
What happened
The Cyber Safety Review Board was created under Executive Order 14028 to bring together public and private sector experts for authoritative reviews of major cyber incidents. CISA's own page describing the board, read as it stands now, lists three completed reviews: the 2022 report on the Log4j vulnerability, a 2023 review of the Lapsus$ extortion group's intrusions, and an April 2024 report on the Microsoft Exchange Online intrusion attributed to the actor later named Storm-0558. The page records no review published after that date.
According to reporting from SecurityWeek and Defense One, both of which quote the same internal memo, Acting DHS Secretary Benjamine Huffman ordered the immediate termination of memberships across several DHS advisory committees, including the CSRB, on 20 January 2025, citing a commitment to eliminating what the memo called the misuse of resources. Both outlets report that the CSRB was, at the time, in the middle of a review of the Salt Typhoon telecommunications intrusions, and that the termination left that review without the members needed to complete it.
Confidence and limits
The board's establishment and its three completed reports are confirmed directly from CISA's own page. The termination memo's date, its stated rationale, and its effect on the Salt Typhoon review rest on two independent outlets that both quote the memo directly and agree on its substance, which this entry treats as reasonably solid, but neither the memo itself nor a CISA or DHS statement confirming the termination was located and opened directly for this entry. Whether or how the Salt Typhoon review was later completed by other means is not established here.
Why it mattered
The CSRB was one of the few standing mechanisms for an authoritative, public, cross-sector account of a major incident, comparable in intent to the National Transportation Safety Board's role after aviation accidents. Its three published reports on Log4j, Lapsus$ and the Storm-0558 Exchange Online intrusion remain the board's documented output. Ending an incident review before it is complete removes the possibility of a single authoritative public account of that incident, leaving that role to individual vendors, victims and outside researchers, each with a narrower vantage point and its own incentives.
Defensive takeaway
When evaluating lessons from a major incident, do not wait for a CSRB-style report that may not materialise on the earlier schedule, and weight vendor and victim disclosures accordingly, recognising each has a narrower vantage point than an independent board was designed to provide.
- Does your incident learning process still assume a CSRB-style independent federal review will eventually be published for major incidents?
- Have you reviewed the board's three completed reports, on Log4j, Lapsus$, and the Storm-0558 Exchange Online intrusion, for lessons applicable to your own environment?
- If your sector faced a Salt Typhoon-scale intrusion, what other bodies would you rely on for an authoritative public account?
The board's own published record stops at three reports; whatever became of its unfinished review of the telecommunications intrusions is not something this entry can confirm from a primary government document.
Do not expect an independent federal review of a major incident on the CSRB's earlier timeline or format; if you need an authoritative external account of an incident for your own board or insurer, plan around vendor and sector-specific reviews instead.
CISA's own Cyber Safety Review Board page, read directly, confirms the board's creation and its three published reports through April 2024 and shows no activity recorded after that date. The termination memo itself, its exact text and its 20 January 2025 date, is established here only through two independent reputable outlets that quote it, not through a primary government document opened directly.
Sources & reading trail
Confirms the board's establishment and lists its three completed reports, with no review recorded after April 2024.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Quotes the internal DHS memo terminating advisory committee memberships including the CSRB and its stated rationale.
reputable-original-reporting · Source published: 22 January 2025 · Retrieved: 16 September 2026
Corroborates the memo's date, signatory and rationale, and the effect on the ongoing Salt Typhoon review.
reputable-original-reporting · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.