Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
President Donald Trump’s April 9, 2025 memorandum ordered a review of former CISA director Christopher Krebs and a comprehensive evaluation of the agency’s activities over the preceding six years. It also directed action on security clearances. The memorandum did not abolish CISA or announce that its statutory cybersecurity mission had ended.
What the memorandum ordered
The White House titled the April 9, 2025 document “Addressing Risks from Chris Krebs and Government Censorship.” It directs several distinct actions; they should not be conflated into a single finding against CISA.
- Clearances: The memorandum directs immediate action, consistent with existing law, to revoke Krebs’s active security clearance. It also directs a review of active clearances held by people at entities associated with him, including SentinelOne. A directive to review clearances is not proof that every clearance was revoked.
- Review of Krebs: The attorney general and secretary of homeland security are directed to review his conduct as a government employee, including possible suitability violations, unauthorized disclosure of classified information, and conduct the memorandum alleges was inconsistent with Executive Order 14149.
- Review of CISA: The two officials, consulting other agency heads, are directed to conduct a comprehensive evaluation of all CISA activities during the prior six years. That period is broader than Krebs’s tenure and does not mean he personally directed every activity under review.
- Report and recommendations: The officials are to submit a joint report to the president through the White House counsel, with recommendations for remedial or preventative action.
The memorandum’s accusations are the administration’s stated rationale for the review, not findings independently established by the order itself. The document also says its actions must be consistent with existing law and that it creates no enforceable substantive or procedural right or benefit.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteWhy Krebs became the focus
Krebs was CISA’s founding director and led the agency during the 2020 election. He became a prominent defender of the election-security assessment that found no evidence voting systems changed or deleted votes. Trump’s memorandum characterizes Krebs’s work as censorship and abuse of government authority; those are allegations, not neutral descriptions that should be treated as settled facts.
#1 Best Overall
At the time of the contemporaneous Computerworld report published April 10, 2025, Krebs was chief intelligence and public-policy officer at cybersecurity company SentinelOne. That made the clearance directive relevant to his private-sector role as well as his former government service. Computerworld reported SentinelOne said fewer than 10 employees held relevant clearances and that it did not expect a material business impact; that company statement does not establish the eventual outcome of the clearance review.
What CISA does—and what the dispute is about
CISA’s work is broader than election-related communications. The six-year evaluation could encompass election-security coordination and public communications about election-related cyber risks, but also critical-infrastructure protection, incident response, vulnerability coordination, and exchanges of threat intelligence with companies and other nongovernmental organizations.
The central factual distinction is between sharing threat information or warnings and coercing a platform to remove lawful speech. Government contact with a technology company can take different forms: for example, reporting a potential cyber threat is not automatically equivalent to directing moderation of political content. Whether particular communications crossed a legal or ethical line depends on evidence about what was said, by whom, under what authority, and whether pressure was applied.
The memorandum alleges censorship and improper government conduct, including in connection with election and other information-related matters. The material cited here does not establish a final, independently adjudicated finding that CISA as an institution coerced platforms. Nor does it provide a complete evidentiary record of the underlying contacts. Claims about alleged coercion therefore need to remain attributed unless supported by specific, independently documented findings.
What “under review” means for CISA’s authority
A presidential memorandum can direct executive-branch officials to review conduct and report to the president. This memorandum does not itself rewrite CISA’s statutory authorities, end its congressionally created functions, or announce that the agency has been dismantled. Changes to its legal mission or statutory authority would require separate legal action; changes to organization, programs, or funding would depend on the applicable administrative and budgetary processes and, where required, Congress.
Likewise, a security-clearance action is not a criminal conviction, and the order does not by itself establish that a criminal case was opened. A review of Krebs personally and an evaluation of CISA’s institutional activities are related in the memorandum but remain separate inquiries: a finding about an individual would not automatically prove institutional misconduct.
Why a review can matter before it reaches a finding
An agency can continue operating formally while staff and partners respond cautiously to uncertainty. Computerworld cited concerns about morale, neutrality, operational stability, and public-private cooperation. These are risks identified by commentators, not proof that broad delays or reduced cooperation had already occurred across CISA.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Employees could seek additional approvals or document decisions more extensively, potentially slowing sensitive work.
- Officials could become more cautious around election security, misinformation-related coordination, or contacts with platforms.
- Companies and infrastructure operators could involve counsel earlier or share less information if they fear routine exchanges may later be treated as politically suspect.
- Leadership could divert time and resources to compliance and record review while the evaluation proceeds.
The institutional stakes extend beyond election disputes. CISA depends on credibility and voluntary cooperation with state and local governments, election officials, technology firms, and critical-infrastructure operators. If partners become less willing to share incident details or threat indicators, the practical effect could reach ransomware response and infrastructure resilience even if no formal authority changes. That is a plausible concern, not an established result of the memorandum.
Best Value
What private-sector partners should do
The memorandum alone gives organizations no reason to treat existing CISA advisories as invalid or to stop using established security channels. A proportionate response is to preserve operational resilience and good records while distinguishing formal changes from political scrutiny.
- Continue monitoring CISA advisories and relevant sector-specific alerts; assess each on its technical merits and applicability.
- Maintain records of government security communications under existing legal, confidentiality, and retention rules.
- Review internal escalation procedures for sensitive government contacts, including when legal or compliance staff should be involved.
- Maintain multiple threat-intelligence sources, such as sector information-sharing organizations, incident-response providers, and relevant vendors, without assuming they replace CISA.
- Track formal changes to CISA programs, authorities, or funding separately from statements about the review.
How to judge the eventual outcome
A credible assessment of the review should distinguish evidence from political characterization and account for continuity of essential cyber functions. Useful questions include:
- Evidence: Are conclusions supported by documents, testimony, court records, or inspector-general findings, rather than assertions alone?
- Scope: Does the inquiry examine specific conduct, or presume ordinary election-security and threat-information work was improper?
- Process: Were affected employees or contractors given notice and a meaningful opportunity to respond? What legal standards and methods did reviewers use?
- Consistency: Were comparable government-platform interactions evaluated under the same criteria across administrations?
- Continuity and transparency: Were critical cybersecurity functions protected, and does the report explain its evidence and reasoning?
The memorandum and the contemporaneous coverage cited here establish that a review was ordered; they do not establish its eventual completion or findings. They also do not establish a later decision to eliminate CISA, a final disposition of the clearance reviews, quantified changes to the agency’s staffing or programs, or a measured decline in industry participation. Those outcomes should not be inferred from the original order.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

