From 210 items, 1 important content pieces were selected


Critical Infrastructure

  1. CISA ends six free cybersecurity assessments amid budget cuts ⭐️ 7.0/10

Critical Infrastructure

CISA ends six free cybersecurity assessments amid budget cuts ⭐️ 7.0/10

The Cybersecurity and Infrastructure Security Agency (CISA) has discontinued six free cybersecurity assessments that critical infrastructure operators previously used to evaluate operational technology (OT) security. Tatyana Bolton, executive director of the OT Cyber Coalition, attributed the cuts to severe budget reductions that have constrained the agency’s capacity. The source does not specify which six assessments were eliminated, an effective date, or the number of operators affected, and CISA’s official position on the change is not detailed in the reporting.

rss · Utility Dive · Sep 3, 15:35

Federal cybersecurity support for utilities The Cybersecurity and Infrastructure Security Agency (CISA), part of the U.S. Department of Homeland Security, has long offered free vulnerability assessments to help owners and operators of critical infrastructure identify weaknesses, interdependencies, and gaps in operational technology security, particularly benefiting smaller utilities and municipal operators that lack in-house resources for such evaluations. These assessments have served as a baseline federal support mechanism for sectors like water, electricity, and rail, filling a gap for organizations without the budget to hire private cybersecurity consultants. The reported change follows sustained budget pressure on the agency, which one industry advocate described as forcing difficult tradeoffs in what services it can still provide.

What an operator should do Operators that relied on CISA’s free assessments, particularly smaller utilities, water systems, and rail operators without in-house OT security teams, should inventory which of these services they used and identify substitutes, whether commercial assessors, sector-specific information sharing and analysis centers, or state-level programs. Security and risk management functions should budget for this gap now rather than discovering it at the next audit or incident, since the shift moves both cost and scheduling risk onto the operator. Larger transmission and distribution utilities with established OT security programs are likely less exposed than smaller municipal or rural systems that had no alternative funding for these evaluations.

Constraints The practical impact depends on details not provided here, including which six assessments were cut, whether any replacement federal or state programs exist, and how quickly commercial alternatives can be procured and scheduled, especially for smaller operators with limited cybersecurity budgets and staff.

References

Tags: #OT cybersecurity, #CISA, #regulatory capacity, #critical infrastructure policy, #budget cuts