senate committtee

Senate Report: Federal Agencies Have Failed To Respond to Growing Cybersecurity Threats

Eight agencies, including the Department of Homeland Security and Education Department, are using outdated systems that have few security updates and have failed to protect Americans’ personal data.

Federal agencies tasked with protecting the personal and financial data of millions of Americans have failed to update their systems or implement basic cybersecurity defenses, according to a recent Senate report.

The June report, titled “Federal Cybersecurity: America’s Data at Risk,” is the product of a subcommittee’s 10-month review of a decades’ worth of inspectors general reports of core government agencies. Eight agencies, including the Department of Homeland Security, the Department of State, the Department of Education and the Social Security Administration, were found to have several vulnerabilities in their cybersecurity systems and practices.

“The federal government remains unprepared to confront the dynamic cyber threats of today,” the report reads. “The longstanding cyber vulnerabilities consistently highlighted by Inspectors General illustrate the federal government’s failure to meet basic cybersecurity standards to protect sensitive data.”

Seven agencies were found to have failed to adequately protect personally identifiable information, and six agencies failed to install security patches in a timely manner. All eight agencies that were surveyed use “legacy,” or outdated, systems that are no longer supported by the vendor with security updates, leading to substantial risk of breaches.

Most shockingly, the Department of Transportation was using a 48-year-old system to track hazardous materials data. The program was finally phased out at the end of May because there were very few employees who knew how to use it, according to the report.

But other agencies are also using old systems to carry out their core responsibilities. Homeland Security continues to use Windows XP and Windows Server 2003 for many of its internal systems, despite the fact that Microsoft discontinued support for those programs years ago.

These findings are compounded by the fact that the federal government experiences tens of thousands of cyber incidents and breaches per year. More than 77,000 incidents were reported in 2015, with that number dropping significantly in recent years due to a rule change that allows agencies to report fewer kinds of attacks, according to NBC News.

Investigators found that the Education Department is particularly vulnerable to these incidents. The agency has been unable to prevent unauthorized devices from connecting to its network for years, according to the report.

Only recently has the department been able to limit unauthorized access to 90 seconds, which is still plenty of time to “launch an attack or gain intermittent access to internal network resources,” the report said. Those resources include the personal and financial data of millions of Americans who have applied for federal student loans.

In addition to its findings, the subcommittee offered some recommendations, including the hiring of more cybersecurity experts, prioritizing funds for systems updates and having more regular reports on the status of cyber threats. Jake Olcott, vice president of government affairs at the cybersecurity company BitSight, told Fortune that government officials should be held accountable for breaches just as corporate executives are.

“The reality is, unlike in the commercial sector today, where CEOs and board members are being fired because of data breaches, there is not the same level of accountability and responsibility in the federal government,” Olcott told Fortune. “Start holding people accountable for improving security performance…Those are the things you need congressional and executive leadership.”

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • AI to Help Resolve Non-Emergency Calls Across Utah and Decrease 911 Caller Wait Times

    The Utah Communications Authority (UCA), which oversees the state’s next generation 911 technology services, recently announced that public safety answering points (PSAPs) throughout the state plan to implement Motorola Solutions’ Virtual Response technology to automate the receipt and resolution of 10-digit non-emergency line calls in Utah with the help of AI. Read Now

  • Report Reveals Local Governments Face Surge in Ransomware Attacks with Minimal Resources

    KnowBe4, the cybersecurity platform that comprehensively addresses human risk management, recently released new research highlighting the critical cybersecurity challenges facing state, local, tribal, and territorial (SLTT) governments. The report details how government organizations have become prime targets for cybercriminals while simultaneously facing severe resource constraints. Read Now

  • Video Surveillance Trends to Watch

    With more organizations adding newer capabilities to their surveillance systems, it’s always important to remember the “basics” of system configuration and deployment, as well as the topline benefits of continually emerging technologies like AI and the cloud. Read Now

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.