



The Government Accountability Office reviewed 18 of the Department of Defense's major IT business programs, which together carry a planned price tag of $10.3 billion through fiscal 2026. Fifteen of 17 operational programs tracked the required performance metrics; two did not, leaving their progress on customer satisfaction and innovation officially unknowable. Only six of those 17 met every performance target they did bother to set.
On fraud risk, seven of the 18 programs reported that staff were either unaware of, or untrained in, how to recognize and report signs of fraud or tampering in IT systems. DOD's response was that personnel get general fraud awareness training, just not training specific to IT fraud, which is a distinction the department seems more comfortable with than GAO is. Six programs also have no plan yet to meet DOD's own 2027 zero-trust cybersecurity deadline, and three lack an approved cybersecurity strategy at all.
GAO's response to all this was one new recommendation and a reminder of the pile of prior recommendations DOD still hasn't acted on, some dating back to 2022. The report notes DOD is 'making efforts' via revised guidance, a modernized architecture, and an AI acquisition strategy, none of which has yet closed the gaps this year's questionnaire turned up.
The full dispatch is available from the source below.