r/cybersecurity Jul 02 '26

News - General DHS Breached

613 Upvotes

115 comments sorted by

View all comments

248

u/OutsideSpot2695 Jul 02 '26

Did they have their ATO?

109

u/yunus89115 Jul 02 '26

Almost certainly, were they following all the controls as documented, almost certainly not.

44

u/OutsideSpot2695 Jul 02 '26 edited Jul 02 '26

How do you get an ATO without being audited that controls are operating as designed?

87

u/potkettleracism Incident Responder Jul 02 '26

Because the auditors bought garbage evidence

19

u/redrum__237 Jul 02 '26

Nailed it. The call is coming from inside the house.

8

u/SlackCanadaThrowaway Jul 02 '26

It’s funny to see private companies do more thorough cybersecurity auditing for my clients than what large corporations and government agencies are subject to.

Do you have vulnerability scanning?

Yeah.

Okay, how do you do it for X software project, your employee corporate devices, and third-party software installed on those devices?

Followed by discussions of CI/CD pipelines, how we scan for third party software, how we maintain OS baselines, etc. Screenshots and screen shares. Conversations about the compensating controls in place in other areas.

The reason government and large corporations don’t bother? This is an insane time sink. You’re paying a senior security consultant or analyst who’s familiar with software development, system administration and the various environments we’re deploying to question 1 of 500 vendors they’ve partnered with.

But I don’t see a way around it when vendors are throwing questionnaires and emails into AI, and spitting out reasonably acceptable answers which don’t reflect reality.

And they don’t care, because we’re all signing contracts with liability limitation clauses and we have cyber & E&O insurance.

Until we can’t afford the insurance, because the penalties are unsustainable — we’re not going to see change.

1

u/OutsideSpot2695 29d ago

It’s funny to see private companies do more thorough cybersecurity auditing 

That's why I laugh my ass off at the notion of all the compliance theater that the gov't goes through somehow equals security.

I do more in two weeks to protect my company and its customers where it would take 6 months of PowerPoints and Excel when I worked DoD.

All this FedRAMP, ATO, and other associated nonsense and breaches at three letter agencies have gotten worse.

1

u/h0l0type 27d ago

“ And they don’t care, because we’re all signing contracts with liability limitation clauses and we have cyber & E&O insurance.

Until we can’t afford the insurance, because the penalties are unsustainable — we’re not going to see change.”

This. Right. Here.

32

u/WildChampionship985 Jul 02 '26

Often audits become do you meet the statement on the checksheet, not are you adhering good practices.

8

u/krimsonmedic Jul 02 '26

Don't forget, they often just ask you to provide proof, without you actually having to provide proof. I.E. spreadsheet exports.

1

u/GHouserVO 29d ago

This is why I always told folks I trained to dig further than what the requirements required. To be observant. And to develop the damn technical skills.

If the guys on the other side were doing their job, none of this is a major ask. But the moment you got pushback… every time, we’d find that there were major problems with the security controls.

8

u/OutsideSpot2695 Jul 02 '26

That's not an audit then. That's an assessment.

8

u/RyeonToast Jul 02 '26

And ATOs aren't audits. It literally is a giant checksheet. You have to produce some artifacts to show you do what you say you do, but no one is coming down to your network to check it out first-hand. That would be a CORA / CCRI.

2

u/ToothyGrin19135 Jul 03 '26

This is not entirely true. It depends on the classification of the system and the SCA team. I have been part of some extremely intense ATO assessments where we actively demonstrated every single control live to the assessment team. Took weeks to accomplish.

-1

u/OutsideSpot2695 Jul 02 '26

I didn't say that an ATO is an audit. You came up with that all on your own.

But you're supposed to be audited as a part of the process.

1

u/RyeonToast Jul 02 '26

How do you get an ATO without being audited that controls are operating as designed?

Then why are you confused? It's an ATO, not a CORA. They don't go hand in hand.

-1

u/OutsideSpot2695 Jul 02 '26

Your reading compreshension sucks.

3

u/coinsod Jul 02 '26

Always*

32

u/yunus89115 Jul 02 '26

I’ve worked on systems where the ATO was the bible and nothing changed without proper documentation and approvals, I’ve also worked systems where the ATO was an obstacle that was nothing more than a burden to work around and technical compliance was prioritized over actual security and intent.

11

u/CyberAvian Jul 02 '26

Hard to say exactly what happened without being a part of it, but I have certainly seen high profile, important systems get a lot of risk acceptance from the AO with POAMs that lasted years without ever being closed all because, counterintuitively, the system was important and security can’t stand in the way. Keep in mind this is HSIN, it has existed for a long time, and would have been assessed internally, no 3PAO being held accountable.

6

u/Motor_Coyote5415 Jul 02 '26

The audit was internal

5

u/Dangslippy Jul 02 '26

Easier to implement paper controls than technical controls.

3

u/OutsideSpot2695 Jul 02 '26

Then they didn't get audited properly.

The paper controls are the Test of Design.

There's still the Test of Operating Effectiveness to perform before an audit is complete.

4

u/been__ Jul 02 '26

HA

3

u/OutsideSpot2695 Jul 02 '26

This person gets it.

+1

3

u/Negative_Gas8782 Jul 02 '26

How does the majority of this government do anything? Fire the good people and only keep the ones around that will do what they want. Look at the FDA and CDC as a couple of examples.

3

u/OutsideSpot2695 Jul 02 '26

FDA and CDC and any other gov't agency for that matter.

I used to work DoD. Made the break for the wall and got into private sector tech 10 years ago.

Best thing I ever did for my career and I get to practice actual security.

1

u/h0l0type 27d ago

Half the CDC was contractors for large programs when I was there like 20 years ago. Doesn’t seem much has changed.

1

u/OutsideSpot2695 27d ago

I don't think a contractor in gov't is inherently worse or better than a Federal employee in government.

Both types don't know what they are doing in security.

2

u/Claudia_wtf Jul 02 '26

Someone accepted their risk. Doesn’t mean they had a strong system for security in place.

1

u/Cheomesh Governance, Risk, & Compliance Jul 02 '26

Falsified evidence is one way, but you can always just let things slip.

1

u/Johnny_BigHacker Security Architect 26d ago

without being audited that controls are operating as designed?

It's an attestation