The Circus at CISA Continues – Shimmy Says Ep 50
The leadership situation at CISA continues to raise questions.
In this episode of Shimmy Says, Alan “Shimmy” Shimel looks at the latest controversy surrounding the nominee to lead the Cybersecurity and Infrastructure Security Agency and what it says about the state of America’s cyber defense leadership.
With workforce reductions, budget pressures, and rising geopolitical tensions, the timing of this latest development could not be worse.
Shimmy also discusses the surprising absence of major U.S. cyber agencies from RSA Conference and what that might signal about government-industry collaboration.
Transcript
Hi everyone, it's Shimmy, and welcome to my second Shimmy. Says this week, if you didn't catch my one yesterday about Apple being the AI of choice for the Edge, check it out. It's a great one.
But today I wanted to talk about something else, and unfortunately it's a little more serious. I think, you know, I wrote over the last couple weeks I've written several articles about cso. It started with when they took their ball and went home because Jen Easterly was made the CEO at RSA conference, RSAC.
But beyond that, I mean, that was just toddler like petulance. But beyond that, the, the problems there are deeper. The first one I wrote was called C on life support.
And the basic point behind that article was that the agency that is tasked with helping defend America's digital infrastructure looked like it was slowly being hollowed out from the inside. Their budgets were cut, their people were cut, they were reassigned, budget was moved over, leadership was let go vengeful kind of political stuff in, in the way of not, not, not keeping the right people, not the kind of shut stuff that maybe shows up in a dramatic headline, but the kind of stuff, it's like a slow institutional death. 'cause it catches up to you, the people, the people are the heart and soul of the organization.
You know, a few days after that, I wrote another piece that things were worse than we thought, right? Because when they let Jen Easterly go, they never had a permanent replacement put in and that they finally nominated someone, but he was being, he wasn't replaced yet. So they had a temporary, uh, direct to put in.
Well, this article and the article that I wrote there was, based upon what came out with that, that, you know, the public story we were talking about was just part of the mess. Internally, things were even a bigger s**t show, and I'm sorry to say it, but a s**t show, you know, turmoil, confusion about direction, morale issues, institutional rot that makes people nervous when they actually realize what the mission is over there. And then this week we got another story.
So they fired that temporary director because he really was a clown. And they, you know, the guy who's been nominated and has not been approved, and then he was renominated, he's still not approved. Well, CBS news reports the other day that, you know, while he was waiting to get approved, he's been, uh, appointed a senior advisor at the Department of Homeland Security working with the Coast Guard.
Well, it seems he was escorted out of the building yesterday and dismissed from his position. No one knows why, but you don't get escorted out of the building with your dismissal unless something, something's going on. And according to the reporting, his access badge was taken away.
So not only was he escorted outta the building, he was told, don't come back. Now, look, they haven't given no one, they've been mom on what this was all about. So we don't know what really happened here.
We don't have an explanation. And I'm eventually, I'm sure we'll find out more of the details. But looking at what we know right now, you gotta wonder, is that the person you want running csa?
And how much longer is he still gonna be the designated, uh, supervisor, administrator for csa? The government, you know, the administration still, still insists he's their man, but if, if this happened to him, is this really someone you want running csa especially on top of what's gone on here lately since the, the, the, the firings, the layoffs, the budget cut, the mission scope change, you know, 'cause being walked out of a federal facility and having your credentials pulled, it's not usually how a normal job transition works. I think you have to agree.
It's the kind of things that tend, it's the kind of thing that tends to raise questions. And guys, like I said, we've got enough questions, but the biggest one is an obvious one. What the hell is going on at Cesar?
It's like a circus worse than a circus. It's like a clown show. This agency's already dealing with enough problems.
The leader leadership situation has been unstable now for a long time. Budgets have been cut, people have been transferred, other good people have left with the government shutdown, there's like a thousand people there now. The workforce is still shrinking by all accounts, morale has taken a huge hit.
Is this really how you wanna run the central cyber defense agency that's tasked with taking care of critical infrastructure on stuff like what's going on there now, continuity experience, relationships between government and industry. People who know how systems work and can pick up the phone during a crisis and movings and get things moving. You don't build that overnight.
This takes time. It takes culture, it takes people. And when you lose it, like they've been losing it, rebuilding.
It can take years, I'm afraid. So when the nominee to run the agency suddenly shows up in the news because he was escorted out of a building, people should take notice. You know, they say what they mean, they mean what they say.
Even if this story does eventually turn out to be something else, the optics are just not good. There's another piece of the puzzle though, that we gotta think about. And I wrote about it as well this week.
I we're at war. We're at war with an adversary who has invested for asymmetrical, uh, cyber warfare. They are desperate.
They're, they're getting pounded every day. If you don't think they're gonna unleash the dogs, and we're gonna see cyber attacks and cyber terrorism, you're crazy at the same time, right? When we need our federal cyber defenses to be working hand in hand with private industry, what do they do?
They boycott RSA 'cause they had a hissy fit. The Jen Easterlies over there. An event with tens of thousands, 40, 45,000.
Every vendor practitioner you could think of, no interaction with the government there because they took their balls and went home. It's not the way the cyber cybersecurity community works. It works by collaboration, by working together.
Government itself can't defend the internet and industry itself can't defend critical infrastructure. Both of them have to work together. And I, it's not happening at CSA right now.
So all of this has raised a lot of eyebrows. When it becomes clear that csa, the FBI and the NSA are basically taking their ball and going home, not showing up the way they normally do, not interacting, this is, this is highly unusual. It's highly dysfunctional.
Now, as I mentioned before, we're at the middle of a war with Iran that has cyber. There's so much going on in, you know, the geopolitical moment here. Is this really the time we want CSA to be a circus?
It, it, it can't be. We need to step back here and look at all of this, you know, mil, this military con. They, we sh we sunk a ship in Sri Lanka by submarine.
The whole Middle East is being attacked. The, that region is volatile. Iran's not the only cyber terrorist capable organization.
There. You have all the proxies in Iraq and Lebanon and the Houthis. And, and make no mistake, Iran has spent years developing these cyber capabilities in the past.
They've already targeted banks, they've targeted infrastructure. If you don't think they're gonna do it this time, I don't know where you know, where you're getting your information. 'cause at the, the, at the end of the day, it's probably one of the only avenues they have left for an asym asymmetric, uh, asymmetrical attack.
They don't have much left. So as things become more desperate, desperate people do desperate things, and we're gonna see desperation in cyber attacks. It's exactly the time that we need csa, right?
It's so this is, this moment's a particularly bad time for leadership and chaos. Bad morale at this, at America's cyber defense agency, which is what Cesar is. This is exactly the time we need stability.
We need people who've been at the helm to be back at the helm. It's when you want the private sector to be confident that they have a stable partner in the government side of it that's working smoothly. That together we can weather this potential attacks from this enemy.
But instead we have confusion. We have a circus, we have budget fights, we have leadership drama, we have innuendo, we have morale, we have just craziness. We have a nominee who just was in the news for being warped out.
The three major cyber organizations stepping back from RSA, this is like a perfect storm of dead crap going on in normal times. I'd say it's, it's worrying. But in today's times, I'd say this could be a catastrophe in the making.
Let me say something though. The people inside csa, the ones who actually go in and go to work every day, even with this government shutdown, you know, they're good people. Some of the best people, they left their private sector jobs to serve the country.
They're talented people who believe in the mission at csa and in spite of all this, they show up every day trying to keep things running. But you can't run these institutions on fumes forever. And on the dedication of the staff alone, they need leadership.
They need resources, they need stability, they need, they need supporters. And they're not getting it right now. It looks more and more shaky.
And, and, and here's another thing to remember. Do you think the criminals, do you think the Iranian cyber attackers are saying, oh, let's wait for Washington to sort itself out. Let's wait till they appoint a new director.
No, they don't pause or wait. They see a weakness. They see an opening.
And this is, and we're vulnerable. Critical infrastructure operators don't get to delay attacks until the organizational charts finalized. Guys, these are real constant threats that we gotta deal with now.
And that's why this current situation, you can laugh and say send in the clowns, but it's frustrating and it's a potential catastrophe waiting to happen. The pol politic politicalization over its csa, the budget fights the chaos. Well, it's all part of what Washington is today.
This administration thrives are just creating chaos. But chaos doesn't work when the world comes crashing in. We hope.
I hope you should hope that the professionals who are still inside there can keep this system running. That they can continue to coordinate with the private sector. They can continue to defend the infrastructure that our country depends on.
Because if the instability continues much longer, there's not much hope there. We may eventually learn something or lesson here the hard way. Now when the circus comes to town and they set up the big top, at the top of the nation's cyber defense eng agency, it's really isn't time to send in the clowns guys, not a clown show.
Anyway, that's it for this episode of Shimmy Says, I hope you en enjoyed the whole week worth of shimmy text on gang. Hey, if you want the full breakdown on this, I do have an article up on Security Boulevard called The Circus at CSA Continues. I'll see you next week on Shimmy says on the gang, enjoy your weekend.
We're out. Let's stay safe. Says.





