CISA Seeks 600 Cybersecurity Hires Amid 50% Staffing Shortfall
The Cybersecurity and Infrastructure Security Agency plans to hire 600 professionals to address a severe talent drain that has left the agency at half capacity. DHS Secretary Markwayne Mullin told Congress a new director is expected soon but rebuilding will take a year. The move signals a renewed federal cyber commitment at a critical time.
Key Takeaways
- The Cybersecurity and Infrastructure Security Agency plans to hire 600 professionals to address a severe talent drain that has left the agency at half capacity.
- DHS Secretary Markwayne Mullin told Congress a new director is expected soon but rebuilding will take a year.
- The move signals a renewed federal cyber commitment at a critical time.
Mentioned
Key Intelligence
Key Facts
- 1DHS plans to hire approximately 600 cybersecurity professionals for CISA to address a severe staffing shortage.
- 2CISA is currently operating at about half its intended staffing capacity after losing 1,000 employees, roughly one-third of the workforce.
- 3Secretary Markwayne Mullin estimates it will take one year to rebuild the agency once a new permanent director is in place.
- 4President Trump has already met with a candidate for CISA director, but no name has been publicly disclosed.
- 5The previous nominee, Sean Plankey, withdrew in April 2026 after it became clear the Senate would not confirm him.
- 6Former acting director Madhu Gottumukkala ended his tenure in February 2026; the agency has since been led by acting director Nick Andersen.
To rebuild half-staffed CISA
I want to put the talented individuals that know what they're doing and have partnerships with our state and local officials.
Testimony before Congress
Analysis
For cybersecurity leaders and practitioners, CISA’s staffing crisis has direct implications for threat intelligence sharing, incident response, and critical infrastructure protection. The agency’s reduced capacity means fewer resources for joint cyber defense operations, delayed guidance on emerging threats, and gaps in election security oversight. The planned hiring of 600 specialists signals a renewed federal commitment, but attracting top talent in a competitive market remains a challenge.
The Department of Homeland Security (DHS) has publicly acknowledged that the Cybersecurity and Infrastructure Security Agency (CISA) is facing a severe personnel crisis, with Secretary Markwayne Mullin telling Congress on June 25, 2026, that the agency is operating at roughly half its intended staffing levels. During his testimony, Mullin announced plans to hire approximately 600 cybersecurity professionals and install a new permanent director—a move he described as essential to rebuilding the agency’s reputation as the nation’s go-to source for cyber defense. This declaration comes after a year of leadership turnover, political headwinds, and a voluntary exodus of about 1,000 employees, or one-third of the workforce, during the second Trump administration.
For cybersecurity leaders and practitioners, CISA’s staffing crisis has direct implications for threat intelligence sharing, incident response, and critical infrastructure protection.
The immediate trigger for the hearing was the persistent vacancy at the top of CISA. After former acting director Madhu Gottumukkala ended his nine-month tenure in February 2026, the agency cycled through another acting leader, Nick Andersen, while the White House’s intended nominee, Sean Plankey, withdrew from consideration in April following clear signals that the Senate would not confirm him. Plankey later assumed a CEO role at a defense technology firm in May, leaving CISA without a Senate-confirmed leader for over a year. Mullin revealed that President Trump has already met with a new candidate, but no name has been released, and the confirmation process will likely take months, delaying the full rebuild.
The operational consequences of this hollowing out are profound. CISA is the linchpin of U.S. civilian cyber defense, responsible for protecting critical infrastructure, coordinating incident response, sharing threat intelligence, and assisting state and local governments. With a skeleton crew, its capacity to detect and counteract nation-state threats, ransomware attacks, and systemic vulnerabilities is compromised. Private-sector partners, who rely on CISA for timely alerts and collaborative defense measures, may face longer response times and reduced support during emergencies. The dismantling of the election security program earlier in the administration further eroded the agency’s mandate, even as cyber threats to electoral processes intensify globally.
Mullin’s statement that the agency “actually has the resources we need” suggests that funding is not the bottleneck—talent acquisition is. The 600 targeted hires are not just to fill seats but to bring in specialized expertise and preexisting relationships with state and local partners. This framing highlights a broader labor market reality: the U.S. cybersecurity talent gap remains acute, with over 500,000 unfilled positions nationwide according to industry estimates. CISA must compete with the private sector for a limited pool of skilled professionals, an uphill battle when the agency’s stability and mission are in question.
What to Watch
The one-year rebuild timeline, contingent on the new director’s arrival, underscores the depth of institutional damage. Rebuilding trust, reestablishing partnership networks, and recruiting and vetting 600 cleared personnel will be a monumental management challenge. The agency’s ability to attract talent will hinge on the new director’s vision, the perceived political support from the White House, and whether mission clarity is restored—particularly around controversial areas like election security and counter-disinformation efforts. Without a clear mandate, many candidates may opt for less turbulent careers in the private sector.
For the cybersecurity community, this rebuilding phase is both a risk and an opportunity. In the short term, the reduced federal capabilities could embolden adversaries to test U.S. defenses. However, if the rebuild succeeds, a revitalized CISA could emerge with a sharper focus and a workforce tailored to contemporary threats—cloud security, supply chain risk, AI-enabled attacks—rather than the legacy structures. The upcoming director appointment and the initial hires will signal whether the administration prioritizes a restoration of CISA’s traditional all-hazards role or a realignment toward a narrower, critical-infrastructure-focused mandate. Until then, state and local governments and private-sector CISOs will need to fill the void with their own resources and intelligence-sharing arrangements.
Sources
Sources
Based on 2 source articles- govinfosecurity.comDHS Eyes 600 New Cybersecurity Hires , New Director for CISAJun 30, 2026
- bankinfosecurity.comDHS Eyes 600 New Cybersecurity Hires , New Director for CISAJun 29, 2026
Cite This Page
"CISA Seeks 600 Cybersecurity Hires Amid 50% Staffing Shortfall." Cyber Intelligence Brief, July 21, 2026. https://getcyberbrief.com/story/cisa-600-cybersecurity-hires-staffing-shortfall
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |