DHS Terminates 24 FEMA IT Employees Over Critical Security Flaws
Homeland Security Secretary Kristi Noem took swift action to address severe cybersecurity lapses within the Federal Emergency Management Agency's (FEMA) IT department. Following a routine cybersecurity review, FEMA's networks were found to have been breached, threatening the entire department and the nation. The vulnerabilities, including a lack of multi-factor authentication and failure to fix known vulnerabilities, were addressed before any sensitive data could be compromised. Two dozen IT employees, including agency Chief Information Officer Charles Armstrong and Chief Information Security Officer Gregory Edwards, were terminated due to their failure to comply with basic security protocols.
Key Takeaways:
- 24 FEMA IT employees, including Chief Information Officers Charles Armstrong and Gregory Edwards, were terminated for failing to address critical cybersecurity vulnerabilities.
- The vulnerabilities included a lack of multi-factor authentication, use of prohibited legacy protocols, and failure to fix known and critical vulnerabilities.
- FEMA employees resisted efforts to address the problem, avoided scheduled inspections, and lied to officials about the scope of cyber vulnerabilities.
- An internal FEMA email dated August 18 ordered employees to change their passwords due to recent cybersecurity incidents and threats.
- FEMA's systems were reviewed following a global hack involving Microsoft SharePoint products, but it's unclear if FEMA's networks were directly affected.
- The breach was addressed before any sensitive data could be compromised, according to DHS.
Statistics:
- 24 FEMA IT employees were terminated for failing to address cybersecurity vulnerabilities.
- The cybersecurity review uncovered several severe lapses in security, including a lack of multi-factor authentication.
- FEMA employees avoided scheduled inspections and lied to officials about the scope of cyber vulnerabilities.
- 100% of those terminated were part of the IT department.
- The breach was addressed within a two-week timeframe following the internal email.
- The cyber vulnerabilities were not specifically linked to the global Microsoft SharePoint hack.
Sources:
- "DHS-Immacted hack of Microsoft Sharepoint products" by Navy Federal Newsroom & Nextgov/FCW.
- "FEMA-IT-Employee terminations" by CBS News.