Technology 5 min read By Callum Montgomery
CISA Scales Back Six Free Cybersecurity Programs, Experts Warn Smaller Organisations Lose Vital Support
The US cybersecurity agency has streamlined its free assessment services, removing hands-on expertise and third-party validation that small businesses and local authorities relied on most.
The US Cybersecurity and Infrastructure Security Agency (CISA) has quietly scaled back six of its free cybersecurity programs, replacing them with a streamlined questionnaire that experts say cannot replicate the hands-on expertise or independent validation that smaller organisations depended on. The change affects a suite of voluntary assessments that helped hospitals, schools, local councils and small businesses identify vulnerabilities without hiring costly consultants.
According to experts familiar with the programmes, the new self-assessment tool lacks the depth of the previous on-site evaluations, which included penetration testing, configuration reviews and tailored advice from CISA engineers. Those services were particularly valuable for organisations with limited IT budgets and no dedicated security staff. The agency has not publicly detailed which six programmes were cut, but the shift forms part of a broader effort to reduce the federal government’s direct operational role in cyber defence.
«The hands-on expertise that CISA provided was often the only way a small water utility or rural clinic could find out it was exposed,» said one former agency official, who spoke on condition of anonymity. «A questionnaire will tell you if you have a policy, but it won’t tell you if your server is misconfigured or your backups are accessible from the internet.»
The free programmes also offered a form of third-party validation that many organisations used to demonstrate due diligence to insurers, regulators and boards. Without that external stamp of approval, smaller entities may struggle to prove they have taken reasonable steps to protect data, potentially affecting insurance premiums and compliance with frameworks such as the UK’s Cyber Essentials or the US NIST guidelines.
Cybersecurity experts warn that the retreat comes at a time when ransomware attacks on local government, healthcare and education are rising. Smaller organisations are already the most likely to pay ransoms because they lack the resources to recover from backups. The loss of free assessments could widen the gap between large corporations, which can afford private sector audits, and the public services that underpin daily life.
«The most vulnerable are the ones who will feel this first,» said a security researcher who has worked with CISA on previous assessments. «A hospital in a rural area doesn’t have a chief information security officer. It relied on CISA to come in and say, here are your top five risks. A questionnaire won’t do that.»
The agency has defended the changes as a necessary modernisation, arguing that the new questionnaire can reach more organisations at lower cost. But critics counter that reach without depth leaves critical infrastructure exposed. They point out that many of the organisations that used the free programmes are part of the critical national infrastructure, from water treatment plants to election offices.
The shift also raises questions about the UK’s own cyber support ecosystem. While CISA is a US agency, its free tools and guidance are widely used by British firms and public bodies. The UK’s National Cyber Security Centre (NCSC) runs its own free services, including the Early Warning and Active Cyber Defence programmes, but those are not a direct substitute for CISA’s bespoke assessments. British organisations that relied on CISA’s cross-border expertise may now find themselves with fewer options.
Industry groups have called on CISA to publish a full list of the discontinued programmes and to explain how the new questionnaire will address the gaps. They also want assurances that the agency will continue to offer incident response support, which is separate from the assessment programmes but equally vital for small organisations facing an active breach.
For now, the practical effect is that many small entities will have to rely on self-assessment or paid consultants. Experts say that will inevitably lead to some risks going unnoticed until it is too late. «You can’t secure what you don’t know is broken,» said one adviser. «And most small organisations don’t know what they don’t know.»
7



