Fed watchdog flags gaps in security incident oversight

federal-reserve-bank
Plans to allow U.S. banks to reduce the capital they hold create uncomfortable echoes of past turmoil in credit markets. As regulators contemplate relaxing standards meant to protect the public, they should look to past financial crises.
Andrew Harrer/Bloomberg
  • Key takeaway: The Inspector General report found that gaps in coordination and unclear responsibilities among Fed divisions contributed to a sensitive information security incident that remained unresolved for more than a year.
  • Expert quote: "The lack of clarity in each division's role in responding to this incident highlights the need for a consolidated program to manage insider risks at the Board." —Federal Reserve Office of the Inspector General report.
  • What's at stake: The Fed said it plans to implement processes and protocols to clarify roles and strengthen the escalation of alerts by the first quarter of 2027.

WASHINGTON — The Federal Reserve has weaknesses in how its divisions coordinate to identify and resolve information security incidents, a government watchdog said.

Processing Content

The Fed's Office of Inspector General released a report Monday detailing an incident involving a former staffer in the Division of International Finance who potentially removed hundreds of documents containing sensitive and classified information from the board and the Federal Open Market Committee using an unencrypted USB device. The report raised concerns about how multiple Fed divisions responded to and handled the matter.

The case was examined as part of the OIG's 2025 audit of the board's controls for records management during employee offboarding. 

"During our audit, we identified concerns with the response to an information security incident involving the potential removal of sensitive Board and FOMC classified information by a former IF employee," the OIG said in its report. "The 2024 incident was not fully resolved and the removed information was not fully retrieved."

According to the report, three months before retiring, the employee triggered 279 data loss prevention, or DLP, alerts. The DLP tool identified 111 of those alerts as potentially involving sensitive FOMC classified information. The alerts occurred shortly before the employee took a "personal trip to a restricted country," the report said.

The IG report said several divisions responsible for resolving the alerts, including information security operations, the Records Management Program, the Division of International Finance and the FOMC Secretariat, may have failed to properly document and escalate the situation.

For example, the information security team believed it could do nothing beyond alerting the Records Management Program, while FOMC Secretariat personnel believed the Legal Division had been informed. It had not.

"Each group's conflicting understanding of escalation and resolution responsibilities resulted in a general lack of clarity about how to proceed in addressing the incident and contributed to overreliance on the employee's division," the OIG said. "This lack of clarity contributed to the incident remaining unresolved for over a year."

The OIG said concerns about the board's handling of the incident prompted it to issue a management alert before completing its planned audit. 

Read more:

Although the report focuses on the 2024 incident, the OIG noted that the same employee had attempted to export classified Fed documents in previous years.

In 2021, the Division of International Finance was notified that the employee had copied sensitive FOMC classified files to an unencrypted USB device. The employee said it was an accident, according to the report. Then, in 2023, the employee unsuccessfully attempted to send sensitive FOMC classified information to a personal email account.

"The employee's ongoing pattern of potential and confirmed security violations; the employee's imminent departure; and the presence of multiple insider threat risk indicators, including multiple international trips, signaled the possibility that a credible insider threat incident and potential material information security breach had occurred," the IG report said. "The lack of clarity in each division's role in responding to this incident highlights the need for a consolidated program to manage insider risks at the Board."

The government watchdog said the 2025 audit covered all employees, including interns, who departed the board between Jan. 1 and Dec. 31, 2024. During that period, departing employees submitted 18 information-removal requests, while the IS Operations team notified the Records Management Program of five potential cases involving the removal of information by departing employees. 

Going forward, the Fed's inspector general recommends strengthening incident-handling controls to prevent future information security incidents involving the unauthorized removal of sensitive information by departing employees. The Fed said it plans to implement processes and protocols to clarify roles and strengthen the escalation of alerts by the first quarter of 2027. 

The report is one of a series of reviews released by the Fed's inspector general in recent months. In July, the watchdog released a 40-page report detailing shortcomings in the central bank's efforts to prevent employees and officials from disclosing proprietary information and analysis. In June, the OIG released a report examining how the board could strengthen its processes for monitoring and mitigating risks associated with international travel. 


For reprint and licensing requests for this article, click here.
Federal Reserve Risk Market Risk Regulation and compliance
MORE FROM AMERICAN BANKER
Load More