iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The Cyber Safety Review Board (CSRB) was designed to examine significant cyber incidents and recommend ways to prevent them—not to regulate organizations or enforce cybersecurity rules. Its own 2023 review called for limited subpoena authority, permanent staff, and predictable funding, addressing practical limits on how thoroughly it can investigate. But the board’s status after a 2025 shake-up of federal advisory committees is not verified in the sources available as of October 4, 2026.
What the Cyber Safety Review Board does
The Department of Homeland Security established the CSRB within DHS under the framework of Executive Order 14028. It is a public-private advisory body that reviews significant cyber incidents and issues findings and recommendations. Its role, as described in the Federal Register notice, is not that of a regulator or law-enforcement agency.
The board also does not appear to choose and launch reviews entirely on its own. CISA’s 2024 FAQ says only the President, the DHS Secretary, or the CISA Director could task a review. That makes the authority to select a review one part of the independence debate: the board’s remit depends on decisions by government officials.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Does the CSRB have subpoena power?
The CSRB’s 2023 inaugural review recommended that Congress grant it limited subpoena authority. That recommendation is evidence that the board wanted a way to compel some information; it is not evidence that Congress granted the power. The available cited sources do not establish that the CSRB received subpoena authority.
#1 Best Overall
In practice, the board relied on voluntary cooperation. Its inaugural review says it received responses from over 80 companies, while also noting that some organizations declined to provide some or all requested information. The figure describes responses received, not the number of organizations approached, and it cannot be treated as a compliance rate.
Voluntary requests can produce substantial evidence when organizations cooperate, but refusals can leave gaps in a review of an incident that spans multiple organizations. Limited compulsory process could address that constraint, while raising questions about the scope and safeguards of any subpoena power. The board’s proposal was for limited authority, not a general enforcement mandate.
Why experts say the board needs more independence
“Independence” in this debate refers to several practical conditions, not a single settled change to the board’s design:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →- Review selection: The President, DHS Secretary, or CISA Director could initiate a review under CISA’s 2024 FAQ. Greater independence could involve more board control over which incidents merit examination.
- Evidence access: The board’s inaugural review describes reliance on voluntary participation and recommends limited subpoena authority. The question is whether it can obtain relevant evidence when a request is refused.
- Staff and funding: The inaugural review says the board used existing CISA capabilities for staffing and resources, following a non-Federal Advisory Committee Act advisory committee model. It called for steady, predictable appropriations, permanent staff, and budget certainty.
- Institutional distance: Cyber incidents may involve agencies with responsibilities for cyber defense, intelligence, or law enforcement. A review body needs room to reach its own findings while operating within the federal structure.
CyberScoop quoted Wheeler, identified as a witness and CEO of Red Queen Dynamics, saying: “Many individuals on the CSRB are beloved and respected, but they do have full-time jobs and they do not have the time, freedom or authority to conduct independent, thorough investigations.” The concern is therefore not simply who sits on the board; it is whether members have the time, resources, and authority to investigate effectively.
Rank #3
The board itself framed the authority question in its inaugural review: “The Board recommends that Congress codify enhancements to the Board’s authorities, to include granting limited subpoena authority to the Board.” Its request for stable appropriations and permanent staff likewise points to operational independence—whether it can sustain investigative work without relying on ad hoc support.
What the proposed reforms would change
The reforms discussed in the cited material concern different parts of the board’s operating model. They are proposals and unresolved design questions, not a record of changes already adopted.
Rank #4
| Area | Documented model or constraint | Reform direction |
|---|---|---|
| Access to evidence | Voluntary requests; some organizations declined some or all requested information (CSRB inaugural review, 2023). | Limited subpoena authority recommended by the board; the cited sources do not establish that it was granted. |
| Staffing and resources | Existing CISA capabilities supported the board’s work under its advisory committee model (CSRB inaugural review, 2023). | Permanent staff, predictable appropriations, and budget certainty recommended by the board. |
| Review selection | Reviews could be tasked by the President, DHS Secretary, or CISA Director (CISA FAQ, 2024). | Greater board control over review selection is an independence question; the cited sources do not document a settled change. |
| Effect of findings | The CSRB reviews incidents and makes recommendations; it is not described as a regulator or enforcement body (Federal Register notice). | Any move toward binding authority would be a separate design choice, not an existing CSRB power established by these sources. |
Congressional scrutiny continued in 2024: the Senate hearing record, titled around the board’s outcomes and enduring questions, shows that its performance and future were subjects of oversight. A hearing, however, does not itself establish that any recommended reform became law.
Free tools Windows power users keep installed
One-click scans. No signup required.
What happened to the CSRB after January 2025?
According to a January 29, 2025, letter from the Senate Committee on Homeland Security and Governmental Affairs, Acting DHS Secretary Benjamine C. Huffman terminated current memberships on DHS advisory committees on January 20, 2025. In March, the House Homeland Security Committee chair asked DHS to examine the board’s structure as the administration considered reconstituting it. In May, Senator Mark Warner and colleagues urged DHS Secretary Kristi Noem to reestablish the CSRB.
Best Value
Those records document calls and discussion, not a completed reconstitution. The official CISA page’s retention of historical CSRB materials does not establish current membership or operations. The cited sources do not verify the board’s status as of October 4, 2026, so it would be premature to describe it as currently operating—or permanently dissolved—on that evidence alone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

