Watchdog: Most US Federal Agencies Missed Deadline for Cloud Security Rules
A new inspector general report from the Department of Homeland Security has found that 86% of US federal civilian executive branch agencies failed to fully implement mandatory cloud security policies by their June 2025 deadline. The directive, part of CISA's Secure Cloud Business Applications (SCuBA) project created after the 2022 SolarWinds attack, required agencies to adopt secure configuration baselines for cloud platforms.
By February this year, compliance had barely improved, with 76% of agencies still failing to meet all mandatory requirements. Common gaps included not blocking outdated authentication methods, not enforcing multifactor authentication, and lacking policies to protect sensitive personal information. The IG warned that these shortfalls leave agencies exposed to preventable cyberattacks and noted that CISA lacks the authority to compel timely compliance with its directives.
While this report focuses on US federal agencies, it highlights a broader lesson for any organisation relying on cloud services: security frameworks only reduce risk if they are actually implemented and checked, not just adopted on paper.