The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed it is ending six free assessment programs long used by critical infrastructure operators to evaluate their cybersecurity posture, Cybersecurity Dive reported.
What’s New
CISA’s regional field staff will no longer conduct Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys. All six relied on CISA’s Cyber Security Evaluation Tool (CSET). Acting Cybersecurity Division head Chris Butera said eliminating the “legacy assessments” would “reduce redundancy for CISA and organizations requesting an assessment,” adding that operators can instead reference CISA’s Cybersecurity Performance Goals.
Why It Matters
Experts told Cybersecurity Dive that the Cybersecurity Performance Goals are not a substitute for the hands-on, in-person guidance the discontinued assessments provided. Tatyana Bolton, executive director of the OT Cyber Coalition, said “severe budget cuts have forced CISA into a corner where they can no longer provide the level of hands-on, operational support to critical infrastructure that they once did.” The change follows a reported loss of roughly a third of CISA’s workforce and comes as small utilities and rural operators — among the heaviest users of the free assessments — face rising cyber and physical threats with fewer federal resources to call on.

Leave a Reply