Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
DHS watchdog finds 86 percent of civilian agencies missed CISA’s cloud security directive deadline.
The DHS inspector general reported that 88 of 102 federal civilian executive branch agencies, about 86 percent, missed the June 2025 deadline to implement all mandatory Secure Cloud Business Applications policies in CISA Binding Operational Directive 25-01. By February 2026, 78 of 102 agencies, or 76 percent, were still noncompliant. Unimplemented baselines included blocking outdated authentication, enforcing multifactor authentication, and protecting sensitive and personally identifiable information. The IG concluded CISA lacks authority to compel timely BOD implementation, weakening the federal cloud posture; SCuBA was developed after the 2022 SolarWinds attack, and CISA did not respond to the report.
- 88 of 102 agencies missed the June 2025 BOD 25-01 deadline.
- As of February 2026, 76 percent remained noncompliant.
- Missing controls include MFA, legacy-auth blocks, and PII protection.
- The IG says CISA cannot compel agencies to implement BODs.
- SCuBA was created after the 2022 SolarWinds attack.
Full article699 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The DHS inspector general said CISA lacks the power to compel agencies to implement its Binding Operational Directives.
Listen to this article
0:00
Learn more.
Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found.
The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs.
The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses.
The IG took a look at the Secure Cloud Business Applications (SCuBA) project, created in response to the 2022 SolarWinds attack. It provides secure configuration baselines, settings and assessment tools to help agencies reduce the risk of breaches.
A December 2024 directive gave agencies a list of requirements to align with SCuBA, with a deadline of June 2025.
The IG found that 88 of 102 agencies, or 86%, didn’t implement all the mandatory SCuBA policies from BOD 25-01. As of February of this year, “compliance with BOD 25-01 had not improved. A total of 78 out of 102 (76%) [Federal Civilian Executive Branch] agencies were still not in compliance with implementing all mandatory SCuBA policies.”
“Some examples of baselines that FCEB agencies did not implement included blocking outdated authentication procedures, enforcing multifactor authentication, and implementing a policy to protect sensitive and personally identifiable information,” the IG report states. “Implementation of these baselines could mitigate vulnerabilities and threats from affecting the cloud business applications.”
That’s the result of CISA’s lack of power to enforce its BODs, which translates into greater risk, the IG concluded.
“Without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened,” the report states. “When agencies do not adopt required configurations or meet implementation deadlines, their cloud environments remain exposed to preventable threats.”
CISA didn’t respond to the report, according to the IG.
The agency didn’t immediately respond to a request for comment from CyberScoop.
More Scoops
CISA delivers new directive to agencies on securing cloud environments
The cyber agency’s SCuBA guidelines were developed after pilots with 13 agencies and continue a post-SolarWinds cloud strategy.
Threat awareness, cloud security, quantum computing among chief agency cyber policy priorities ahead
Agencies face ‘inflection point’ ahead of looming zero-trust deadline, CISA official says
Latest Podcasts
Government
ShinyHunters claims attack on FBI exposes almost all agents
Citing China, President Trump doubles down on hands-off approach to AI regulation
Dems seek top-to-bottom assessment of CISA workforce
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data