While we’re on the regulation front.
Oregon Senator Ron Wyden announced that he is blocking the nomination of Sean Plankey to lead the Cybersecurity and Infrastructure Security Agency. He cites the agency’s ongoing refusal to release a crucial unclassified report from 2022. This report outlines security issues within U.S. telecommunications companies, which Wyden describes as a “multi-year cover-up” of negligent cybersecurity practices. He argues that the public deserves to see this technical document, as it does not discuss policy options and is essential for understanding current threats and the need for improved cyber defenses. Wyden’s statement follows the fallout from the Salt Typhoon hack, which compromised multiple telecommunications companies and exposed sensitive communications, including those of Vice President JD Vance and former President Donald Trump. The senator has been urging CISA to publish the report since July 2022, but the agency has cited a “deliberative process privilege” as the reason for withholding it. Wyden claims that U.S. telecommunications companies still fail to meet minimum cybersecurity standards, leaving critical vulnerabilities unaddressed.
The Cybersecurity and Infrastructure Security Agency is also facing potential cuts that could affect nearly 40 percent of its workforce, with reports suggesting that up to 1,300 employees may be laid off. Experts warn that these reductions could significantly weaken U.S. national security amid rising cyber threats from nation-state actors. Recent layoffs at CISA included critical personnel, such as threat hunters, which could hinder the agency’s ability to share vital threat intelligence with the private sector. In March, CISA also slashed funding by ten million dollars for the Multi-State Information Sharing and Analysis Center, which is crucial for state and local governments’ cybersecurity efforts.
Former Cybersecurity and Infrastructure Security Agency Director Chris Krebs has pledged to combat a federal investigation initiated by President Trump, which accuses him of falsely asserting that the 2020 election was not rigged. In an interview, Krebs announced he will resign from his position at cybersecurity firm SentinelOne to address these allegations, which include the loss of his security clearance. Krebs, who was appointed by Trump in 2018, was dismissed in November 2020 after affirming the integrity of the election results. He emphasized that the government is using its power to suppress dissent and target corporate relationships.
Finally, nearly all staff members of the Defense Digital Service at the Pentagon are resigning, following pressure from the Department of Government Efficiency led by Elon Musk. This mass resignation, expected to be completed by May 1, will effectively shut down the program, which was created in 2015 to accelerate technology adoption during national security crises. The Defense Digital Service played a crucial role in developing rapid response tools during the Afghanistan withdrawal and other key initiatives. Jennifer Hay, the director, stated that the team had hoped to contribute to Musk’s plans for automating operations and adopting artificial intelligence, but felt sidelined by the new department’s direction. As a result, the Pentagon’s “SWAT team of nerds” will dissolve, reflecting broader challenges faced by digital modernization efforts within the government.
Why do we care?
This cluster of stories—Wyden’s blockade, layoffs at CISA, Krebs’ legal battle, and the collapse of the Defense Digital Service—exposes an unraveling of U.S. cybersecurity leadership and modernization capability at a time when threats are escalating.
I was criticized recently for saying the CISA cuts could not be overstated. I’ll cede perhaps over-amplification of the message. Some may argue this is just bureaucratic noise—that day-to-day cybersecurity operations continue regardless of who leads CISA or whether one team leaves the Pentagon. That’s only partly true. The internet and cyber threat landscape operate on trust, collaboration, and speed. Erosion in any of those—especially at the government level—directly degrades the threat response ecosystem.
As I’ve argued here continuously, if you believe selling cybersecurity is key to your customers and your business, then you care very much that the marketplace trust the cyber security market, of which these standards and neutral government groups are part of.

