Two high-ranking officials from the Cybersecurity and Infrastructure Security Agency, known as CISA, have resigned amid concerns of a potential staff exodus due to recent budget cuts. Bob Lord and Lauren Zabierek both announced their departures on LinkedIn, emphasizing their contributions to the Secure by Design program, which aims to enhance security in software development. The resignations come as CISA faces the possibility of cutting nearly 40 percent of its workforce, which equates to around 1,300 employees. This follows a recent reduction in funding that cut $10 million from the Multi-State Information Sharing and Analysis Center, nearly half of its budget. The agency’s acting director has indicated that while the Secure by Design initiative may evolve, its commitment to improving cybersecurity remains unchanged. Concerns about these changes reflect broader worries about the impact of the current administration’s policies on national cybersecurity efforts.
The Cybersecurity and Infrastructure Security Agency has notified its threat hunting staff that it will discontinue the use of Google-owned VirusTotal and has already ceased using the cyber threat intelligence service Censys. These changes come amid broader budget cuts within the agency, affecting over 500 cyber threat hunters. CISA’s notification highlighted the importance of these tools for their operations and indicated that the agency is actively seeking alternatives to minimize disruption. Recent reports suggest that the agency may be ending all threat hunting contracts with the private sector, raising concerns about its capability to effectively address cyber threats.
The Pentagon is set to implement a secure software assurance program aimed at enhancing the security of applications used within its networks. This initiative, led by Rob Vietmeyer, the Chief Software Officer for the Department of Defense, will establish criteria for vendors to ensure their software meets security standards, akin to the Cybersecurity Maturity Model Certification program. Vietmeyer emphasized the need to accelerate discussions with industry partners to establish trust in software components and their development pipelines. In the coming weeks, the Department of Defense will issue Requests for Information to gather feedback on security controls necessary for software products, as adversaries increasingly target vulnerabilities in the software supply chain. The overarching goal is to create a streamlined authority to operate process, significantly reducing the time needed for risk management assessments and ensuring that software installed does not introduce unacceptable risks into the defense environment.
Why do we care?
If CISA falters, who fills the gap? For MSPs, this isn’t just policy-watching—it’s a business model decision. Providers who pivot to embed Secure by Design, and vendors who embrace it, into their offerings can claim real estate that regulators, customers, and insurance providers will increasingly demand.

