Photo: Samuel Corum/Anadolu Agency/Getty Images

A Senate subcommittee analysis of a decade of annual inspectors general reports shows that at the 7 worst-performing federal agencies, known cybersecurity issues can linger for as long as a decade.

The big picture: The report, compiled by the Permanent Subcommittee on Investigations, tracked cybersecurity problems in 7 agencies with the lowest ratings in a recent federal audit, as well as the Department of Homeland Security, which exercises some oversight control. Many of the problems were common across agencies.

Details: The 7 low-performing agencies were the Social Security Administration and the Departments of State, Transportation, Housing and Urban Development, Agriculture, Health and Human Services and Education.

  • At the Department of Education, for example, the inspector general identified in 2011 that unauthorized outside devices were able to connect to the network. That problem wasn't addressed until last year, and even then the network allowed connections for 90 seconds — enough to open a doorway for hackers.
  • Agriculture, Transportation, and HHS all had recurring or unaddressed problems that were a decade old. State had problems stretching back 5 years.
  • Every agency audited used at least some legacy systems so outdated that the vendors no longer provide security patches. Six agencies did not patch in a timely manner.

Between the lines: The report identifies several problems that allow cybersecurity issues to linger in many agencies.

  • There is a global cybersecurity talent shortage, and many of the less glamorous agencies struggle to get the best talent.
  • Agency cybersecurity executives often don't have access to their directors' ears or congressionally mandated authority to make decisions. There's also often high turnover at those jobs.
  • Agencies struggle to make needed changes as a result of tight budgets.

What's next: The report suggests that agencies centralize operations, prioritize staffing and embrace different budgeting models.

Go deeper

Updated 5 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 5:30 p.m. ET: 33,484,120 — Total deaths: 1,004,082 — Total recoveries: 23,212,633Map.
  2. U.S.: Total confirmed cases as of 5:30 p.m. ET: 7,180,179 — Total deaths: 205,729 — Total recoveries: 2,794,608 — Total tests: 102,342,416Map.
  3. Health: Americans won't take Trump's word on the vaccine, Axios-Ipsos poll finds.
  4. States: NYC's coronavirus positivity rate spikes to highest since June.
  5. Sports: Tennessee Titans close facility amid NFL's first coronavirus outbreak.
  6. World: U.K. beats previous record for new coronavirus cases.
  7. Work: United States of burnout — Asian American unemployment spikes amid pandemic

What to watch in tonight's debate

Joe Biden (left) and President Trump (right) are facing off in Cleveland for the first presidential debate. Photos: Alex Wong (of Biden) and David Hume Kennerly (of Trump)/Getty Images

President Trump will try to break Joe Biden's composure by going after his son Hunter and other family members in tonight's first presidential debate — a campaign source tells Axios "nothing will be off the table" — while Biden plans to stick to the economy, coronavirus and new revelations about how Trump avoided paying taxes.

Driving the news: Biden and Trump are set to debate at 9 p.m. ET at Case Western Reserve University in Cleveland, and it will be moderated by Fox News' Chris Wallace.

Massive layoffs hit Disney theme parks

A person posing for a photo in front of the iconic Disney castle at Disneyland Resort in Hong Kong on Sept, 25. Photo: Miguel Candela Poblacion/Anadolu Agency via Getty Images

Disney is laying off 28,000 workers at its theme parks and experiences and consumer products divisions, the company said in a statement Tuesday.

Why it matters: The coronavirus pandemic has forced the company to close its California theme parks and limit attendance at re-opened parks elsewhere around the U.S. Around 67% of the 28,000 laid off workers are part-time employees, according to Josh D’Amaro, chairman of Disney's parks, experiences and products division.