TMCnet Feature Free eNews Subscription
April 14, 2025

The CIO-CISA Disconnect: Is the Agency Still Effective in Cybersecurity?



In 2018, the US federal government decided its national cybersecurity response needed an overhaul. The result was the creation of the Cybersecurity and Infrastructure Agency, commonly known as CISA.

“With the advancement of technology and our increased dependence on computer networks, nation states, hackers, and cybercriminals are finding new ways to target our critical infrastructure,” said Representative Michael McCaul (R-TX), who introduced the bill that ultimately established the cybersecurity agency. CISA, McCaul said, would elevate US cybersecurity efforts to address new threats.

Yet, the increase in cybercrime in the eight years since CISA began its work has caused some experts to be concerned the agency may not be living up to its mandate. As statistics from the World Economic Forum show, monetary damage caused by cybercrime has skyrocketed in the US under CISA’s watch, increasing from $2.7 billion in 2018 to $12.5 billion in 2023.

“CISA has acted as a vital informational agency over the last few decades in creating materials, processes, and a centralized hub for Chief Information Officers (CIOs) and other corporate executives charged with protecting their organizations from cyberattacks,” says Yashin Manraj, CEO of Pvotal Technologies. “However, the agency's effectiveness has often been called into question as the number of cyberattacks in the same period has consistently and exponentially increased.”

Pvotal Technologies provides companies with the technology and vision to build sophisticated enterprises without limits. Its solutions lead to infinite enterprises that give business leaders the control over technology systems required to drive operational efficiency and experience industry-leading productivity gains. Manraj’s deep technical knowledge from product development, design, business insights, and coding gives him a unique nexus to identify and solve gaps in the product pipeline.

CISA’s mission

According to its website, CISA’s mission is twofold. First, it fosters connections between stakeholders in the industry and the government. Second, it provides those stakeholders with resources, analyses, and tools that allow them to construct effective cybersecurity frameworks. The overall impact of its efforts, CISA says, is a “secure and resilient infrastructure for the American people.”

The resources and tools CISA makes available include:

  • Factsheets on infrastructure components found to have vulnerabilities.
  • Publications providing guidance on a variety of best practices developed by the agency.
  • Playbooks designed to empower companies to take advantage of new security protocols.
  • Alerts on emerging attack vectors that include steps for addressing them.

The list of resources CISA makes available through its website is extensive, with over 80 posted during 2024. However, it seems the resources are going to waste due to a lack of effective outreach. According to experts like Manraj, this is because the CIOs, Chief Information Security Officers (CISOs), and Chief Security Officers (CSOs) who should be benefiting from CISA’s work aren’t tapping in.

“Unless CxOs already have an eagerness or awareness of cybersecurity concerns, we found that CISA was unlikely to be beneficial or even leveraged properly,” Manraj shares. “The agency has drifted away from its core functionality with the amount of PR designed for PR's sake rather than highlight the value it can provide preemptively, during an attack, and following one, for suitable clients.”

The challenge before CxOs

The disconnect Manraj highlights comes at a time when CIOs and other cybersecurity professionals need more help than ever. The threats they face have increased in both volume and sophistication, making it paramount that CIOs stay up to date on trends and persistent in applying best practices proven to be effective.

CIOs also must address ever-expanding attack surfaces. Cloud computing, remote work models, and Internet of Things (IoT) devices all add new vulnerabilities. Securing an ever-expanding network requires enhanced strategies and more resources.

The biggest challenges today’s CIOs face, however, may be a lack of human resources. Studies show today’s companies are dealing with a cybersecurity talent crisis, with an estimated 4.8 million professionals needed around the globe. If companies don’t have the workforce required to bring strategies to life, no amount of publications or playbooks from CISA will help to bolster security.

To address the talent shortage, the US House of Representatives Homeland Security Committee recently introduced a bill to launch a scholarship program for two-year cybersecurity degrees at community colleges and technical schools. Representative Mark E. Green (R-TN), who introduced the bill in late 2024 and reintroduced it in February 2025, says its provisions could equip “up to 10,000 cyber professionals per year with industry-relevant skills.”

If the bill, which is known as the Providing Individuals Various Opportunities for Technical Training (PIVOTT) to Build a Skills-based Cyber Workforce Act of 2025, becomes law, it would give CISA an opportunity to improve its outreach efforts. According to Representative Green, the bill “maximizes CISA’s existing resources, relationships with the public and private sectors, and expertise to address the current skills gap between education and work.”



» More TMCnet Feature Articles
Get stories like this delivered straight to your inbox. [Free eNews Subscription]
SHARE THIS ARTICLE

LATEST TMCNET ARTICLES

» More TMCnet Feature Articles