Key Takeaways
- The VA’s Office of Information and Technology (OIT) has lacked a Senate‑confirmed CIO and a permanent CISO for roughly two years, leaving critical cybersecurity leadership vacant.
- An independent FISMA audit this summer rated VA’s information‑security program deficient in seven areas, producing 19 recommendations that the agency rejected, dismissing the audit as merely a “snapshot in time.”
- Despite a substantial FY 2026 budget increase for zero‑trust initiatives, VA admits its identity, network, and application defenses remain at the lowest maturity level (“Initial”), indicating spending lacks a strategic plan tied to risk.
- A recent VA memo that removes the FedRAMP requirement for contracts highlights a broader problem: risk decisions are made without thorough analysis of the human impact on veterans.
- Bill James argues that appointing a resourced, permanent CISO would simultaneously address the cybersecurity gaps identified by FISMA and restore the empathy‑driven risk mindset already present in the Veterans Health Administration.
- Effective enterprise risk management requires ownership, continuity, and a process that turns audit findings into concrete fixes—something VA currently lacks.
Enterprise Risk Management Failures at the VA
During my tenure as deputy assistant secretary for DevOps in the Department of Veterans Affairs’ Office of Information and Technology (OIT), I observed a persistent breakdown in how the agency manages enterprise IT risk. Policies exist on paper, but execution consistently falls short because leadership turnover prevents any single individual from seeing a initiative through from conception to completion. This gap is not a recent anomaly; it has persisted for at least two years, undermining the VA’s ability to protect veterans’ data and services.
Audit Findings Highlight Systemic Deficiencies
An independent audit conducted under the Federal Information Security Modernization Act (FISMA) this summer revealed that VA’s information‑security program is deficient across seven distinct areas. The Office of Inspector General issued 19 concrete recommendations aimed at remediating these weaknesses. Rather than treating the findings as a roadmap for improvement, VA leadership dismissed the audit as merely a “snapshot in time” and refused to concur with any of the suggestions, signaling a reluctance to act on external assessments.
Leadership Vacuum in Critical Cybersecurity Roles
The root of the problem lies in the prolonged absence of confirmed leadership. VA has yet to secure a Senate‑confirmed Chief Information Officer (CIO); the administration’s third nominee underwent a hearing in June but remains unconfirmed. Simultaneously, the Chief Information Security Officer (CISO) position has been filled only by acting officials, with two successive acting holders in a row. For roughly two years, the two roles most accountable for managing enterprise IT risk have effectively been vacant, leaving the agency without the authority and continuity needed to drive lasting change.
Funding Without a Strategic Plan
Congress has recognized the urgency of improving VA’s cyber posture, allocating a substantial increase in zero‑trust funding for fiscal year 2026. Yet when asked about the maturity of its zero‑trust implementation, VA’s own assessment places identity, network, and application defenses at the lowest rung—“Initial.” This disconnect shows that money is being appropriated without a clear, published plan linking expenditures to specific risks that a permanent CISO would prioritize. Consequently, there is no mechanism for Congress or oversight bodies to verify whether the spending is actually moving the agency beyond its baseline rating.
Risk Decisions Lacks Human‑Centered Analysis
A recent VA memo eliminated the requirement that contracts obtain Federal Risk and Authorization Management Program (FedRAMP) certification. While I agree in principle that the secretary—and by extension the CIO—owns the risk of serving veterans, the memo reveals a deeper flaw: risk acceptance is being reduced to a cost‑saving measure without a thorough analysis of how those decisions affect veterans. My personal mantra as deputy assistant secretary for DevOps—“DevOps equals empathy”—emphasized tracing every technical choice back to its human impact. The Veterans Health Administration (VHA) already operates a formal enterprise risk‑management office that treats risk as a mission‑wide concern; OIT must adopt a similar mindset to ensure that procurement and technical decisions truly serve those who rely on VA services.
Lessons from the Unfunded Requirements Review
Each fall, OIT conducts an unfunded requirements review (UFR) where executives approve last‑minute funding for programs they may not have directly overseen. In one instance, I was asked to sign off on wide‑area network infrastructure funding. Initially, the decision seemed straightforward, but after consulting with VHA’s telehealth team I learned that the network carried real‑time calls from veterans receiving care. That conversation shifted my perspective and altered the funding decision. The episode illustrates how a lack of continuous, informed oversight can lead to misaligned investments, and how frontline insight is essential for effective risk management.
Path Forward: Appoint a Permanent, Resourced CISO
The solution to VA’s chronic risk‑management failure is both clear and actionable: appoint a permanent, Senate‑confirmed CISO with adequate authority and resources. A stable CISO would bridge the gap between policy and execution, ensuring that cybersecurity investments—such as the zero‑trust funds—are guided by a strategic risk‑based plan. Moreover, a empowered CISO could enforce the empathy‑driven risk analysis already practiced by VHA, making certain that every procurement and technical decision balances cyber threats with the potential impact on veterans’ health services. Only then can VA move beyond treating audits as mere snapshots and begin building a resilient, veteran‑centric IT enterprise.
About the Author
William “Bill” James served as deputy assistant secretary for DevOps at the Department of Veterans Affairs’ Office of Information and Technology. His debut techno‑thriller, The Chariot Protocol, set within the VA environment, is slated for publication in September 2026. This commentary reflects his observations from years inside the agency and his call for leadership that aligns technology, risk management, and the mission of serving veterans.

