GAO Calls on DHS to Implement Cybersecurity and Disaster Preparedness Recommendations

0
1

Key Takeaways

  • The Government Accountability Office (GAO) has identified three priority areas for the Department of Homeland Security (DHS): disaster preparedness and response, IT and cybersecurity, and immigration and border security.
  • As of July 2025, DHS carries 507 open GAO recommendations, of which 39 are designated priority; five have been implemented and two were closed as no longer valid, leaving the priority count unchanged at 39.
  • GAO’s assessment shows an 86 % implementation rate for its recommendations at DHS, higher than the government‑wide average of 77 % for recommendations made five years ago.
  • Specific GAO actions include urging FEMA to consolidate fragmented disaster‑recovery programs, directing CISA to issue clearer guidance for the Continuous Diagnostics and Mitigation (CDM) program, and correcting ICE detention reporting and CBP’s non‑intrusive inspection equipment deployment at the southwest border.
  • Parallel GAO reviews reveal limited progress in DHS’s human‑resources IT modernization effort and significant cost overruns—approximately $11.4 billion (26 % increase)—across major acquisition programs.
  • The upcoming 2026 Homeland Security Summit (Nov. 12, 2026) will focus on artificial intelligence, cyber defense, and operational capabilities, providing a forum for government and industry leaders to address the gaps highlighted by GAO.

Overview of GAO’s Priority Concerns for DHS
The Government Accountability Office has consistently highlighted three overarching domains where DHS must improve its operations to meet evolving threats and fulfill its statutory missions. First, disaster preparedness and response suffer from program fragmentation that hampers effective coordination between federal, state, and local entities. Second, IT and cybersecurity weaknesses persist, particularly in the adoption of comprehensive network‑defense tools and the protection of operational technology systems. Third, immigration and border security policies are hampered by inaccurate data reporting and incomplete deployment of screening technologies, which together undermine situational awareness and resource allocation. These priority areas form the backbone of GAO’s latest recommendations and are reflected in the department’s open recommendation inventory.

Disaster Preparedness and Response Recommendations
GAO’s letter to Secretary Markwayne Mullin specifically targets the Federal Emergency Management Agency (FEMA), urging it to address the fragmentation of its disaster‑recovery programs. State and local officials have repeatedly complained that they must navigate a patchwork of initiatives, each with distinct eligibility rules, timelines, and limited information‑sharing capabilities. To alleviate this burden, GAO recommends that FEMA either consolidate overlapping programs or simplify their requirements, thereby creating a more streamlined pathway for assistance. By reducing administrative complexity, FEMA could improve the speed and effectiveness of aid delivery, enhance coordination with partners, and ultimately strengthen national resilience against natural and man‑made disasters.

Cybersecurity Improvements Urged by GAO
On the cybersecurity front, GAO spotlighted the Continuous Diagnostics and Mitigation (CDM) program managed by the Cybersecurity and Infrastructure Security Agency (CISA). Launched in 2012, CDM aims to provide federal agencies with real‑time visibility into their network health and to deploy essential data‑protection tools. However, GAO found that several agencies have not fully adopted CDM due to insufficient guidance from CISA. The watchdog advises CISA to issue clearer, more detailed direction on how agencies should roll out CDM components, integrate them into existing security architectures, and collaborate to mitigate cyber risks affecting operational technology systems—such as those governing power grids, water treatment facilities, and transportation networks. Strengthening CDM implementation would elevate the overall cyber posture of the federal enterprise and reduce vulnerabilities that adversaries could exploit.

Immigration and Border Security Gaps Highlighted
GAO also identified significant shortcomings in DHS’s immigration and border‑security data and equipment planning. It reported that U.S. Immigration and Customs Enforcement (ICE) publishes detention figures that fall short of the actual count by tens of thousands of individuals, obscuring the true scale of detained populations and hindering oversight. Consequently, GAO recommends that ICE correct its detention reporting mechanisms to ensure accuracy and transparency. Separately, the watchdog noted that U.S. Customs and Border Protection (CBP)’s rollout plans for non‑intrusive inspection (NII) equipment at the southwest border omit nine vehicle crossings that together account for nearly 40 % of passenger‑vehicle traffic in the region. GAO urges CBP to revise its equipment deployment strategy to include these high‑volume crossings, thereby enhancing the agency’s ability to detect contraband, weapons, and unauthorized individuals while maintaining the flow of legitimate trade and travel.

Current Status of GAO Recommendations at DHS
As of July 2025, DHS maintains a total of 507 open GAO recommendations, a figure that reflects both longstanding issues and newly identified concerns. Of these, 39 are classified as priority recommendations, indicating they address high‑risk areas that require urgent attention. Since GAO’s initial priority‑recommendation issuance in May 2025, DHS has successfully implemented five of them, while two were rescinded because they were no longer applicable or valid. An additional seven priority recommendations were identified in July, bringing the priority count back to 39. This dynamic underscores the ongoing nature of oversight work and the need for sustained corrective action across the department.

Implementation Rates and Open Recommendations
GAO’s broader analysis reveals that DHS has implemented 86 % of the recommendations it has received over the past five years, outperforming the government‑wide average of 77 % for recommendations made five years ago. This relatively high implementation rate suggests that DHS has established mechanisms for tracking and closing GAO findings, yet the remaining 14 %—equating to dozens of open items—still represent areas where further work is required. The persistence of open recommendations, particularly in the priority category, indicates that while progress is being made, certain systemic challenges—such as fragmented programs, guidance gaps, and data‑quality issues—remain resistant to quick fixes. Continued monitoring, adequate resourcing, and clear accountability will be essential to drive the remaining recommendations toward closure.

Broader DHS Modernization Reviews: Human Resources IT
Parallel to the priority‑area findings, GAO has examined DHS’s efforts to modernize its human‑resources (HR) information‑technology systems. In a September 2025 report, GAO concluded that the department’s investment in HR‑IT modernization has yielded limited results and lacks an approved strategy or measurable goals to gauge success. Without a clear roadmap, DHS risks squandering resources on disparate upgrades that do not interoperate or deliver the intended efficiencies in talent acquisition, workforce planning, and employee services. GAO recommends that DHS develop a comprehensive, outcome‑driven modernization plan, complete with performance metrics, to ensure that HR‑IT investments translate into tangible improvements in workforce management and operational readiness.

Acquisition Portfolio Challenges and Cost Overruns
GAO’s scrutiny of DHS’s acquisition portfolio paints a concerning picture of cost growth and schedule delays. According to a separate report, the baseline costs of major acquisition programs have increased by an estimated $11.4 billion—approximately a 26 % rise—since their initial baselines were established. These overruns are accompanied by delays affecting many of the department’s largest programs, undermining timely delivery of critical capabilities such as surveillance aircraft, border‑security technology, and emergency‑response equipment. GAO attributes the trend to insufficient early‑stage planning, evolving requirements, and weak contract oversight. To reverse this trajectory, GAO advises DHS to reinstate rigorous baseline validation, enforce stricter change‑control procedures, and enhance program‑management oversight to curb unnecessary expenditures and keep projects on schedule.

Implications of the 2026 Homeland Security Summit
The forthcoming 2026 Homeland Security Summit, scheduled for Nov. 12, 2026, will convene government officials, industry leaders, and academic experts to discuss artificial intelligence, cyber defense, and operational capabilities across major DHS agencies. The summit’s agenda aligns directly with the areas highlighted by GAO: AI‑driven analytics could help consolidate disaster‑recovery data, advanced cyber‑defense tools could address CDM adoption gaps, and innovative sensor technologies might improve non‑intrusive inspection coverage at the southwest border. By fostering collaboration and sharing best practices, the summit offers a platform for translating GAO’s recommendations into concrete initiatives, accelerating implementation, and measuring outcomes against the performance metrics GAO urges DHS to adopt.

Conclusion: Path Forward for DHS
In summary, GAO’s latest oversight work identifies three critical priority domains—disaster preparedness, cybersecurity, and immigration/border security—where DHS must act to close gaps that threaten national safety and operational effectiveness. While the department has demonstrated a respectable 86 % implementation rate for GAO recommendations, the persistence of 507 open items, including 39 priority recommendations, signals that sustained effort is needed. Addressing FEMA’s program fragmentation, strengthening CISA’s guidance for the CDM initiative, correcting ICE detention data, and expanding CBP’s NII equipment deployment are immediate steps that can yield measurable improvements. Simultaneously, DHS must remedy shortcomings in its HR‑IT modernization strategy and rein in acquisition cost overruns to ensure that future investments deliver value on time and on budget. The 2026 Homeland Security Summit provides a timely forum to advance these objectives, leveraging emerging technologies and cross‑sector partnerships to build a more resilient, secure, and efficient homeland security enterprise.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here