$10.3 billion sat behind uneven controls
GAO surveyed 18 major Defense Department IT business programs with $10.3 billion in planned fiscal 2024–26 spending. Seven programs said staff were unaware of or had not received training during the prior two years to recognize and report fraud or tampering in IT systems; only 10 said they had assessed program-specific fraud risks.
DOD responded that general fraud-awareness training is mandatory, but it does not require training specific to fraud in IT systems. GAO said the narrower gap can leave software and cybersecurity work vulnerable.
| Practice | Programs reporting it | Gap |
|---|---|---|
| Fraud-training awareness | 11 of 18 | 7 |
| Fraud-risk assessment | 10 of 18 | 8 |
| Zero-trust implementation | 12 of 18 | 6 |
| Approved cybersecurity strategy | 15 of 18 | 3 |
Performance data were incomplete, too
Seventeen programs were operational. Six met all performance targets, 10 met more than one but not all, and one met none. Two operational programs did not identify the minimum required metrics across customer satisfaction, business results, financial performance and innovation.
The four largest programs accounted for half the planned spending. GAO’s summary does not identify those four in the web text, so this analysis does not attribute a particular gap to a named system.
DOD partially agreed with the new recommendation
GAO recommended that the CIO work with the comptroller to build program-level antifraud training and awareness. DOD partially agreed and pointed to the comptroller’s fraud role; GAO maintained that IT leadership must coordinate training for major systems. Six older annual-review recommendations also remained unimplemented.
A missing plan or training response is a control weakness, not proof that fraud or a breach occurred. No such incident count is established by this review.
Method and limitation
The newsroom converted GAO’s reported practices into gap counts, preserved the 18-program denominator and separated operational performance from security controls. GAO based the control data on program questionnaires as of April 2026 and followed up where documentation was missing.
Self-reported awareness does not test employee skill or control effectiveness. Program identities and individual risk ratings are needed for a system-by-system accountability judgment.
