IRS cybersecurity framework ‘not effective’ in key categories
Deficiencies could leave sensitive taxpayer data “vulnerable to inappropriate and undetected use,” TIGTA says.
• less than 3 min read
Any regular CFO Brew reader knows that cybersecurity threats are a strategic challenge for both the finance and technology functions. And government entities like the IRS certainly aren’t immune to cyber threats.
In fact, the IRS’s cybersecurity efforts were “not effective” in key areas including identification, detection, and protection in fiscal year 2026, according to a recent report from the Treasury Inspector General for Tax Administration (TIGTA).
The stakes are high for an agency that houses a large amount of sensitive taxpayer information. (It processed 271.4 million tax returns and other forms in 2025.) Without the IRS fixing its cyber shortcomings, “taxpayer data could be vulnerable to inappropriate and undetected use, modification, or disclosure,” according to the report.
Cyber shortcomings. A 2014 law called the Federal Information Security Modernization Act (FISMA) requires federal agencies to implement and report on information-security frameworks. Inspectors use a set of 30-plus metrics across six function areas established by FISMA to evaluate these frameworks.
The IRS scored “effective” in three of those six areas: govern, respond, and recover. The other three—identify, protect, and detect—were found to be not effective, according to the TIGTA report.
Some of the shortcomings TIGTA noted:
- “The IRS does not have a tool” that detects and alerts officials to “unauthorized software assets” and that prevents unauthorized programs from running on its network.
- Six of the seven information systems TIGTA reviewed “had critical vulnerabilities that were not remediated within 30 days, as required.”
- The IRS lacks endpoint detection and response capabilities to protect against malware on 29% of its “high value asset systems.”
- The agency’s information security continuous monitoring program (ISCM) is outdated because of its “recent reorganization.” Although the IRS disagreed with TIGTA on this point, the report notes that the agency’s current ISCM “references key roles that no longer exist within the IRS.”
“While the IRS has made some improvements over last fiscal year’s reported maturity level ratings, we determined that the IRS needs to take further steps to improve its security program deficiencies,” the report noted.
CFO Brew helps finance pros navigate their roles with insights into risk management, compliance, and strategy through our newsletter, virtual events, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
About the author
Alex Zank
Alex Zank is a reporter with CFO Brew who covers risk management and regulatory compliance topics. Prior to CFO Brew, he covered the property/casualty insurance industry.
CFO Brew helps finance pros navigate their roles with insights into risk management, compliance, and strategy through our newsletter, virtual events, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.