GAO Has Launched Audit of DHS Security Network

The investigation focuses on three major security incidents and concerns over delayed notifications to Congress.

Updated on Oct. 8, 2026 in Cybersecurity

GAO Has Launched Audit of DHS Security Network

Live Poll

Do you trust government agencies to be transparent when they experience a cybersecurity data breach?

The Government Accountability Office has opened a formal review into three security incidents occurring on the Homeland Security Information Network between 2023 and 2026. This federal audit seeks to evaluate how the Department of Homeland Security handled these breaches and why it delayed reporting them to lawmakers.

Why it matters

This review, initiated by the fiscal 2025 defense policy package, aims to identify systemic weaknesses in network oversight. It addresses critical lapses in internal notification protocols after analysts repeatedly failed to flag active intrusions.

The GAO review covers three distinct breaches, including two caused by internal employee or contractor errors. A mid-2026 intrusion allowed attackers to maintain persistent access through hidden points and stolen credentials for weeks before discovery.

The players

Government Accountability Office

This is a non-partisan legislative agency that provides auditing, investigative, and evaluation services for the United States Congress.

Department of Homeland Security

This federal department is tasked with public security, including the management of domestic information networks and response to cyber threats.

The details

Investigators will examine two incidents resulting from human error, including a 2023 contractor coding mistake that granted unauthorized users entry to the network. During the 2026 incident, department analysts dismissed malicious activity as harmless on two separate occasions before the threat was neutralized.

Timeline

  1. A contractor coding error occurred in 2023.

  2. A security incident was recorded in 2025.

  3. Suspicious activity began on the network in mid-May 2026.

  4. Intruders installed hidden access points by June 4, 2026.

  5. Media reports highlighted the network intrusion in summer 2026.

The Tech Race

This audit follows a directive in the fiscal 2025 defense policy package. The investigation underscores the ongoing difficulty of securing legacy federal infrastructure against evolving digital threats.

The investigation highlights critical vulnerabilities that could affect the integrity of sensitive government data. Public scrutiny of these incidents may lead to tighter contractor vetting and mandatory security training protocols for federal employees.

The takeaway

Maintaining secure government networks requires both robust technical safeguards and vigilant human oversight. Organizations must ensure that suspicious network activity is escalated properly to prevent long-term access by malicious entities.

Further reading

For broader insight into federal protection efforts, explore the latest developments in Cybersecurity.

Source note: This article includes information reported by Nextgov.

Live Poll

Do you trust government agencies to be transparent when they experience a cybersecurity data breach?