News: 1741873514

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

CISA: We didn't fire our red team, we just unhired a bunch of them

(2025/03/13)


The US cybersecurity agency is trying to save face by seeking to clear up what it's calling "inaccurate reporting" after a former senior pentester claimed it laid off the entire Red Team.

The Cybersecurity and Infrastructure Security Agency (CISA) says it has not terminated the entirety of its ethical hackers, although some contracts were withdrawn in line with usual procedure.

"Contrary to inaccurate reporting, CISA has not 'laid off' our Red Team," it said in a statement. "CISA has taken action to terminate contracts where the agency has been able to find efficiencies and eliminate duplication of effort.

[1]

"As good stewards of the taxpayer dollar and in accordance with good fiscal governance practices, CISA regularly reviews contracts across the agency to ensure that we have the capabilities that we need and that we are allocating resources in ways that make the most impact. This was a contract action that did not impact the employment status of CISA personnel."

[2]

[3]

Former CISA employee Christopher Chenoweth said via LinkedIn that he and more than 100 others had their government contracts terminated on February 28, as ordered by Elon Musk's Department of Government Efficiency (DOGE). He said this comprised his entire red team and all support roles, and the following Wednesday (March 5) a second red team tasked with "mission-critical work" was also cut.

The "wall of receipts" listed on DOGE's website, which outlines all the terminated government contracts, now lists 95 total terminations at the Department of Homeland Security (DHS), of which CISA is a part.

[4]

When The Register [5]reported Chenoweth's claims yesterday, the number of terminations stood at 86 for the department, although those figures were only updated as of March 5. The number has since risen to 95, but none mention penetration testing or explicitly relate to CISA's cuts.

CISA's statement went on to say: "CISA's red teams continue their work without interruption. The team works directly with network defenders, system administrators, and other technical staff to address strengths and weaknesses across critical infrastructure networks and systems.

"They continue to assist organizations in refining their detection, response, and hunt capabilities to protect the nation's critical infrastructure from a range of threats."

[6]

Red teams play an important role in fortifying an organization's defenses. Composed of ethical hackers, they simulate cyberattacks that could be carried out by real-world adversaries. Defenses are then shored up to prevent these scenarios. It's a widely used and respected method of improving cyber resilience.

Often conflated with [7]penetration testing , [8]red teaming is different. Penetration testing involves probing specific systems for vulnerabilities that could be exploited by attackers and potentially used to carry out the attacks red teams attempt to simulate.

The two are often deployed harmoniously by organizations looking to improve their overall resilience.

Cuts, cuts, cuts

Among the many cuts DOGE claims total around $20 billion are key information sharing and analysis centers (ISACs), some of which have operated for decades.

[9]Medusa ransomware affiliate tried triple extortion scam – up from the usual double demand

[10]CISA pen-tester says 100-strong red team binned after DOGE canceled contract

[11]Ex-NSA grandee says Trump's staff cuts will 'devastate' America's national security

[12]So … Russia no longer a cyber threat to America?

The Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC) is one of these. Its website now states that the DHS pulled funding and the Center for Internet Security, which oversees the initiative, no longer supports it.

The EI-ISAC's role was to advise election officials and voting machine makers about cybersecurity risks that could impact the integrity of elections. It isn't the first move made by the current US administration to [13]loosen oversight on election security.

Also confirmed this week to be shut down is the Multi-State Information Sharing and Analysis Center (MS-ISAC), which was similarly tasked with informing responses to threats against local and national elections.

It was originally reported by a few select media outlets, but CISA [14]confirmed this week that the news was indeed true.

The revelations were naturally received poorly by the security community, which has spoken out against the cuts in droves.

"The EI-ISAC and the MS-ISAC provide real-time threat-sharing and response coordination that election offices can't replicate by themselves. Losing that coordination leaves towns and counties to fight nation-state hackers on their own," Tim Harper, a senior policy analyst at the separate Center for Democracy and Technology, told The Register this week.

"Many state and local election offices rely on EI-ISAC as their only source of federal cybersecurity support, so cutting it puts entire counties at risk. Defunding EI-ISAC doesn't just weaken election security, it leaves communities wide open to cyberattacks on schools, emergency services, and local governments," he added. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Z9MPMTfmiQq7f-id6OBg0QAAAQQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Z9MPMTfmiQq7f-id6OBg0QAAAQQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Z9MPMTfmiQq7f-id6OBg0QAAAQQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Z9MPMTfmiQq7f-id6OBg0QAAAQQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2025/03/12/cisa_staff_layoffs/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Z9MPMTfmiQq7f-id6OBg0QAAAQQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2024/05/13/ai_xforce_red_penetration/

[8] https://www.theregister.com/2024/09/29/interview_with_a_social_engineering/

[9] https://www.theregister.com/2025/03/13/medusa_ransomware_infects_300_critical/

[10] https://www.theregister.com/2025/03/12/cisa_staff_layoffs/

[11] https://www.theregister.com/2025/03/05/us_government_job_cuts_nsa/

[12] https://www.theregister.com/2025/03/04/russia_cyber_threat/

[13] https://www.theregister.com/2025/02/26/dhs_cisa_doge/

[14] https://therecord.media/cisa-cuts-10-million-isac-funding

[15] https://whitepapers.theregister.com/



Yeah, whatever.

JimmyPage

Which is now my default response to any news from the US now.

Anonymous Coward

This, combined with Congress passing a resolution to make 6 months = 1 day for the purposes of declaring a "national emergency" while the economy is being deliberately imploded feels very Chile 1973 or Democratic Kampuchea if it was run by 4chan shitposters: https://www.congress.gov/bill/119th-congress/house-resolution/211/text

Re: Chile 1973

Anonymous Coward

"while the economy is being deliberately imploded feels very Chile 1973"

To repeat Chile 1973, you need a willing, or even eager, military.

That might require some more work from the Draft Dodger et al. as they have left no opportunity unused to insult the military, servicemen and women, or veterans in the strongest of words.

PR for the Win!!!

lglethal

This reporting is completely false! It couldnt be more wrong! Under no circumstance did we get rid of more than 100 red team members! No way! Didnt happen!!!!

It was 99 testers! And it wasnt a red team... It was more of a maroon colour...

Re: PR for the Win!!!

Chloe Cresswell

My first thought to this:

"Purple alert! Purple alert!"

"What's a purple alert?"

"Well, it's like not as bad as a red alert, but a bit worse than a blue alert -- sort of a mauve alert."

Re: PR for the Win!!!

Andy Non

And when the consequences eventually hit the fan, more of a brown alert.

Re: PR for the Win!!!

Sgt_Oddball

"Step up to red alert!"

"Sir, are you absolutely sure? It does mean changing the bulb..."

Re: PR for the Win!!!

Anonymous Coward

Orange alert surely.

GDP numbers

James Anderson

Government spending is counted in GDP.

It has to be to be enable comparisons between countries that privatise/nationalise differently.

Typically markets, investors treasury departments panic when GDP goes down. Gonna be interesting.

But you shall not escape my iambics.
-- Gaius Valerius Catullus