IC Technology & Surveillance — 2026-05-03

ODNI Tells CISOs They Are On Their Own for Threat Assessments

ODNI released its 2026 Annual Threat Assessment in March; CSO Online reported April 30 that the document eliminated standalone country sections on China, Russia, Iran, and North Korea present in the 2025 edition. The 2026 report also omits named-campaign tracking of Volt Typhoon and Salt Typhoon, which detailed adversary pre-positioning in US critical infrastructure, instead covering operational domestic outcomes such as border encounter metrics and fentanyl seizures. The Cipher Brief, also reporting May 2, characterized the structural shift as cuts to cyber intelligence that undermine national security.

Analysis
Stripping Volt Typhoon and Salt Typhoon from ODNI's 2026 Annual Threat Assessment, reported by three outlets on the same day without primary document analysis, withdraws the one publicly attributable body of evidence linking Chinese state actors to pre-positioning in U.S. energy, water, and communications networks, ending the document's function as a shared threat baseline for uncleared critical infrastructure operators. The structural change more plausibly reflects a classification upgrade than intelligence elimination, but the concurrent CISA staff exodus means uncleared operators lose both reference point and operational backstop simultaneously. Formal acknowledgment of that compounded gap, through IG reports, GAO products, or congressional testimony, remains possible before October 2026, though bureaucratic incentives likely favor absorbing it quietly.
3 sources
  1. ODNI to CISOs on threat assessments: You are on your own - CSO Online
  2. Cutting Cyber Intelligence Undermines National Security - The Cipher Brief
  3. 2026 ODNI Annual Threat Assessment - Digital Asset Redemption

View in full brief →

UNCLASSIFIED // OPEN SOURCE