Security News

Watchdog: Most US Federal Agencies Missed Deadline for Cloud Security Rules

CyberScoop · 24 Sept 2026
Key Takeaway Small businesses using cloud platforms should ensure basics like multifactor authentication and blocking outdated login methods are actually turned on, not just assumed to be in place.

A new inspector general report from the Department of Homeland Security has found that 86% of US federal civilian executive branch agencies failed to fully implement mandatory cloud security policies by their June 2025 deadline. The directive, part of CISA's Secure Cloud Business Applications (SCuBA) project created after the 2022 SolarWinds attack, required agencies to adopt secure configuration baselines for cloud platforms.

By February this year, compliance had barely improved, with 76% of agencies still failing to meet all mandatory requirements. Common gaps included not blocking outdated authentication methods, not enforcing multifactor authentication, and lacking policies to protect sensitive personal information. The IG warned that these shortfalls leave agencies exposed to preventable cyberattacks and noted that CISA lacks the authority to compel timely compliance with its directives.

While this report focuses on US federal agencies, it highlights a broader lesson for any organisation relying on cloud services: security frameworks only reduce risk if they are actually implemented and checked, not just adopted on paper.

cloud security government MFA compliance CISA
Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.