The Consumer Financial Protection Bureau’s ability to safeguard sensitive consumer and corporate data has sharply deteriorated, according to a new audit from the Office of Inspector General (OIG). The watchdog’s annual report concluded that the CFPB’s information security program is “not effective,” marking a steep drop from last year’s rating and exposing serious weaknesses across the agency’s cybersecurity operations.
Audit finds “significant degradation” in security maturity: The audit found that the CFPB’s cybersecurity maturity fell from “managed and measurable” (level 4) to “defined” (level 2) under the Federal Information Security Modernization Act’s (FISMA) five-tier scale, well below the level considered effective by the Office of Management and Budget. Inspectors cited multiple issues, including expired system authorizations, inadequate risk documentation, and the loss of contractor support following the cancellation of key information-security task orders earlier this year.
- The report stated that “the CFPB is not maintaining its authorizations to operate for many systems and is using risk acceptance memorandums without a documented analysis of cybersecurity risks.”
- These deficiencies, compounded by contractor terminations and staff departures, have left the Bureau “unable to maintain an effective level of awareness of security vulnerabilities in its environment”.
Key areas of concern: Auditors identified three major problem areas:
- Cybersecurity risk profiles: The CFPB does not use cybersecurity profiles or enterprise-wide risk registers to identify and prioritize threats.
- System authorizations: Thirty-five systems lacked current authorizations to operate or had risk memorandums without sufficient analysis.
- Outdated software: The Bureau continues to run end-of-life applications no longer supported by vendors, increasing exposure to malicious exploits.
Despite these lapses, the audit noted modest progress, including new ransomware response procedures and enrollment of staff in continuous background-check programs.
CFPB pledges fixes: In its response, the CFPB agreed with all six of the OIG’s recommendations and said corrective actions, ranging from rebuilding risk registers to restoring continuous monitoring contracts, will be completed by late 2026. The Bureau pushed back, however, on what it called a “misleading impression” that it had a lax security posture, noting that some of the affected systems were low-risk and contained no consumer data.
- The findings come after months of turbulence for the CFPB, which has faced deep workforce and budget reductions ordered by the Trump administration and an internal reshuffling that disrupted cybersecurity oversight.
- With the agency still managing vast troves of personally identifiable and supervisory information, lawmakers and regulators are warning that the Bureau remains a prime target for cyberattacks until its defenses are rebuilt.




