The U.S. Government Accountability Office said in a report published September 28, 2026 that several of the Defense Department's 18 major IT business programs have not assessed fraud risks, trained staff to spot fraud in IT systems, or put approved cybersecurity strategies and zero trust plans in place. The watchdog issued one new recommendation and repeated six earlier ones that remain unimplemented.
What GAO reviewed
GAO said the Defense Department relies heavily on IT to support business functions including health care, human capital, financial management, logistics and contracting. According to DOD's Office of the Chief Information Officer, the department planned to spend $10.3 billion on the 18 major IT business programs from fiscal years 2024 through 2026, with the four largest programs accounting for 50 percent of that planned spending.
The review is the seventh in a series required by a provision in the National Defense Authorization Act for fiscal year 2019, as amended, which directs GAO to assess selected DOD IT programs annually through March 2029. GAO selected the 18 programs listed as DOD's major IT investments in its fiscal 2026 submission to the Federal IT Dashboard and administered a questionnaire to the program offices.
Fraud risk gaps
Of the 18 programs, seven reported through GAO's questionnaire that program staff were either unaware of or did not receive training to recognize and report signs of fraud or tampering in IT systems. Eleven of 18 reported receiving training or knowing about available training over the past two years, and 10 of 18 reported assessing fraud risks facing the program, based on GAO's analysis of responses as of April 2026.
DOD officials told GAO the department does not currently require training to recognize and report signs of fraud in IT systems, and that personnel instead receive mandatory, general fraud awareness training. GAO said the reported lack of awareness can increase the risk of software development- and cybersecurity-related fraud within IT programs, making them vulnerable to exploitation.
Cybersecurity and software development findings
GAO reported that 15 of 18 programs had a DOD approved cybersecurity strategy and 12 of 18 were implementing zero trust architecture as part of their security framework. Six programs had not developed plans to implement zero trust in their cybersecurity frameworks by DOD's 2027 deadline, and three programs did not have an approved cybersecurity strategy, while five programs reported using artificial intelligence tools to secure their systems.
Ten of the 18 programs reported actively developing software using recommended Agile and iterative approaches, but eight of those 10 did not report or demonstrate using required metrics and management tools for tracking customer satisfaction and software development progress, an issue GAO said it had previously flagged.
Performance measures and DOD's response
Of the 18 programs, 17 were operational, and 15 of those identified the minimum number of performance metrics required by the General Services Administration across customer satisfaction, strategic and business results, financial performance, and innovation. The other two did not, leaving their progress on those measures unknown, GAO said. Among the 17 programs that identified metrics, six met all performance targets, 10 met more than one but not all, and one met no targets.
GAO's new recommendation calls on the Secretary of Defense to direct the CIO, working with the Office of the Under Secretary of Defense (Comptroller), to ensure major IT business programs promote and sustain an anti-fraud tone through training on fraud risk awareness and fraud risk assessment activities. DOD partially agreed and described actions under way; GAO said that while DOD identified the Comptroller as the dedicated entity overseeing fraud risk management, the OCIO must coordinate with that office so staff of major IT business systems receive fraud risk training.
GAO also noted DOD efforts driven by legislative and policy changes, including revising business systems investment management guidance, modernizing its business enterprise architecture, adopting a zero trust cybersecurity strategy, developing AI acquisition guidance, updating its strategic plan and implementing cost efficiency initiatives.
What to do
- Defense IT program offices should provide training focused on recognizing fraud risks in IT systems and on fraud risk assessment activities, as GAO recommends, rather than relying only on general fraud awareness training.
- Programs without an approved DOD cybersecurity strategy should develop one, per GAO's earlier recommendation.
- Programs should develop plans to implement zero trust architecture ahead of DOD's 2027 deadline.
- Operational programs should identify and track at least five performance metrics across customer satisfaction, strategic and business results, financial performance, and innovation, as required by the General Services Administration.
- Agile programs should report and demonstrate the required metrics and management tools for tracking customer satisfaction and software development progress.
Key facts and where they come from
- DOD planned to spend $10.3 billion on 18 major IT business programs from FY 2024 through FY 2026.
the department planned to spend $10.3 billion on the 18 major IT business programs from fiscal years (FY) 2024 through 2026
- Seven of 18 programs reported staff were unaware of or did not receive training to spot fraud in IT systems.
seven programs reported via GAO's questionnaire that program staff were either unaware of or did not receive training to recognize and report signs of fraud or tampering in IT systems
- Six programs lacked plans to implement zero trust by DOD's 2027 deadline.
six of the 18 programs had not developed plans to implement zero trust in their cybersecurity frameworks by DOD's 2027 deadline
- Three programs had no approved cybersecurity strategy; five reported using AI tools to secure systems.
while five programs reported using artificial intelligence (AI) tools to secure their systems, three programs did not have an approved cybersecurity strategy
- Ten of 18 programs reported assessing fraud risks facing the program.
Assessing fraud risks facing the program
10 of 18
- GAO reiterated six prior unimplemented recommendations and made one new one.
GAO reiterates that DOD should address the six recommendations previously made that have not yet been implemented from prior annual assessment reviews.
- DOD partially agreed with the new recommendation.
DOD partially agreed with GAO's recommendation and described actions it was taking to address the recommendation.
