FHFA Cybersecurity Audit Finds Program Not Effective
The Federal Housing Finance Agency’s information-security programs and practices were not effective under federal cybersecurity maturity standards, according to an inspector-general audit issued Thursday, July 30, 2026.
The audit, report AUD-2026-004, gave FHFA an overall rating of Level 2, Defined. Under the federal inspector-general FISMA metrics used for the review, an agency’s information-security program is considered effective at Level 4, Managed and Measurable or higher.
The finding does not allege that FHFA was hacked or that borrower data was stolen. It identifies control weaknesses involving overdue security assessments and privileged accounts that remained enabled after periods of inactivity.
The report also draws an important distinction: auditors concluded that FHFA complied with FISMA-related policies, procedures, standards and guidelines, but that the agency’s overall information-security programs and practices were not effective.
Three sampled systems lacked current assessments
The review covered FHFA and the FHFA Office of Inspector General’s information-security programs from April 1, 2025, through March 31, 2026. Sikich CPA LLC conducted fieldwork remotely and at FHFA’s Washington headquarters from October 2025 through June 2026 under contract with FHFA-OIG.
Auditors tested selected controls and systems rather than every FHFA system. Three of the four systems selected for testing did not have current annual security-control assessments and documented assessment reports:
- FHFA’s General Support System, whose last control assessment report was dated Aug. 27, 2024;
- a cloud-based Security Information and Event Management application, last assessed March 20, 2025; and
- the Suspended Counterparty System, last assessed Feb. 24, 2025.
FHFA also had not created Plans of Action and Milestones to track the overdue assessments and related remediation. Auditors said that gap could limit the agency’s ability to identify, track and correct control deficiencies in a timely manner.
Privileged accounts remained active
The audit found a separate access-control weakness in a cloud-based workflow system. Five of 12 enabled privileged accounts—about 42 percent of the accounts reviewed—were not disabled after 35 days of inactivity or had no recorded application login.
Two accounts remained enabled between 37 and 51 days after their last application login. Three accounts had no recorded login activity and were later disabled after between 73 and 538 days of inactivity within the cloud system.
The system’s annual user re-authorization review also reauthorized all five accounts in August 2025 without identifying their inactivity or determining whether the users still needed privileged access.
Because privileged accounts have elevated permissions, auditors said inactive or unused accounts could remain enabled longer than intended, weakening least-privilege controls and increasing the risk of unauthorized or unintentional disclosure of sensitive information in the system’s workflows and modules.
Management disagreed with four recommendations
FHFA management disagreed with all four new recommendations. In its response, management pointed to authority-to-operate extensions, continuous monitoring, enterprise directory services and single sign-on.
Auditors maintained the recommendations. They said authority-to-operate extensions did not replace the need for documented annual assessments and remediation tracking. They also said single sign-on did not prevent FHFA from identifying and disabling privileged accounts after 35 days of application-level inactivity, including accounts that had never logged in.
The four recommendations call for FHFA to:
- conduct and document annual security-control assessments;
- create Plans of Action and Milestones to track overdue assessments and remediation;
- update cloud-system privileged-account controls to identify and disable inactive accounts after 35 days based on application-level activity; and
- improve the annual privileged-user re-authorization review by checking last-login activity, continued need for access and appropriate privilege levels.
FHFA-OIG reviewed Sikich’s work and reported no material noncompliance with generally accepted government auditing standards.
Why the finding matters
The audit rated two of the six cybersecurity functions at Level 3, Consistently Implemented, and four at Level 2, Defined. None reached Level 4, Managed and Measurable, the effectiveness threshold. The overall program therefore received a Level 2, Defined rating.
The report identified two new weaknesses mapped across four cybersecurity functions and four IG FISMA metric domains. It also noted five open recommendations from prior audits; those were not new findings from this review.
FHFA is responsible for the supervision, regulation and mission oversight of Fannie Mae, Freddie Mac and Common Securitization Solutions, which operates the Common Securitization Platform. The agency also regulates the 11-bank Federal Home Loan Bank System and serves as conservator for Fannie Mae and Freddie Mac.
That role places FHFA at the center of the U.S. mortgage-finance system. The audit does not show that mortgage borrowers were directly affected, but it raises an accountability question about whether the regulator’s own systems have sufficiently documented testing and access controls.
What happens next
The next accountability question is whether FHFA accepts and completes the four corrective actions, including documented annual testing, remediation tracking and stronger access reviews.
Readers should watch for FHFA-OIG follow-up reports or management updates showing whether the recommendations are addressed and independently verified. The report does not establish a final resolution or a deadline for completion.
Sources
- FHFA Office of Inspector General audit report, AUD-2026-004
- FHFA FY 2024 Performance and Accountability Report
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.