Talk to an Expert
Blog · December 3, 2018

State Department Shamed for Poor Adoption of Multi-Factor Authentication

Senators demand answers after government report finds that only 11 percent of the Department of State’s devices use multi-factor authentication.

Five US senators have sent a letter to Secretary of State Mike Pompeo requesting answers why the State Department has not widely deployed basic cyber-security protections, such as multi-factor authentication (MFA).

The letter was sent yesterday and was signed by senators Ron Wyden [D-Ore], Cory Gardner [R-Colo], Ed Markey [D-Mass], Rand Paul [R-Ky], and Jeanne Shaheen [D-N.H.].

The five senators cite two recent governmental reports in their letter, reports that pinpoint serious issues with the State Department implementing cyber-security best practices.

The first of these is a 2018 General Service Administration (GSA) assessment of the Department of State’s cyber-security practices.

The GSA said that only 11 percent of high-value devices deployed by the Department of State had multi-factor authentication enabled, meaning they were protected only by passwords, lacking a multi-layer authentication system that involved SMS tokens, security keys, biometrics, or other second factors.

The first of these is a 2018 General Service Administration (GSA) assessment of the Department of State’s cyber-security practices.

The GSA said that only 11 percent of high-value devices deployed by the Department of State had multi-factor authentication enabled, meaning they were protected only by passwords, lacking a multi-layer authentication system that involved SMS tokens, security keys, biometrics, or other second factors.

“We are sure you will agree on the need to protect American diplomacy from cyber attacks, which is why we have such a hard time understanding why the Department of State has not followed the lead of many other agencies and complied with federal law requiring agency use of MFA,” the five senators wrote in the joint letter.

Further, the senators also cited a report by the Department of State’s Inspector General (IG), which found last year that 33 percent of US diplomatic missions failed to conduct even the most basic cyber threat management practices, like regular cyber-security reviews and audits.

The bipartisan group is now looking for answers from the State Secretary Pompeo, and gave his office until October 12 to answer three questions:

What actions has the Department of State taken in response to the designation of the Department of State’s cyber readiness as “high risk”?
What actions has the Department of State taken to rectify the near total absence of multifactor authentication systems for accounts with elevated privileges accessing the agency’s network, as required by federal law?
Please provide us with statistics, for each of the past three years, detailing the number of cyber attacks against Department of State systems located abroad. Please include statistics about both successful and attempted attacks.

CREDIT: Catalin Cimpanu, Zero Day, ZDNET

See the enclave in action.

The Compliant Computing Enclave keeps CUI inside one boundary, with your endpoints out of scope and the evidence trail already built.

Talk to an Expert
Keep reading

More from the blog

September 3, 2026

Week 6: Too Embedded to Reject

How GCC High vendor lock-in changes the decision Last week, we examined the assessor problem. This...

Read it →

August 26, 2026

Week 5: FedRAMP’s Assessor Problem

Why FedRAMP assessor independence matters Last week, we examined the larger architecture problem. This week, we...

Read it →

August 20, 2026

Week 4: The Problem Did Not Stop with Encryption

Why GCC High security architecture matters Last week, we focused on the encryption question. This week,...

Read it →