As Middle East tensions flare following U.S. and Israeli strikes, cybersecurity experts warn of an imminent and heightened threat of Iranian cyberattacks on American infrastructure, while the lead U.S. defense agency, CISA, grapples with severe operational disruptions.
Escalating Iran Cyber Threat
- Iran is likely storing cyber capabilities for a retaliatory strike against U.S. interests, with experts cautioning that the timing is critical. Pavel Gurvich, CEO of Tenzai, noted, "From a timing perspective, it's now or never... the danger is meaningfully higher."
- Recent Iranian retaliatory actions have included physical attacks on U.S. bases and embassies, raising concerns about parallel cyber campaigns targeting critical infrastructure and businesses.
CISA's Operational Downturn
- Due to a partial government shutdown and funding lapse since February 17, 2026, CISA has suspended numerous activities:
- Cybersecurity assessments and training programs are on hold.
- The agency's website is not actively managed, with the last update on February 17, citing a "lapse in federal funding."
- CISA warns that prolonged shutdown will increase vulnerabilities in national defenses.
Leadership Instability and Staff Reductions
- CISA faces leadership chaos: temporary director Madhu Gottumukkala was reassigned after internal conflicts, controversial decisions (including uploading sensitive documents to ChatGPT), and failing a polygraph test.
- Chief Information Officer Bob Costello announced his departure from federal service, amid reports he was asked to resign.
- The agency has lost approximately one-third of its employees since the current administration began, further straining resources.
Congressional and Official Concerns
- Lawmakers, such as House Appropriations Committee Chairman Tom Cole, have warned that CISA is "stretched thin," impairing the U.S. ability to protect critical infrastructure and hospitals during a shutdown.
- Homeland Security Secretary Kristi Noem stated that DHS is monitoring threats with partners, but CISA's diminished capacity hampers effective response efforts.
