When FEMA made headlines last week for a catastrophic cybersecurity failure, it was described as sudden, shocking, and unprecedented. DHS Secretary Kristi Noem announced the firing of FEMA’s CIO, CISO, and 22 IT staff after a cybersecurity review uncovered systemic neglect: no multi-factor authentication, use of prohibited legacy protocols, unpatched vulnerabilities, poor monitoring, and even reactivation of compromised accounts after DHS disabled them.
It was dramatic, but it wasn’t new.
FEMA is an agency that exists to manage extremes — hurricanes, wildfires, floods, and disasters that test the limits of resilience. Yet its own IT and cybersecurity infrastructure collapsed under the most basic of failures. That collapse wasn’t the result of a single moment of negligence. It was years in the making.
The Known Weaknesses
DHS’s own Office of Inspector General (OIG) has been sounding the alarm for years.
In 2019 (OIG-19-58), FEMA was cited for relying on unauthorized devices and manual workarounds, introducing errors and bypassing controls.
In 2023 (OIG-23-16), FEMA was caught reclassifying failed security settings as “informational” instead of fixing them, artificially inflating compliance metrics while problems lingered.
The OIG also flagged failure to promptly disable accounts of former employees, leaving dormant accounts active long after departures.
These weren’t minor footnotes — they were warnings that the foundation of FEMA’s IT was compromised. By 2025, when DHS OCIO conducted its review, the problems had simply matured into full-blown collapse.
Failures Evolve Over Years
Think of cyber resilience like a row of dominos. A single domino rarely causes collapse. But line up enough weaknesses, and a small push will topple the entire chain.
Agency / Company 🏢Appears stable on the surface.
Leadership Prioritizes Convenience Over Security ⚡Sometimes leaders chase speed, demanding delivery over safeguards. Other times they avoid change, fearing disruption. Both paths prioritize convenience, not resilience.
Identity Sprawl 👤Accounts are created outside approved process. ICAM mandates exist (OMB M-19-17, OMB M-22-09, NIST SP 800-63, FISMA), but identity still grows uncontrolled.
MFA Unenforced 🔑Executive Order 14028 and OMB M-22-09 mandated phishing-resistant MFA. FEMA skipped it. This wasn’t just oversight — it was ignoring federal law.
Patches Skipped 🛠️CISA BOD 22-01 requires patching known exploited vulnerabilities in weeks, not months. FEMA missed the timelines.
Controls Bypassed 🚧OMB A-130 and NIST SP 800-53 require baseline controls and documentation. Bypassing them undermines the Authority to Operate. FedRAMP prohibits running systems without controls, yet FEMA looked the other way.
Collapse 🔓Years of ignored mandates, governance gaps, and cultural rot finally knocked the last domino down.
These aren’t the only causes of cyber failure — but they are some of the most prevalent. Third-party dependencies, insider threats, and cloud misconfigurations all play roles in other incidents. Collapse is rarely about a single gap. It’s the accumulation of ignored fundamentals that makes failure inevitable.
Leadership and Culture
Technology alone doesn’t fail. Leadership and culture drive collapse.
The federal government still places most CISOs under CIOs — a structure that biases toward IT delivery rather than security governance. FEMA’s collapse demonstrates why this model is dangerous. IT leaders under pressure to innovate, deploy, and deliver are often tempted to downplay or defer security controls. Without independent CISO authority, cybersecurity becomes subordinate to convenience.
DHS itself noted that FEMA’s IT staff didn’t just miss requirements — they actively resisted oversight, lied about vulnerabilities, and re-enabled compromised credentials. That isn’t technical oversight. It’s cultural resistance.
The message is clear: security programs don’t collapse from patching delays alone. They collapse when leadership and culture treat governance as optional.
Comparative Federal Failures
FEMA is not the first federal agency to fall victim to neglected fundamentals:
OPM Breach (2015): Identity management failures left millions of personnel records exposed. MFA was not enforced, legacy systems were in use, and sensitive data was left vulnerable.
GAO & IRS Audits: Repeatedly flagged unpatched systems and expired software still running in critical tax infrastructure.
State-Level Ransomware Attacks: Several state governments were taken offline for weeks due to a lack of MFA, poor segmentation, and weak backup strategies.
Comparative Private-Sector Failures
The private sector is no different. Some of the most damaging breaches of the last decade were not “advanced” attacks, but preventable ones caused by the same neglected fundamentals FEMA failed to address.
Equifax (2017): One of the most infamous breaches in U.S. history came down to an unpatched Apache Struts vulnerability. The patch had been available for months. The result: 147 million personal records exposed.
Colonial Pipeline (2021): A single unused VPN account without MFA led to the shutdown of fuel distribution across the East Coast. The company paid a $4.4 million ransom, but the bigger cost was public trust.
Health Sector Ransomware (2020–2023): Hospitals across the U.S. and Europe have had surgeries canceled, patients diverted, and care delayed — often because patching was incomplete, MFA unenforced, or privileged accounts were mishandled. Lives were put at risk not because attackers were clever, but because defenses were weak.
The lesson is consistent across public and private sectors: most breaches don’t begin with zero-days. They begin with ignored basics.
The Federal Mandates Already Exist
It’s important to remember: nothing FEMA failed at was new or unregulated.
Identity Sprawl: OMB M-19-17 and NIST SP 800-63 mandated centralized ICAM.
MFA: EO 14028 and OMB M-22-09 required phishing-resistant MFA.
Patching: CISA BOD 22-01 mandated patching KEVs within weeks.
Controls: OMB A-130, NIST SP 800-53, and FedRAMP all required enforced, risk-documented controls.
Leadership Accountability: FISMA holds agency heads directly responsible for program effectiveness.
The problem is not lack of policy. It’s lack of enforcement.
Lessons for Leaders
Leadership sets the tone. Speed or inaction both prioritize convenience over resilience.
Mandates don’t equal compliance. Federal law already covers these basics. Accountability is missing.
Fundamentals matter. MFA, patching, ICAM, and baseline controls are non-negotiable.
Culture drives security. A culture of workarounds will eventually collapse.
Remediation is long-haul. Failures evolve over years. They can only be fixed with sustained effort.
Closing Thought
FEMA is supposed to be the model for resilience, but its downfall shows what happens when leadership, culture, and governance neglect the basics.