Jun 25, 2019

Cybersecurity problems linger at low-performing federal agencies

Photo: Samuel Corum/Anadolu Agency/Getty Images

A Senate subcommittee analysis of a decade of annual inspectors general reports shows that at the 7 worst-performing federal agencies, known cybersecurity issues can linger for as long as a decade.

The big picture: The report, compiled by the Permanent Subcommittee on Investigations, tracked cybersecurity problems in 7 agencies with the lowest ratings in a recent federal audit, as well as the Department of Homeland Security, which exercises some oversight control. Many of the problems were common across agencies.

Details: The 7 low-performing agencies were the Social Security Administration and the Departments of State, Transportation, Housing and Urban Development, Agriculture, Health and Human Services and Education.

  • At the Department of Education, for example, the inspector general identified in 2011 that unauthorized outside devices were able to connect to the network. That problem wasn't addressed until last year, and even then the network allowed connections for 90 seconds — enough to open a doorway for hackers.
  • Agriculture, Transportation, and HHS all had recurring or unaddressed problems that were a decade old. State had problems stretching back 5 years.
  • Every agency audited used at least some legacy systems so outdated that the vendors no longer provide security patches. Six agencies did not patch in a timely manner.

Between the lines: The report identifies several problems that allow cybersecurity issues to linger in many agencies.

  • There is a global cybersecurity talent shortage, and many of the less glamorous agencies struggle to get the best talent.
  • Agency cybersecurity executives often don't have access to their directors' ears or congressionally mandated authority to make decisions. There's also often high turnover at those jobs.
  • Agencies struggle to make needed changes as a result of tight budgets.

What's next: The report suggests that agencies centralize operations, prioritize staffing and embrace different budgeting models.

Go deeper

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 10 p.m. ET: 1,014,673 — Total deaths: 52,973 — Total recoveries: 210,335Map.
  2. U.S.: Total confirmed cases as of 10 p.m. ET: 244,678 — Total deaths: 5,911 — Total recoveries: 9,058Map.
  3. 2020 updates: The Democratic National Committee said its July convention will be postponed until August because of the coronavirus. A federal judge declined to delay Wisconsin's April 7 primary election.
  4. Jobs latest: Coronavirus unemployment numbers are like a natural disaster hitting every state.
  5. Public health latest: Anthony Fauci called for all states across the U.S. to issue stay-at-home orders. The FDA will allow blood donations from gay men after 3-month waiting period, citing "urgent need."
  6. Business latest: Treasury Secretary Steven Mnuchin said oil companies are eligible for aid from new lending programs the Federal Reserve is setting up, but not direct loans from his department.
  7. U.S.S. Theodore Roosevelt: Navy removes captain of aircraft carrier who sounded alarm about coronavirus.
  8. 1 future thing: In developing countries, consequences of COVID-19 could be deeper and far more difficult to recover from.
  9. What should I do? Answers about the virus from Axios expertsWhat to know about social distancingQ&A: Minimizing your coronavirus risk.
  10. Other resources: CDC on how to avoid the virus, what to do if you get it.

Subscribe to Mike Allen's Axios AM to follow our coronavirus coverage each morning from your inbox.

Mark Meadows considers new White House press secretary

Photos: Alyssa Farah, Defense Department; Stephanie Grisham, Alex Wong/Getty Images; Kayleigh McEnany, Scott W. Grau/Icon Sportswire via Getty Images

White House Chief of Staff Mark Meadows has privately discussed bringing on Pentagon spokesperson Alyssa Farah or Trump campaign spokesperson Kayleigh McEnany as a new White House press secretary, two sources familiar with the talks tell Axios.

Why it matters: Meadows' start on Tuesday as Trump's new chief presents a chance to overhaul a press shop that's kept a low profile since President Trump ended the tradition of daily press secretary briefings.

CNN: Fauci advises all states issue stay-at-home orders

Dr. Anthony Fauci listens to President Trump speak during a briefing on April 1. Photo: Win McNamee/Getty Images

Director of the National Institute of Allergy and Infectious Diseases Anthony Fauci recommended on Thursday that all states across the U.S. implement stay-at-home orders, at a CNN town hall.

Why it matters: The recommendation stands in contrast to President Trump's calls for "flexibility." Nearly 4o states have issued stay-at-home orders to promote social distancing as a way to combat the novel coronavirus — but the orders vary in strictness and duration.

Go deeperArrow8 hours ago - Health