What Is CISA, and Who Does Its Job in Other Countries?

Every big hack story ends the same way. Somewhere around paragraph four, after the breach and the ransom and the outage, comes the line: “CISA has issued an advisory urging users to…” It happened again this month, when CISA warned that Russian state hackers were targeting home and office routers.

If you’ve ever read that line and thought, who exactly is telling me this — this one’s for you. Because the answer turns out to be a good story, the agency is having the hardest year of its short life, and the way other countries handle the same job says a lot about how the internet actually works in each place.

Quick Summary: CISA (the Cybersecurity and Infrastructure Security Agency) is the U.S. government’s civilian cyber defense agency — it warns, advises, and coordinates, but doesn’t police the internet. As of mid-2026 it’s operating with deep budget and staffing cuts and no confirmed director. Other countries split the same job very differently: the UK gave it to a spy agency with a public help desk, the EU spread it across 27 national agencies, and in Russia and China “cybersecurity” mostly means the security of the state.

What is CISA and what does it do?

CISA was created in November 2018, inside the Department of Homeland Security, and calls itself America’s cyber defense agency. Its formal job is coordinating the security of critical infrastructure — the power grid, water systems, hospitals, banks, election equipment, and the software all of that runs on.

The part that touches you is smaller and more useful than the mission statement sounds. CISA publishes plain-language warnings when something dangerous is being actively exploited. It keeps a public list — the Known Exploited Vulnerabilities catalog — of the specific software flaws criminals are using right now, which is what tells every IT department in America what to patch first. And it runs public campaigns like Secure Our World, which is where the advice in my recent post on why your devices suddenly want so many software updates ultimately points.

A useful way to picture it: CISA is a fire marshal, not a fire department. It doesn’t show up with hoses when your network burns — it inspects, warns, publishes the fire code, and occasionally walks through your building pointing at the blocked exits. Whether anyone fixes them is still up to the building.

One thing CISA is not: a surveillance or law-enforcement agency. It doesn’t investigate crimes (that’s the FBI) or hack adversaries (that’s the NSA and Cyber Command). It’s the civilian, defensive, advice-giving branch of the family — a distinction worth holding onto, because it’s exactly what several other countries chose not to do.

A hard season for the agency

Honest reporting requires saying that CISA in 2026 is a diminished version of itself, and that this is partly by design.

The administration’s fiscal 2026 budget proposed cutting roughly $495 million and nearly 1,000 positions — about a third of the agency — and eliminating its election security program outright. The stated reasoning: refocus on the core cyber-defense mission and shed work the administration viewed as overreach, including the agency’s controversial involvement in flagging online misinformation. Critics see it differently; in June 2026, Senator Mark Warner said the cuts had already cost CISA roughly a third of its workforce and left the country more vulnerable.

Sean Plankey withdrew his nomination in April 2026 after 13 months stalled in the Senate, and many of the agency’s divisions are still run by acting leaders.

Both things can be true: an agency can need refocusing and be genuinely weakened by how fast the cutting happened. What’s not in dispute is the timing — as I covered in the updates post, AI has just made vulnerability discovery dramatically faster for attackers and defenders alike, which makes this an odd moment for the referee to be short-staffed. That’s not a partisan observation; it’s a scheduling one.

Meanwhile, the advisories keep coming. The July router warning shows the machine still runs. It just runs leaner.

The same job, four very different ways

Now the interesting part. Every wired country needs someone doing CISA’s job. Who they give it to tells you what the country thinks “security” means.

United Kingdom: the spy agency with a help desk. The UK’s National Cyber Security Centre, founded in 2016, is openly part of GCHQ — the British signals-intelligence agency. On paper that sounds like the opposite of CISA’s civilian model. In practice the NCSC is arguably the most public-friendly cyber agency on Earth: it publishes guidance for ordinary citizens, runs a one-click address for forwarding phishing emails, and operates “Active Cyber Defence” services that quietly take down scam sites at scale. The bet the UK made: put the defenders where the intelligence is, then force them to talk to the public. It has largely worked.

The European Union: twenty-seven agencies and a coordinator. The EU doesn’t have one CISA — it has a national agency in every member state (Germany’s BSI and France’s ANSSI are the heavyweights) plus ENISA, the EU-level agency that coordinates them and writes the rulebook. The EU’s real power tool is law: the NIS2 directive forces hospitals, utilities, and other essential services in every member state to meet minimum security standards or face fines. Where the U.S. mostly advises, Brussels mostly requires — the same instinct behind the European Central Bank giving its banks an October deadline to prepare for AI-driven attacks.

Russia: no fire marshal, only the security service. Russia has no civilian CISA equivalent. National cyber defense runs through the FSB — the domestic successor to the KGB — via a state threat-monitoring system called GosSOPKA, and researchers note Russia has no unified cyber command and no published cyber strategy at all. The same agencies responsible for defending Russian networks also conduct offensive hacking abroad and enforce internet censorship at home. There is no meaningful version of “an agency that exists to help you patch your router.”

China: the fire marshal works for the intelligence service. China has the pieces — a powerful internet regulator (the CAC), a national emergency-response team, national vulnerability databases. But a 2021 law requires anyone who discovers a software flaw in China to report it to the government within 48 hours, before any public disclosure. Researchers at the Atlantic Council have documented how those reports flow onward to the Ministry of State Security, where some are stockpiled for offensive hacking rather than fixed. Microsoft has publicly linked the law to a rise in zero-day attacks from Chinese state groups. In other words: the bug reports go in, and exploits sometimes come out.

CountryWho does the jobCivilian or intelligenceMain toolPublishes or collects?
United StatesCISACivilianAdvisories, KEV catalogPublishes
United KingdomNCSC (part of GCHQ)IntelligencePublic guidance, scam takedownsPublishes
European UnionENISA + 27 national agenciesCivilianNIS2 law, mandatory standardsPublishes and requires
RussiaFSB, via GosSOPKAIntelligenceState threat monitoringCollects
ChinaCAC and MSSIntelligence48-hour bug reporting lawCollects
The same job, five ways. The last column is the one that matters.

Line those four up next to CISA and the pattern is hard to miss. The question that actually separates them isn’t budget or org charts. It’s who the agency thinks it’s protecting — you, or the state. The U.S. and its allies built agencies that publish what they find. Russia and China built systems that collect what they find. Everything else is detail.

What this means for you

Nothing above requires you to do anything. But two of these agencies produce free material worth knowing about, because it’s the same guidance companies pay consultants to repackage.

What I’d Do / What I’d Skip

Do: Bookmark two pages. CISA’s Secure Our World covers the four habits that stop most trouble (updates, passwords, two-factor, phishing awareness) in plain English. And don’t let the .uk put you off — the NCSC’s personal-security guidance is some of the clearest security writing anywhere, and advice this good doesn’t check your passport.

Skip: Any product marketing itself as “government-grade” or “NSA-level” security. Those phrases are decoration. The actual government guidance is free, and it mostly tells you to do the boring things well.

If you take one idea from the tour: when you hear that a hack “was attributed to state-sponsored actors,” the agencies in the last two entries above are frequently the actors in question — the same bodies that, at home, are in charge of “cybersecurity.” That’s not a reason for fear. It’s just useful context for reading the news like someone who knows who’s who, the way you already read what happens to your data when a company gets hacked differently once you know what’s happening backstage.

A good cyber defense agency is one of those things, like a fire code, that you benefit from daily without ever thinking about it. Somebody has to tell the country to turn on its updates. This week, at least, it’s still CISA — leaner, quieter, and still worth listening to.


Verified Resources & Documentation

Keep Reading