A DHS inspector-general report published 23 September found that 88 of 102 federal civilian executive branch agencies — 86% — failed to implement all mandatory Secure Cloud Business Applications (SCuBA) policies required by Binding Operational Directive 25-01 by its June 2025 deadline, and that compliance had not improved by February 2026, when 78 of 102 were still non-compliant. The unimplemented baselines include blocking outdated authentication procedures, enforcing multifactor authentication and adopting a policy to protect sensitive and personally identifiable information — controls directly relevant to both credential-theft campaigns and the device-code phishing pattern that dominated this week's enforcement news. The IG's structural finding matters more than the rate: CISA lacks the authority to require full and timely implementation of BODs, so a directive that binds agencies in name produces cloud environments that "remain exposed to preventable threats". ScuBA was created after the 2022 SolarWinds attack to give agencies secure configuration baselines and assessment tooling; the report concludes that without defined enforcement oversight the federal cloud security posture is weakened enterprise-wide. CISA did not respond to the IG's report and did not answer CyberScoop's request for comment.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-24 |
| Source | CyberScoop |
| Reliability | Tier 2 |