OLYMPUS RISK INTELLIGENCE PROTOCOL — INSTITUTIONAL ASSESSMENT DIVISION CASE WTW-2026-111

CISA

THE INSTITUTIONS THE SWITCHBOARD
APPARATUS — STATE FLAGGING SWITCHBOARD
Status
ACTIVE — U.S. federal agency (DHS), established 16 November 2018; disinformation/MDM work dismantled 2025
Hazard — Reach
86
RCH / FND / ENT
9 / 8 / 7
Conduct
STATE-JAWBONE — LAUNDERED CONTENT FLAGGING

Institutional Archetype

THE SWITCHBOARD — CISA is the government end of a pipeline built so that no call is ever a direct order. A federal cybersecurity agency spots a social-media post it considers misleading, and instead of contacting the platform — which would be state action, and state action against speech is unconstitutional — it routes the flag to an academic intermediary, which analyzes it, which forwards a recommendation to the platform, which acts. The government’s preferred outcome is achieved; at no node did the government technically direct a takedown. The switchboard’s value is precisely that separation: it makes the current flow while keeping every operator able to say, truthfully, that they did not do the thing the system was built to do. This profile scores the position — the state seat at the head of a laundering pipeline, and the agency that formally reclassified true information as a threat — not the motives of any officer who sat in it.

Mandate & Origin

CISA — the Cybersecurity and Infrastructure Security Agency — was established on 16 November 2018, when President Trump signed the Cybersecurity and Infrastructure Security Agency Act of 2018, reorganizing the DHS National Protection and Programs Directorate (NPPD) into a standalone agency. Its statutory mission is critical-infrastructure security: it brands itself “America’s Cyber Defense Agency,” charged with defending federal networks and the sixteen critical-infrastructure sectors — power grids, water treatment, elections administration — against cyberattack. Its first director was Christopher Krebs (fired by tweet in November 2020; the person is drama, treated elsewhere, and not re-litigated here). The relevant expansion came under director Jen Easterly, who from 2021 staffed a team to monitor online “disinformation” as part of what she termed the nation’s “cognitive infrastructure.”

The mandate is the tell. Protecting water plants from hackers is a cyber-defense function. Monitoring domestic speech about election procedures, vaccine efficacy, and COVID origins is not — yet that is where the “cognitive infrastructure” line carried the agency. CISA’s own Mis-, Dis-, and Malinformation (MDM) materials define malinformation as information “based on fact, but used out of context to mislead, harm, or manipulate.” A cybersecurity agency had formally entered true information into the threat catalogue. That category did not exist in its 2018 charter; it materialized because infrastructure built for one purpose acquired capabilities that exceeded the justification.

Funding & Backers

CISA is a federal agency, funded by Congressional appropriation (on the order of $3 billion/year), not by outside grantmakers — which distinguishes it from the NGO layer of the flagging machine it fed. The money flows the other direction: CISA sat at the government end, and federal grant dollars flowed out through the ecosystem it worked with — the Election Integrity Partnership, created in summer 2020 “at the request of” CISA, led by the Stanford Internet Observatory with Graphika and the Atlantic Council’s DFRLab as partners. CISA is thus not a funder in this file; it is the demand side — the state customer whose content preferences the grant-funded intermediaries processed through a Jira ticketing system.

Actions & Leadership Choices

The PR register is “protecting critical infrastructure.” The deeds, read end to end, describe a state switchboard for content flagging operated in the vocabulary of cybersecurity — and the deeds support the switchboard frame the archetype names.

  • It built a dedicated channel into the platforms. Per the House Judiciary staff report, CISA coordinated directly with platforms on content, and Facebook stood up a special government portal for CISA to submit flags. The committee titled its account “The Weaponization of CISA: How a ‘Cybersecurity’ Agency Colluded with Big Tech” — the committee’s characterization, not a court finding.
  • It ran a “switchboard” through an intermediary rather than call the platform itself. The EIP pipeline — government flags in, academic analysis, platform-facing recommendations out — is the switchboard in operation. CISA’s defenders note it never held a delete button; that is the point of the design, not a mitigation of it.
  • It reclassified true information as a threat. The MDM “malinformation” definition — “based on fact, but used out of context” — is CISA’s own published language. The Virality Project, extending the same pipeline to COVID content, flagged “stories of true vaccine side effects” as actionable. The category and the pipeline were CISA-adjacent infrastructure whose scope expanded from foreign disinformation to domestic misinformation to true-but-inconvenient information, with no reverse gear.
  • When the courts finally looked, they declined to rule. In Murthy v. Missouri (2024), the Supreme Court documented extensive CISA-and-FBI-to-platform contacts but held 6–3 that plaintiffs lacked standing; Alito’s dissent called it “one of the most important free speech cases to reach this Court in years.” Whether CISA’s jawboning violated the First Amendment remains unadjudicated. The infrastructure was dismantled — CISA’s MDM team was reorganized in 2025 under the Trump administration, and the agency later shed more than a third of its staff — but no court found it unlawful. The switchboard was unplugged by politics, not by a ruling.

Leadership choices. The agency that added “cognitive infrastructure” to a cyber-defense charter did so under its own directorate, not by external capture — the expansion was a leadership choice, made in-house, defended in Congressional testimony, and reversed only when the administration changed. The switchboard is not a program CISA fell into; it is one it built.

CONDUCT verdict: STATE-JAWBONE — LAUNDERED CONTENT FLAGGING. A statutory cyber-defense agency that opened a direct channel to platforms, routed government content preferences through a grant-funded academic intermediary so no takedown was ever technically ordered, and formally entered true information into its threat catalogue as “malinformation.” The work was defended as lawful information-sharing; the Supreme Court declined to rule on the merits; the apparatus was dismantled administratively in 2025. The mechanism was legal until a court said otherwise, and no court did. The switchboard is the finding, not the officer.



Sources: CISA — About (Wayback); CISA — Foreign Influence Operations and Disinformation; CISA — Disinformation Stops With You (infographic set) (Wayback); House Judiciary — CISA Staff Report, “The Weaponization of CISA” (PDF); House Judiciary — New Report Reveals CISA Tried to Cover Up Censorship Practices; The Intercept — Leaked Documents Outline DHS’s Plans to Police Disinformation (Klippenstein & Fang); Supreme Court — Murthy v. Missouri, No. 23-411 (PDF); DHS OIG — DHS Needs a Unified Strategy to Counter Disinformation, OIG-22-58 (PDF); Cybersecurity and Infrastructure Security Agency — Wikipedia.

RCH 9 REACH
FND 8 FUNDING
ENT 7 ENTRENCHMENT
OLYMPUS RISK INTELLIGENCE PROTOCOL does not exist. It was assembled in a GitHub issue thread in October 2023 by engineers who had read the extinction risk letter and wanted to understand who specifically had signed a document saying AI might kill everyone and then continued working on AI. These dossiers are satire. The biographical facts cited are sourced from published reporting, public statements, academic papers, and court records. The psychometric scores are not clinical assessments. No part of this constitutes professional psychological evaluation or diagnosis. Do not use these dossiers to make decisions about anything.