EPA watchdog says agency missed critical systems in cyber inventory
An Environmental Protection Agency watchdog found that three of six information systems it reviewed met federal criteria for heightened cybersecurity protection but were not classified as high-value assets.
The EPA Office of Inspector General issued the finding on August 25, 2026, in Report No. 26-P-0049. The audit examined whether the agency maintained a complete inventory of systems whose compromise could seriously affect EPA operations, sensitive information or public trust.
The finding concerns EPA’s classification and oversight process. The report does not say that the agency suffered a breach, that any system was hacked or that data was exposed.
Three systems met the criteria
Auditors judgmentally selected six systems from an EPA inventory of 116. They determined that three met the criteria for high-value assets, or HVAs, because of the informational value of the data they contained, but were not classified that way:
- The Superfund Enterprise Management System.
- The Office of Pesticide Programs Local Area Network.
- The Toxic Substances Control Act Confidential Business Information Local Area Network.
The systems contained sensitive records tied to EPA’s core responsibilities. The Superfund system included investigation, cleanup, enforcement, Freedom of Information Act and litigation-support information. The pesticide-program network held pesticide-registration applications, trade secrets and company financial information. The Toxic Substances Control Act network contained confidential business information, scientific data and technical documents about chemical composition.
Under Office of Management and Budget Memorandum M-19-03, federal agencies must establish processes to identify and prioritize protection of high-value assets. An HVA is information or an information system so critical that its loss, corruption or inaccessibility could seriously affect an organization’s ability to perform its mission or conduct business. The designation helps guide monitoring, assessment, contingency planning and remediation.
EPA’s HVA inventory fell from 34 systems to three
The inspector general also pointed to a sharp decline in EPA’s identified HVA inventory. The agency listed 34 HVAs in 2017, but three in 2024.
The OIG did not treat its six-system review as a statistically representative audit of all 116 systems. The systems were selected because they contained different types of environmental information associated with EPA strategic-plan goals. Still, the OIG said the sample findings, combined with the decline in the inventory, suggested that EPA may have considerably more HVAs than it had identified.
Auditors attributed the misclassifications to inadequate governance policies and procedures. They also said EPA did not sufficiently consider the informational value of environmental data when deciding which systems warranted HVA status.
EPA completed the audit’s corrective actions
EPA agreed with the OIG’s findings, conclusions and recommendations. According to the audit’s corrective-action record, the agency implemented written procedures by June 30, 2026, including guidance for system owners and recordkeeping requirements for designation decisions.
EPA also reevaluated the three systems identified by the audit by June 17, 2026. The recommendation required the agency to determine whether the systems should be classified as HVAs and document the supporting rationales. The report confirms that the corrective action was completed, but it does not itself state that all three systems were ultimately designated as HVAs.
Those actions address the specific weaknesses identified by the audit, but they do not erase the underlying finding that the systems had previously been misclassified. The next accountability question is whether the revised procedures produce a complete and durable inventory beyond the three systems examined.
What the audit does not establish
The audit examined selected HVA-program controls. It did not test every cybersecurity control or every requirement in OMB Memorandum M-19-03. The OIG also noted that testing only a limited number of controls within EPA’s three existing HVAs could leave other weaknesses unexamined.
For the public, the immediate takeaway is limited but important: the report identifies a weakness in how EPA decides which systems receive heightened cybersecurity attention, not evidence that sensitive environmental, pesticide or chemical records were breached. Follow-up documentation should show the formal status of the three systems, the rationale for those decisions and whether EPA’s overall HVA count changes.
Sources
- EPA Inspector General audit, Report No. 26-P-0049
- Oversight.gov audit record
- GAO, EPA CIO open recommendations
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.