Reduction in Federal Cybersecurity Support Raises Critical Infrastructure Security Alerts
The U.S. government's plan to cut cybersecurity support for critical infrastructure has raised industry concerns. Experts note that budget reductions and responsibility shifts will exacerbate vulnerabilities, particularly impacting smaller operators.

As the U.S. government prepares to reduce cybersecurity support for operators of critical infrastructure, those responsible for defending these networks are bracing for more vulnerabilities, more hacks, and greater damage.
President Donald Trump's push to reduce the federal role in infrastructure cyber resilience — part of his drive to streamline government and cut services — will worsen already alarming cybersecurity weaknesses in hospitals, ports, railways, and other critical systems nationwide, according to industry leaders and cybersecurity experts.
Trump's chaotic government overhaul has already disrupted vital partnerships between infrastructure operators and federal agencies, as Cybersecurity Dive recently reported. Now, the Trump administration's proposed budget cuts and its plan to give states more responsibility for infrastructure protection could further weaken America's ability to fend off digital threats such as China-backed cyberattacks and a wave of criminal ransomware.
If federal agencies step back as Trump envisions, infrastructure operators may need to scramble to find expensive new sources of cybersecurity advice and assistance. While the impact will ripple across the critical infrastructure sector, smaller operators such as rural hospitals and water utilities will be hit especially hard.
"Government-supported services have been a 'lifeline' for these operators," said Grant Geyer, chief strategy officer at industrial cybersecurity firm Claroty. "Without them, these smaller critical providers are essentially left to fend for themselves in an increasingly dark cyber wilderness."
An 'absurd' shift
Over the past six months, budget cuts have forced tens of thousands of federal workers out and ended many contracts supporting key government functions. The Cybersecurity and Infrastructure Security Agency (CISA), the government's primary cyber defense agency, lost a third of its staff. The program and personnel cuts already made foreshadow more to come, as the Trump administration pushes a strategy of shifting critical infrastructure security responsibilities to state and local governments.
In March, Trump signed an executive order that effectively froze former President Joe Biden's critical infrastructure partnership strategy and directed Sector Risk Management Agencies (SRMAs) — which provide security support and guidance to various industries — to revise their infrastructure protection strategies. In May, the administration proposed a budget that would cut teams within CISA responsible for liaising with infrastructure operators and coordinating government support.
"It feels like the entire (partnership) program could be in jeopardy," said Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center.
Industry figures and cyber experts say Trump's planned budget cuts could destroy agencies' ability to help operators by offering free services such as vulnerability scanning, sending experts to assess systems, and developing highly tailored guidance and recommendations. The result could be more weaknesses in critical infrastructure for hackers to exploit.
The cuts would also "make it harder for SRMAs to maintain relationships with their industries, conduct oversight, or develop effective policy," said Michael Daniel, president of the Cyber Threat Alliance, an information-sharing coalition, and former White House cyber advisor to President Barack Obama.
Moreover, the disproportionate impact of cuts on smaller rural infrastructure operators would widen the existing preparedness gap between well-funded and underfunded organizations.
The White House wants states to take over some of the federal government's work. "Readiness is most effectively owned and managed at the state, local, and even individual level, supported by a capable, accessible, and efficient federal government," Trump said in his March executive order.
But cash-strapped state and local governments, already struggling to help protect infrastructure as shown in the aftermath of many natural disasters, may find it difficult to take on these significant new cybersecurity responsibilities.
Experts say Trump's burden-shifting plan would be disastrous for critical infrastructure.
"The idea of pushing cybersecurity responsibilities to the states," Weiss said, "is absurd."
State and local governments "are not built to fight nation-state actors in cyberspace, nor are they ready," said Frank Cilluffo, director of Auburn University's McCrary Institute for Cyber and Critical Infrastructure Security.
CISA assistance at risk
For years, CISA has developed and refined a suite of free security services for critical infrastructure operators. The agency conducts threat hunting on companies' networks, performs "cyber hygiene" scans of their internet-exposed assets, assesses their defense practices, helps them understand third-party risks, and helps them plan and execute cyberattack simulation exercises to understand their shortcomings. CISA is even testing the inclusion of infrastructure operators in free security programs originally limited to other federal agencies, such as protective DNS.
These free tools and services are central to CISA's role as the core of the federal government's critical infrastructure defense. For small water utilities, rural hospitals, and other financially struggling infrastructure providers, having access to help that is often too expensive to obtain for free is transformative.
But with all of Trump's cuts, operators worry the free help won't last. Trump's proposed CISA budget would cut funding for vulnerability assessments, training courses, and shared services such as security operations centers. The administration has already terminated threat hunting contracts and reduced resources for threat hunters.
Experts warn the consequences would be dire if cybersecurity assistance disappears.
CISA's services "are critical for under-resourced critical infrastructure operators facing sophisticated foreign threats," said Victor Atkins, global director of security and risk strategy services for industrial cybersecurity at consulting firm 1898 & Co.
The agency's "great free services" are so popular that some have waiting lists, said John Riggi, national advisor for cybersecurity and risk at the American Hospital Association.
If CISA significantly scales back these services, Atkins said, "the defense of utilities will be weakened precisely when they are needed most."
The White House may view infrastructure cybersecurity as an area where states can take on some of Washington's duties, but Daniel said "it is unrealistic to think states can take over the missions and activities CISA is giving up," because "budget pressures states face from cuts in other federal funding will hinder significant investment in cybersecurity."
CISA declined to commit to maintaining the breadth and depth of services it currently offers. "We support critical infrastructure operators across the nation every day through robust cybersecurity services, and our commitment to this mission is unwavering," agency spokesperson Marci McCarthy said in a statement. "Operational collaboration means we work side by side with our partners, providing the tailored services and support they need to help defend against the evolving threats they face every day."
Given the interconnected nature of many infrastructure sectors, reduced support could have cascading effects. Daniel noted that U.S. military bases rely on local utilities for water, many of which have been found to use default passwords and vulnerable equipment. "If one system is hacked," said a water industry representative who requested anonymity, "it could have serious consequences for national security."
Agencies diverge in paths
CISA is not the only agency providing vital services and other assistance to infrastructure providers. SRMAs, such as the Environmental Protection Agency (water), the Department of Health and Human Services (healthcare), the Department of Energy (energy), and the Transportation Security Administration (pipelines, rail, and aviation), also issue guidance, conduct site visits, and provide technical support.
These agencies have also signaled different futures for their assistance.
An EPA spokesperson said the agency "intends to continue its free cybersecurity services" because they "align with the government's goal of strengthening the capabilities of state and local governments and water systems to build resilience." One such service, a program that proactively scans utility computer networks for vulnerabilities, "has produced more than 400 mitigations since October 1," the spokesperson said. In its fiscal 2026 budget proposal, the EPA requested $10 million for a state water cybersecurity competitive grant program.
TSA did not respond to a request for comment on its commitment to cyber support. But its proposed budget envisions adding 21 employees and $5.4 million for work overseeing and supporting transportation infrastructure security.
The situation is different for other SRMAs.
HHS has downgraded the office responsible for supporting critical infrastructure sectors, and industry representatives worry about the state of the health sector's once-struggling but now more promising cybersecurity coordination center. An HHS spokesperson said cybersecurity is a "key priority" and the department continues "to work with internal and external partners to update our risk analysis tools."
Meanwhile, at the Department of Energy, the Trump administration wants to cut the budget of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER) by 25%, even while acknowledging that cyber and physical threats "are converging to form a complex and persistent threat landscape." An Energy Department spokesperson told Cybersecurity Dive that CESER "continues to work with our state and local partners to ensure the security of our energy systems," but declined to respond to concerns about service cuts.
Human security concerns
Experts and industry leaders say the signal that the U.S. government will reduce support for critical infrastructure could not come at a worse time. Threats from foreign government adversaries and cybercriminals are increasing, artificial intelligence is enhancing hackers' capabilities, and digitalization is creating new vulnerabilities in operational technology. Infrastructure entities say they have never faced a more dangerous cybersecurity environment.
The healthcare sector provides a stark example of these challenges. "We've seen how bad it is with ransomware still regularly hitting hospitals," Weiss said. These attacks are disrupting patient care, said a healthcare industry representative who requested anonymity, adding that "the urgency of cybersecurity is more about patient safety than ever before."
Given these trends, experts say the government should deepen investment in critical infrastructure security, not scale it back.
"At a time when CISA, NSA, and FBI warn that adversaries like Russia and China are actively targeting the cyber-physical systems of critical infrastructure," Geyer said, "withdrawing support from the entities that keep hospitals running and water systems flowing would be profoundly shortsighted."