CISA Revises Cyber Pay Incentives Amid Staff Retention Concerns
Article Content
- •CISA's CRI program continues but with stricter eligibility criteria.
- •Concerns arise over potential staff losses due to revised performance rating caps.
- •The program aims to address high vacancy rates in CISA's cybersecurity workforce.
The Cybersecurity and Infrastructure Security Agency (CISA) will continue its Cybersecurity Retention Incentive (CRI) program through fiscal 2027, but with revised eligibility criteria that may reduce the number of qualifying employees. The changes tie eligibility to job series and performance ratings, raising concerns about potential staff losses following widespread resignations last year. The Office of Personnel Management has capped higher performance ratings governmentwide, which could further impact retention. The program aims to address ongoing vacancy rates within CISA's cybersecurity workforce, allowing qualifying employees to receive pay increases of up to 25% of their base salary. Last December, CISA had announced plans to eliminate the incentive program due to mismanagement, but the new policy focuses on targeting cybersecurity functions. The revised criteria went into effect on October 1, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What are the new eligibility criteria for the CRI program?
How much can qualifying employees earn through the CRI program?
What prompted the revision of the CRI program?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…