The US Cybersecurity and Infrastructure Security Agency (CISA) mismanaged a program designed to retain skilled security professionals so badly that auditors have concluded it left the agency "unable to adequately protect the Nation from cyber threats."
The Cyber Incentive program began life in 2015 under the National Protection and Programs Directorate, which became CISA in 2018. According [PDF] to the Office of the Inspector General at CISA's parent agency, the Department of Homeland Security, it didn't take long for "fraud, waste, and abuse" of the initiative to become standard operation procedure at the nation's cybersecurity watchdog.
The OIG report, which was triggered by a 2023 hotline complaint, found that CISA had approved incentive payments for a number of ineligible employees,