Dive Brief:
- The Internal Revenue Service has been slow to upgrade its cybersecurity despite external warnings of deficiencies, a lapse that may expose taxpayer data to wrongdoers, the Treasury Inspector General for Tax Administration said.
- The IRS falls short in the way it identifies possible cybersecurity risks, protects against them and detects those that have occurred, TIGTA said in a formal review entitled, “The IRS’s cybersecurity program was not effective for fiscal year 2026.”
- “The IRS needs to take further steps to improve its security program deficiencies,” TIGTA said. Without the improvements, “taxpayer data could be vulnerable to inappropriate and undetected use, modification or disclosure,” TIGTA said.
Dive Insight:
The IRS — which processed more than 165 million individual tax returns last year — pushed back against the report.
The agency manages cybersecurity well, and effectively measures its safeguards in line with federal standards under the Information Security Continuous Monitoring program, IRS Chief Information Officer Kaschit Pandya said in a letter to TIGTA.
The IRS deems its cybersecurity “maturity” level as effective, “including enterprise governance, quantitative performance measurement, automated monitoring, executive oversight and continuous improvement,” Pandya said.
Under federal guidelines, the IRS is required to report on its cybersecurity efforts across six categories — govern, identify, protect, detect, respond and recover.
TIGTA found weaknesses in the areas of identify, protect and detect.
For example, the IRS in a strategy dated March 2025 referred to roles that were eliminated as part of a reorganization and to software tools that the agency no longer uses, according to TIGTA.
“The IRS has not fully met the intent of updating the ISCM strategy and program plan,” TIGTA said.
Also, to ensure adequate safeguards, the IRS needs to demonstrate that all of its security and privacy controls are fully assessed and monitored, TIGTA said. Yet the agency has not completed an assessment of two-thirds of its controls, according to TIGTA.
The IRS in recent years has had to adjust to deep budget and staff cuts, including a $20 billion clawback in funding and a total payroll reduction that exceeded 27,600 by the end of last year, according to the Yale Budget Lab.
Trump ‘“administration officials have indicated a goal of reducing the IRS to roughly 50,000 employees, a reduction of approximately 50% that would return the agency to a staffing level not seen since the 1960s, when total IRS employment ranged from 47,000 to 52,000,” the Yale Budget Lab said.