fismatrade-pressNewsThe Broadside1 min read

TIGTA rates IRS cybersecurity program "not effective"

IRS can govern, respond, and recover, but it still can't reliably identify threats, protect systems, or detect intrusions, the three functions that actually stop a breach.


TL;DR

The Treasury Inspector General for Tax Administration rated the IRS's information security program "not effective" for the most recent fiscal year under FISMA assessments. The agency was rated effective in govern, respond, and recover functions but fell short on identify, protect, and detect, the three NIST CSF functions most directly tied to preventing breaches. TIGTA warned that taxpayer data "could be vulnerable to inappropriate and undetected use, modification, or disclosure" if deficiencies aren't addressed.

The finding isn't new, it's the shape of the gap that's instructive.

IRS has been living with information-system control deficiencies for years. GAO has flagged significant deficiencies in IRS's information system controls going back to at least FY 2016, and as recently as its FY 2025 audit identified four new information-system control deficiencies, three access control and one security management. The August 2025 CIO open-recommendations letter from GAO tallied 36 open recommendations for the IRS CIO, 22 of them sensitive, spanning the cybersecurity and IT acquisition high-risk areas.

What the TIGTA report makes visible is the asymmetry: IRS can plan, respond, and recover (the govern/respond/recover ratings were effective) but it can't find weaknesses, harden systems, or see activity in real time. On identify, the agency still hasn't fully implemented corrective actions on outstanding POA&Ms and hasn't solidified ties with inventory-management system owners. On protect, six of seven sampled systems carried critical vulnerabilities that went un-remediated past the 30-day FISMA window, and IRS didn't produce an inventory of its critical software. On detect, a reorganization stalled the agencywide continuous monitoring strategy.

CIO Kaschit Pandya pushed back on TIGTA's ISCM maturity rating but acknowledged the need for "continued improvement." The letter leaves the door open for a better score next cycle, but the gap between what IRS can govern and what it can actually secure is the same gap an attacker exploits.


Published ·Deep Fathom