Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Audits

Senate Report: Federal Agencies Still Have Poor Cybersecurity Practices

A bipartisan report released this week by the United States Senate’s Homeland Security and Governmental Affairs Committee shows that key government agencies have made little progress in terms of cybersecurity over the past two years.

A bipartisan report released this week by the United States Senate’s Homeland Security and Governmental Affairs Committee shows that key government agencies have made little progress in terms of cybersecurity over the past two years.

A report published in 2019 found that eight federal agencies failed to meet even the basic cybersecurity standards and protocols. Two years later, cybersecurity at those agencies was again analyzed and the findings are — as described in the new report — “stark.”

The new report, titled “Federal Cybersecurity: America’s Data Still at Risk,” is based on recent inspector general audits. The targeted agencies are the Department of Homeland Security, Department of State, Department of Transportation, Department of Housing and Urban Development, Department of Agriculture, Department of Health and Human Services, Department of Education, and the Social Security Administration.

According to the report, only the DHS has established an effective cybersecurity program, while the rest made only minimal improvements.

The findings are alarming considering that threat actors believed to be working for the Chinese and Russian governments successfully infiltrated many federal agencies since the previous report. Moreover, the White House reported 30,819 information security incidents across the federal government for 2020, which represents an 8 percent increase compared to the prior year.

“While several of the agencies made minimal improvements in one or more areas, inspectors general found essentially the same failures as the prior 10 years,” the 47-page report reads. “Only DHS had an effective cybersecurity program for 2020; every other agency failed to implement an effective cybersecurity program.”

It adds, “It is clear that the data entrusted to these eight key agencies remains at risk. As hackers, both state-sponsored and otherwise, become increasingly sophisticated and persistent, Congress and the executive branch cannot continue to allow PII and national security secrets to remain vulnerable.”

Problems identified at the audited agencies included unpatched systems, the use of outdated systems and applications, failure to maintain accurate IT asset inventories, and failure to adequately protect personally identifiable information (PII).

Advertisement. Scroll to continue reading.

In addition to pointing out problems, ​the report makes some recommendations, including the OMB developing and requiring agencies to adopt a risk-based budgeting model for IT investments, a coordinated approach for government-wide cybersecurity to ensure accountability, CISA expanding shared services offerings to federal agencies, and Congress making some changes to the Federal Information Security Modernization Act of 2014.

Related: Electricity Distribution Systems at Increasing Risk of Cyberattacks, GAO Warns

Related: DHS Gives Federal Agencies 5 Days to Identify Vulnerable MS Exchange Servers

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders.

Register

People on the Move

Data security startup Reco adds Merritt Baer as CISO

Chris Pashley has been named CISO at Advanced Research Projects Agency for Health (ARPA-H).

Satellite cybersecurity company SpiderOak has named Kip Gering as its new Chief Revenue Officer.

More People On The Move

Expert Insights