cisatrade-pressNewsThe Broadside2 min read

Wyden demands two-year deadline to purge federal VPNs

Five years after EO 14028 ordered a zero-trust migration, a Senate Intelligence member puts a clock on removing the legacy VPNs that keep getting breached.


TL;DR

Sen. Ron Wyden (D-OR) urged CISA, OMB, and NIST on Monday to set a two-year deadline for federal civilian agencies to purge internet-facing legacy VPNs and replace them with zero-trust architecture. He also called on NSA to order a parallel purge across military and intelligence networks. The Senate Intelligence Committee member cited breaches of Cisco, Fortinet, Ivanti, and Check Point products by foreign adversaries. The letter carries no enforcement power, it asks three agencies to issue directives they haven't yet written.

Sen. Ron Wyden's letter to CISA, OMB, and NIST marks the first time a Senate Intelligence Committee member has called for a government-wide deadline to remove legacy, internet-facing VPN servers, and the vendors he names are the ones whose breach notifications have become a familiar rhythm for federal contractors. Cisco. Fortinet. Ivanti. Check Point. "For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers," Wyden wrote.

The timing is pointed, not accidental. Executive Order 14028 ordered federal agencies to adopt zero-trust architecture back in May 2021. CISA's Binding Operational Directive 26-02, issued in February 2026, required FCEB agencies to manage the lifecycle of end-of-support edge devices, routers, firewalls, VPN gateways that manufacturers no longer patch. But BOD 26-02 didn't touch still-supported VPNs running outdated or proprietary protocols that remain exploitable. Wyden's letter fills that gap: he's asking the agencies to ban the technology category, not just the unpatched instances.

What a directive would mean for contractors

If CISA and OMB act on Wyden's request, primes and subcontractors connecting to federal networks through legacy VPN concentrators face a two-year clock to rip and replace. That's capital expenditure on zero-trust remote access (software-defined perimeters, continuous authentication, microsegmentation) plus the operational grind of migrating remote workflows without breaking them. Agencies that miss the deadline would presumably find their VPN gateways blocked from federal network ingress. Wyden's letter doesn't specify enforcement, but OMB's memo power under 44 U.S.C. § 3553 gives it the authority to impose one.

Wyden also pressed NIST to create "implementation standards" for the migration. That request matters because zero-trust isn't a product you buy; it's an architecture you build, and without NIST guidance, every agency and contractor will build it differently, or worse, buy something labeled "zero-trust" and call the job done.

The letter can't compel; the breaches already did

Wyden's letter has no independent enforcement authority. He's asking CISA, OMB, and NIST to wield theirs. Whether they do is the open question. But the senator is not making a speculative case: he's citing "multiple recent and devastating hacking campaigns" in which Russian and Chinese adversaries exploited internet-facing VPNs to gain administrative access to target networks and steal sensitive data. The breaches are public. The only thing missing, Wyden argues, is a clock counting down.


Published ·Deep Fathom