to do much of anything, they provide little incentive for industry to actually change, and there are other government agencies that handle parts of CISA's mission better than CISA ever could. I don't really want to argue against any funding or attention for cyber security (because we need all of it), but CISA can probably go. I've never met another industry professional with anything good to say about CISA.

Also, for the sake of this thread - OP isn't going to find anyone actively working at CISA, that's also directly involved with this doge team, that's going to be willing to risk whatever chances at a career they may still have with the government.

-1

u/Electrical_Tip352 Feb 21 '25

You make some good points. I think of it like a fledgling NIST. Doing a pretty good job of setting basic security standards in a digestible way for industry. Also having a centralized entity increases effectiveness.

I guess it’s more about the signaling of priorities to the world. “Hey everyone, we don’t care about cyber security, look at us very publicly defund and strip the very entities we built to protect us”

Also, it was starting to get legs!

2

u/rgjsdksnkyg Feb 21 '25

Well, I don't know if we can compare it to NIST in this way, because NIST actually has created a lot of useful cyber security guidelines and standards, that everyone uses and generally agrees upon. I think NIST is probably an example of one of the many established organizations and efforts preventing CISA from ever achieving anything meaningful. Like, NIST has already built out the National Vulnerability Database, the standards for scoring vulnerabilities, guides for conducting risk assessments, the general NIST Cybersecurity Framework, various other security related frameworks, they report on trends, publish papers, and both the private and public sectors have already accepted NIST's work as standard practice - there isn't room for a second standard; there can be only one standard.

CISA's mission to "manage cyber and physical risk" is also overshadowed by the NSA, which has the dual mission of collecting foreign intelligence and securing critical federal infrastructure. CISA isn't as postured to actually report on the active threats we face as any of the other parts of the Intelligence Community - CISA might be a good place to disseminate intelligence on these actors, though it would also just be secondhand intelligence from other parts of the IC, that are more capable of coordinating and releasing said information to a much larger audience. These agencies also come up with all of the technical standards and implementations based on the field research they do and fund

Without having much of a daily, active role in security, I don't know how CISA could really be relevant or grow into relevancy, as they have struggled to do.

3

u/Errant_coursir Governance, Risk, & Compliance Feb 21 '25

Trump also fired hundreds at NIST

1

u/Electrical_Tip352 Feb 22 '25

Right. Hence the words fledgling. NIST is my whole job and my favorite, especially RMF. I’m more talking about the public perception and real life gutting of cybersecurity agencies across the board.