{"id":24215,"date":"2017-12-13T16:22:48","date_gmt":"2017-12-13T16:22:48","guid":{"rendered":"https:\/\/one.sightlinemg.com\/federaltimes\/uncategorized\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/"},"modified":"2026-08-08T18:24:16","modified_gmt":"2026-08-08T18:24:16","slug":"what-agencies-can-learn-from-opms-cyber-challenges","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/","title":{"rendered":"3 lessons agencies can learn from OPM\u2019s cyber challenges"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Office of Personnel Management\u2019s own inspector general recently completed an audit of the agency\u2019s security programs and practices and the findings were, at best, a mixed bag. Thorough and extensive, the resulting report could easily be applied to many agencies and is a piercing commentary on the state of cybersecurity in many federal agencies today.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Interestingly, the audit used the NIST Cybersecurity Framework to measure the overall maturity level of the OPM security program with five levels of maturity ranging from \u201cAd Hoc\u201d to \u201cOptimized.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The OIG report rates OPM\u2019s program overall level at 2 (\u201cDefined\u201d), although it gives the agency the high mark of 4 (\u201cManaged and Measurable\u201d) in their ability to respond to incidents. This comes as no surprise, given the high-profile breach of security clearance records in 2015 at OPM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The resulting OIG report offers three key lessons for agencies seeking to avoid the issues facing OPM today:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>1. Organize your assessment documents regularly.<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The tone of the report suggests a tension between the agency\u2019s security team and those performing the audit \u2014 an all-too-familiar situation seen today. In fact, the OIG notes that the agency has struggled with ongoing security control assessments for over a decade. Citing \u201caudit fatigue,\u201d the security team expresses that the audits are duplicative and strain already scarce resources. However, the OIG puts OPM\u2019s disorganization at fault, mentioning a specific occasion where auditors spent 600 hours evaluating a package of documents, only to discover the documents were outdated and incorrect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whether an organization uses a simple folder or a high-end document management system, it is essential to implement and enforce a strict structure for organizing the voluminous documentation associated with assessment and authorization requirements. From time-stamping documents to making final copies read-only, agencies can save tremendous amounts of labor and time. But organizing documents is more than an administrative exercise. An accurate assessment of risk and planning for security program improvements rests squarely on the accuracy for documentation. If it isn\u2019t clear which documents are correct, how can an agency know how to improve their security posture?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>2. Resolve findings and enforce POA&amp;Ms.<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The OIG report takes OPM to task for its failure to remediate findings from past audits, specifically citing weaknesses in continuous monitoring, contingency planning and Plans of Action and Milestones (POA&amp;Ms). It notes that OPM has only closed 34 percent of the FISMA findings in the past two years \u2014 which is expected to only increase as FISMA audits continue. Some findings and recommendations have even been unresolved for over a decade.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If POA&amp;Ms are organized, it is much easier to stay ahead of audit findings and to resolve them before they become chronic issues. POA&amp;Ms must have some \u201cteeth\u201d to be more than exercises in paperwork. Deadlines need to be taken seriously, and if a resource shortage is the cause of a continuous problem, agencies should document the reasons thoroughly to prepare for future audits. If findings are documented clearly, tension may also ease between security and audit teams \u2014 which can also lead to candid discussion and cooperation on how to improve an agency\u2019s overall security status.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>3. Don\u2019t wait for a major breach to happen.<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OPM\u2019s experience shows the agencies must develop a robust response capability before the face a major breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a result of the 2015 breach, OPM\u2019s reputation suffered and the agency head was asked to leave. More importantly, millions of people \u2014 including myself \u2014 found that their security clearance information had been compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Protection needs to be a reflexive action rather than a reaction. No agency is immune, but a robust and timely response capability could have mitigated the damage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Will IT modernization help?<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, many agencies see modernization as a complicated effort, rather than one that can resolve their security challenges. Support systems for new technology can be hard to find, and thus are more expensive. The transition period to a new system can also bring security issues itself, and there is always potential for new hardware and software to be vulnerable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Modernization is more than installing new software or eliminating unused and redundant legacy systems. It is an ongoing effort. It requires continuous upgrades, constant systems improvements, ongoing staff training, and a commitment to security from the top. It\u2019s essential for agencies to look at modernization as an opportunity to simplify and streamline systems, the types of efforts that can help them avoid the challenges facing OPM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The OPM OIG report could easily be applied to many agencies and is a piercing commentary on the state of cybersecurity in many federal agencies today.<\/p>\n","protected":false},"author":7,"featured_media":37684,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":26,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[106,31,33,26],"tags":[],"coauthors":[7659],"class_list":["post-24215","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-daily-brief","category-home","category-newsletters","category-opinions"],"acf":{"subheadline":"","legacy_arc_id":"XSD4OM74KREMNDYJPYR5WBYEEU","arc_canonical_url":"\/opinion\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>3 lessons agencies can learn from OPM\u2019s cyber challenges - Federal Times<\/title>\n<meta name=\"description\" content=\"The OPM OIG report could easily be applied to many agencies and is a piercing commentary on the state of cybersecurity in many federal agencies today.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"3 lessons agencies can learn from OPM\u2019s cyber challenges\" \/>\n<meta property=\"og:description\" content=\"The OPM OIG report could easily be applied to many agencies and is a piercing commentary on the state of cybersecurity in many federal agencies today.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2017-12-13T16:22:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T18:24:16+00:00\" \/>\n<meta name=\"author\" content=\"Don Maclean, DLT Solutions\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Don Maclean, DLT Solutions\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"3 lessons agencies can learn from OPM\u2019s cyber challenges\",\n\t            \"datePublished\": \"2017-12-13T16:22:48+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:24:16+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/\"\n\t            },\n\t            \"wordCount\": 753,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635703168817731851-477322540jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Daily Brief\",\n\t                \"Home\",\n\t                \"Newsletters\",\n\t                \"Opinion\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/\",\n\t            \"name\": \"3 lessons agencies can learn from OPM\u2019s cyber challenges - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635703168817731851-477322540jpg.jpg\",\n\t            \"datePublished\": \"2017-12-13T16:22:48+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:24:16+00:00\",\n\t            \"description\": \"The OPM OIG report could easily be applied to many agencies and is a piercing commentary on the state of cybersecurity in many federal agencies today.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635703168817731851-477322540jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635703168817731851-477322540jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2017\\\/12\\\/13\\\/what-agencies-can-learn-from-opms-cyber-challenges\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Opinion\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/\",\n\t                    \"ad_zone\": \"opinions\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"3 lessons agencies can learn from OPM\u2019s cyber challenges\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"3 lessons agencies can learn from OPM\u2019s cyber challenges - Federal Times","description":"The OPM OIG report could easily be applied to many agencies and is a piercing commentary on the state of cybersecurity in many federal agencies today.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/","og_locale":"en_US","og_type":"article","og_title":"3 lessons agencies can learn from OPM\u2019s cyber challenges","og_description":"The OPM OIG report could easily be applied to many agencies and is a piercing commentary on the state of cybersecurity in many federal agencies today.","og_url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/","og_site_name":"Federal Times","article_published_time":"2017-12-13T16:22:48+00:00","article_modified_time":"2026-08-08T18:24:16+00:00","author":"Don Maclean, DLT Solutions","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Don Maclean, DLT Solutions","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"3 lessons agencies can learn from OPM\u2019s cyber challenges","datePublished":"2017-12-13T16:22:48+00:00","dateModified":"2026-08-08T18:24:16+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/"},"wordCount":753,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635703168817731851-477322540jpg.jpg","articleSection":["Daily Brief","Home","Newsletters","Opinion"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/","url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/","name":"3 lessons agencies can learn from OPM\u2019s cyber challenges - Federal Times","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635703168817731851-477322540jpg.jpg","datePublished":"2017-12-13T16:22:48+00:00","dateModified":"2026-08-08T18:24:16+00:00","description":"The OPM OIG report could easily be applied to many agencies and is a piercing commentary on the state of cybersecurity in many federal agencies today.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635703168817731851-477322540jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635703168817731851-477322540jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2017\/12\/13\/what-agencies-can-learn-from-opms-cyber-challenges\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Opinion","item":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/","ad_zone":"opinions"},{"@type":"ListItem","position":3,"name":"3 lessons agencies can learn from OPM\u2019s cyber challenges"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635703168817731851-477322540jpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/federaltimes","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/24215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=24215"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/24215\/revisions"}],"predecessor-version":[{"id":24217,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/24215\/revisions\/24217"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=24215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=24215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=24215"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=24215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}