Federal CIO Tony Scott has told audiences that one of his key operating tenets is to never let a good crisis go unexploited.
So it is with the recent megabreach that hit the Office of Personnel Management databases and made off with the personally identifiable information of more than 21 million people who applied for federal jobs and security clearances. The breach — along with a long track record of cybersecurity neglect at the agency — led to numerous congressional hearings and the abrupt resignation of OPM Director Katherine Archuleta in July.
Scott saw his opportunity: He launched a high-profile, 30-day “Cybersecurity Sprint” as a way to apply intense, top-level focus to existing cybersecurity weaknesses across federal agencies and to shore them up as quickly as possible. The effort showed good progress, but far from what is needed. Based on the progress report that Scott unveiled on July 31, many agencies dramatically stepped up their employees’ use of so-called two-factor authentication to gain access to federal networks. In a nutshell, this means federal employees must use their smart ID cards — known as PIV (personal identity verification) cards — as a second form of ID (in addition to their passwords) to access their privileged networks.
The ultimate goal of Scott and the Office of Management and Budget is to get all agencies adopting two-factor authentication for at least 75 percent of their workforces. What is instructive is to compare the percentages each agency was at in fiscal 2013 and fiscal 2014 to where they are now. These are listed agency by agency in the annual OMB Federal Information Security Management Act reports.
In the case of OPM, for example, 0 percent of the workforce was using strong authentication in 2013. In 2014, the figure improved to 1 percent. Miraculously, the figure is now 97 percent.
A few other notable results:
The Transportation Department went from 7 percent in 2013 to 31 percent in 2014 to 97 percent today.
The Interior Department went from 0 percent in 2013 to 36 percent in 2014 to 89 percent.
The Department of Veterans Affairs went from 4 percent in 2013 to 10 percent in 2014 to 81 percent.
The Treasury Department went from 9 percent in 2013 to 43 percent in 2014 to 88 percent.
The Small Business Administration went from 0 percent in 2013 and in 2014 to 44 percent.
Despite these and other positive signs of progress, there are some curious anomalies as well. The Defense, Education, Justice and Energy departments all saw their percentages drop during the sprint. I’d love to hear some explanation of why that happened.
Clearly, there was some major top-level arm-twisting at play.
In fact, former Treasury Department CIO Jim Flyzik was quoted in a recent news report as saying that “government leaders are no longer accepting justifications for why two-factor authentication can’t be rolled out across the entire government — it can be done, and it is happening now. Consequences for failure are more severe than ever before, as a lack of compliance with the rollout will result in the disabling of user accounts until they fulfill all requirements. Thankfully, the tide is now turning, and smart card-based two-factor authentication is becoming a major access requirement for all federal agencies.”
OMB has traditionally shied away from force-feeding good management policy to agencies. But in this case, it did — and with good progress to show for it. My view is that OMB should consider using that strong arm a lot more.
Kudos to Tony Scott, who clearly saw a good crisis and made the most of it. Hopefully, that momentum won’t be lost
Steve Watkins is a contributing editor.
Making the most of a good scandal




