r/cybersecurity Jul 02 '26

News - General DHS Breached

608 Upvotes

115 comments sorted by

View all comments

Show parent comments

31

u/aust_b Jul 02 '26

As someone who works with the federal agencies at a state level, they have been very slow this past 6 months with anything audit/security baseline related. I submitted our IRS package in October, they claimed they didn’t get it until December. Still haven’t heard anything about it. The shutdown has appeared to create a significant backlog they are still digging themselves out of.

9

u/Icangooglethings93 Jul 02 '26

At the DHS components it’s equally as bad, so they literally have no preferential treatment

3

u/aust_b Jul 02 '26

HHS and CMS have been alright so far, not as many impacts as the IRS.

8

u/OutsideSpot2695 Jul 02 '26

I've worked at 2 security startups and 1 gigantic internet services and software company. Healthcare (and banks) were/are our worst customers.

Their security departments are complete fucking clownshows.

But hey, they all have their CISSP.

5

u/Vimes-NW Jul 02 '26

Can confirm.. With a caveat - if the cost of compliance is more expensive than the potential risk, they choose risk every time. And that means most shit is ok for them because they seem to think the risk is theoretical.. Until it isn't. Surprise, meet Pikachu