DHS Secretary Fires FEMA IT Employees Over Security Failures
As part of a routine cybersecurity review ordered by Homeland Security Secretary Kristi Noem, the DHS Office of the Chief Information Officer (OCIO) discovered significant security vulnerabilities that gave a threat actor access to FEMA's network. The investigation revealed severe lapses in security that allowed the threat actor to breach FEMA's network and threaten the entire Department and the nation. Secretary Noem fired two dozen members of the Federal Emergency Management Agency's (FEMA) IT department, including FEMA Chief Information Officer (CIO) Charles Armstrong and Chief Information Security Officer (CISO) Gregory Edwards, for their failure to implement proper security procedures.
Key Takeaways:
- FEMA's IT department failed to implement multi-factor authentication, use prohibited legacy protocols, and inadequately addressed known vulnerabilities, putting the entire Department at risk of cyberattacks.
- The DHS Office of the Chief Information Officer (OCIO) discovered significant security vulnerabilities during a routine cybersecurity review ordered by Secretary Noem, which gave a threat actor access to FEMA's network.
- FEMA spent nearly half a billion dollars on IT and cybersecurity measures in Fiscal Year 2025 alone, but the agency's IT leadership neglected basic duties and exposed the Department to cyberattacks.
- Secretary Noem warned that such behavior will not be tolerated in the Trump administration and stated that the entrenched bureaucrats who led FEMA's IT team for decades resisted efforts to fix the problem.
- The entrenched bureaucrats lied to officials about the scope and scale of the cyber vulnerabilities and avoided scheduled inspections, putting the entire Department at risk.
- The terminated employees include FEMA Chief Information Officer (CIO) Charles Armstrong, Chief Information Security Officer (CISO) Gregory Edwards, and 22 other FEMA IT employees directly responsible for the security failures.
- Secretary Noem stated that the American people deserve results from their government and that the Deep State individuals were more interested in covering up their failures than in protecting the Homeland and American citizens' personal data.
Statistics:
- $495 million: The amount FEMA spent on IT and cybersecurity measures in Fiscal Year 2025 alone.
- 22: The number of FEMA IT employees terminated by Secretary Noem.
- 1: The number of cyberattacks that were prevented because the problem was caught before any American citizens were directly impacted.
- 0: The number of sensitive data extracted from any DHS networks due to the failure of FEMA's IT department.
Sources:
- US Department of Homeland Security. Homeland Security Secretary Fires FEMA IT Employees Over Security Failures. (n.d.)