YOUR AD HERE — REACH DISCERNING READERS OF SERIOUS JOURNALISM
Rates upon inquiry. Clowns extra.
FACT CHECK✒ EDITORIALABSURDITY:
Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices
Filed 2h ago · Via GAO · The Buffoon Desk
THIS STORY IS SCORED
Marty Gots a Plan
Kevin MacLeod · incompetech.com · CC BY 4.0
Photo: Wolfmann · CC BY-SA 4.0 · via Wikimedia Commons
OMB required civilian agencies to inventory their networked IoT and operational technology devices by September 2024, but as of September 2026 only 15 of 22 agencies had built an inventory, 11 were maintaining one, and just 7 had fully met all three requirements, GAO found. Not a single agency has reported an IoT cybersecurity waiver.
Agencies blamed technical and resource constraints, but GAO notes OMB itself hasn't issued updated guidance covering fiscal year 2026, leaving agencies without a clear deadline or direction. The stakes are not abstract: GAO cites a July 2026 incident where cyber actors disrupted water sector operations by changing passwords on networked industrial controllers.
GAO recommends OMB issue updated guidance and actually oversee implementation; OMB did not comment on the report.
The full dispatch is available from the source below.
✒ FROM THE EDITORIAL DESK
An agency that cannot count its own internet-connected thermostats and door locks is not a small filing error, it is a bar left unlocked in a building everyone agreed needed a lock. Two years past the deadline and only seven of twenty-two agencies did the whole assignment, which is the kind of grade that gets sent home to a parent. The water sector hack cited in this same report is what happens while the inventory spreadsheet sits half filled out.