- news
- TAX
IRS cyber weaknesses put taxpayer data at risk again, TIGTA says
Related
Unclear instructions, limited awareness plagued CP53E rollout, TIGTA says
Government says Kwong court misread COVID tax relief law
IRS delayed action on thousands of high-income nonfiler cases, TIGTA says
For the second consecutive year, a watchdog has labeled the IRS’s cybersecurity program so ineffective that taxpayer data could be at risk if the agency fails to address security weaknesses.
For the 2026 fiscal year, a report from the Treasury Inspector General for Tax Administration (TIGTA) found that 86%, or six of seven, sampled information systems had critical vulnerabilities that were not fixed within the IRS’s required 30-day time frame. The report also said the agency could not provide an inventory of its critical software.
“If the IRS does not take steps to mitigate these deficiencies, taxpayer data could be vulnerable to inappropriate and undetected use, modification, or disclosure,” TIGTA said in the report, dated Sept. 15.
The report for fiscal year 2025 also concluded that the IRS’s cybersecurity program was not effective and that taxpayer data could be vulnerable.
For fiscal 2026, TIGTA found that the IRS’s cybersecurity program failed to meet federal standards because the agency fell short in identifying cybersecurity risks, protecting systems and data, and detecting threats. However, the IRS received effective ratings in cybersecurity governance, incident response, and recovery.
Among other findings, TIGTA reported that 841 privileged service accounts spanning 313 systems remain outside the IRS’s privileged account management system. The agency has not fully implemented data-at-rest encryption across critical systems despite an internal goal of completing the effort by the end of fiscal year 2024. The IRS, according to the report, has adjusted the completion date for that implementation to fiscal year 2027.
The report also found that endpoint detection and response capabilities were missing from 29% of the seven high-value asset systems reviewed and cited weaknesses in the IRS’s ability to identify unauthorized hardware and software on its network.
Despite the overall assessment, TIGTA noted progress in several areas. The watchdog said 72% of the cybersecurity metrics reviewed were rated at advanced maturity levels. It also cited improvements in multifactor authentication implementation, audit log collection, and configuration compliance.
The IRS challenged TIGTA’s assessment of two measures related to information security continuous monitoring. IRS officials argued that the agency deserved higher ratings for its monitoring strategy and ongoing security control assessments.
TIGTA disagreed. “The IRS was unable to maintain an organization-wide strategy,” the report said, noting that the agency had not updated its monitoring strategy after a reorganization and had not fully assessed security and privacy controls across its cloud systems.
Only about one-third of required control assessments had been completed, TIGTA said.
The report made no recommendations because TIGTA’s annual reviews under the Federal Information Security Modernization Act are designed to measure agency performance against established cybersecurity metrics rather than to prescribe corrective actions.
— To comment on this article or to suggest an idea for another article, contact Martha Waggoner at Martha.Waggoner@aicpa-cima.com.
