Skip to main content
  1. Home
  2. Computing
  3. News

The U.S. government is worse at cybersecurity than just about everyone else

Add as a preferred source on Google

Looking for another reason to mistrust the government? Its shoddy cybersecurity practices may be just the ammunition you need. New data from security risk benchmarking startup SecurityScorecard suggests that when it comes to safe practices online, U.S. federal, state, and local government agencies rank dead last in comparison to 17 major private industries, including transportation, retail, and healthcare. The report examined the “overall security hygiene and security reaction time” of government institutions, paying special attention to NASA, the FBI, and the IRS, all of which were hacked earlier this year.

Topics of interest included vulnerability to malware infections, exposure rates of passwords, and susceptibility to social engineering, among other criteria.

Recommended Videos

The results were none too complimentary for our government. “Across all industries surveyed by SecurityScorecard,” the report notes, “U.S. government organizations received the lowest security scores. SecurityScorecard tracked 35 data breaches among all U.S. government organizations between April 2015 and April 2016.”

The biggest deficiencies were found within three categories of security; Malware Infections, Network Security, and Software Patching Cadence. Shockingly, 90 percent of state organizations scored an “F” in Software Patching Cadence, and 80 percent received the same score in Network Security.

But the worst offender of all was NASA, who received the lowest score among all 600 U.S. government organizations surveyed. Joining the bottom feeders were the U.S. Department of State, and the IT systems of Connecticut, Pennsylvania, and Washington.

The Obama administration has certainly made attempts to address the overarching insufficiency of cybersecurity practices currently in play across a range of agencies. President Obama has asked for $19 billion from Congress to improve tech defenses, including $3.1 billion to modernize the IT infrastructure at a number of federal agencies.

“With serious data breaches making headlines on what seems like a weekly basis, our team felt compelled to turn a spotlight on government agencies and determine which of them are demonstrating a commitment to securing their infrastructure and which are falling short,” said Dr. Luis Vargas, senior data scientist at SecurityScorecard. “The data we uncovered clearly indicates that while some are improving their security postures, too many are leaving themselves dangerously exposed to risks and vulnerabilities, especially at the larger federal level.”

Lulu Chang
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
The best password managers for 2026
have i been pwned owner uncovers 13 million plaintext passwords leaked from free webhost is a safe password even possible we

Passwords are still a fact of digital life, even as passkeys slowly start to change how we sign in to our accounts. Apple, Google, and other platforms have also made their built-in password managers much more capable, giving people more options than ever for keeping track of their credentials. A dedicated password manager still has an important advantage, though: it can bring passwords, passkeys, two-factor authentication, secure notes, and shared credentials together across the different devices and platforms you use.

The best password managers also make good security habits easier to maintain. They can generate unique passwords instead of leaving you to come up with another variation of the same one, flag compromised credentials, and make it easier to share access without passing passwords around in messages. For families and people who regularly move between operating systems, they can be particularly useful, while privacy-focused services offer another reason to look beyond the tools built into your phone or browser.

Read more
Anthropic wants everyone to take a chill pill at cooking worryingly powerful AI models
Anthropic’s CEO thinks frontier AI is advancing faster than its safeguards, and his proposed fix amounts to giving the industry a speed limit
Claude Anthropic Featured

Anthropic CEO Dario Amodei thinks the AI industry is moving too fast for its own safety work to keep up. He still wants more powerful AI. He just wants companies to take longer getting there.

In a new essay, Amodei is calling for frontier AI companies to deliberately slow how quickly their models improve. The extra time would go toward understanding stronger systems and making sure safeguards work before another leap arrives. He argues AI progress would still remain fast.

Read more
OpenAI AI agents were linked to a cyberattack on RubyGems before the Hugging Face incident
Rogue AI concerns grow after OpenAI agents disrupt RubyGems in May attack
OpenAI logo on Microsoft surface

Artificial intelligence agents being tested by OpenAI were involved in a previously undisclosed cyberattack against RubyGems in May, an incident that is now raising uncomfortable questions about how much control humans really have over increasingly autonomous AI systems.

The attack overwhelmed RubyGems, a popular service used by software developers to publish and access Ruby packages, forcing operators to suspend new account registrations for four days. According to a report by The Wall Street Journal, OpenAI confirmed that its agents had been involved, but said they were using the platform to perform benign tasks and retrieve publicly available information during a training run.

Read more