❌

Normal view

There are new articles available, click to refresh the page.
Yesterday — 24 September 2026Main stream

Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack

23 September 2026 at 15:40

Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found.

The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs.

The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses. 

The IG took a look at the Secure Cloud Business Applications (SCuBA) project, created in response to the 2022 SolarWinds attack. It provides secure configuration baselines, settings and assessment tools to help agencies reduce the risk of breaches.

A December 2024 directive gave agencies a list of requirements to align with SCuBA, with a deadline of June 2025.

The IG found that 88 of 102 agencies, or 86%, didn’t implement all the mandatory SCuBA policies from BOD 25-01. As of February of this year, “compliance with BOD 25-01 had not improved. A total of 78 out of 102 (76%) [Federal Civilian Executive Branch] agencies were still not in compliance with implementing all mandatory SCuBA policies.”

“Some examples of baselines that FCEB agencies did not implement included blocking outdated authentication procedures, enforcing multifactor authentication, and implementing a policy to protect sensitive and personally identifiable information,” the IG report states. “Implementation of these baselines could mitigate vulnerabilities and threats from affecting the cloud business applications.”

That’s the result of CISA’s lack of power to enforce its BODs, which translates into greater risk, the IG concluded.

“Without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened,” the report states. “When agencies do not adopt required configurations or meet implementation deadlines, their cloud environments remain exposed to preventable threats.”

CISA didn’t respond to the report, according to the IG. 

The agency didn’t immediately respond to a request for comment from CyberScoop.

The post Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack appeared first on CyberScoop.

Before yesterdayMain stream

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

27 July 2026 at 09:00

Sen. Ron Wyden implored a trio of federal leaders Monday to lead a comprehensive campaign to purge older, insecure virtual private networks that are directly accessible via the public internet from federal agencies.

“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden, D-Ore., wrote in his missive to top officials at the Office of Management and Budget, Cybersecurity and Infrastructure Security Agency and National Institute of Standards and Technology. They should coordinate “require the adoption of modern, secure remote-access technology across the federal government,” he said.

Such VPNs serve as a digital “front door” accessible via the public internet that allows mobile devices and remote employees to log in, Wyden said in a letter first reported by CyberScoop.

Wyden referenced several attacks that have affected federal agencies, including the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures across Fortinet gateways and vulnerabilities that hackers exploited across Ivanti and Check Point VPN appliances.

“Modern remote-access solutions eliminate this vulnerability entirely. Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence,” he said. “This effectively makes these servers invisible, ensuring that hackers cannot attack an entry point they cannot see.”

Agencies should move away from what a Congressional Research Service report to Wyden called a “castle-and-moat” approach of assuming anyone inside the network is authorized to access an organization’s resources that VPNs rely upon by extending virtual bridges to a more remote workforce, he said. They should instead focus on zero-trust architecture that uses a never-trust, always-verify approach, he said.

Furthermore, CISA, the OMB and NIST need to fundamentally change how the federal government approaches agency vulnerabilities, Wyden wrote. 

“The federal government has become trapped in an endless game of ‘whack-a-mole’ in responding to widespread compromises of legacy remote access technologies,” he said. “To keep federal networks online, CISA has been forced to repeatedly issue extraordinary Emergency Directives and hyper-accelerated patch mandates. These reactive emergency mandates are unsustainable for federal cybersecurity teams, and fail to address the fundamental issue that these flaws are inherent in the use of legacy remote-access appliances.”

CISA needs to issue a binding operational directive that gives agencies two years to fully expunge legacy, public-facing remote access systems, he said. NIST needs to issue implementation standards for transitioning to zero-trust architectures.

OMB needs to issue a memo directing agencies to prioritize zero-trust architecture spending. And OMB needs to team with CISA and the Defense Department to update procurement rules to block agencies and defense contractors from buying network edge, VPN or other remote access solutions unless a vendor supplies an attestation that it complies with NIST zero-trust standards, Wyden wrote.

The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.

❌
❌