Report 25-11

Undetected Vulnerabilities from Personally Owned Devices

OIG is issuing this management advisory to bring to SBA’s attention possible security threats from personally owned devices accessing the agency’s information technology network from national and international locations with only a username and password.

About this document and download

The Office of Inspector General is issuing this management advisory to bring to the U.S. Small Business Administration’s (SBA) attention possible security threats from personally owned devices accessing the agency’s information technology network from national and international locations with only a username and password.

We identified in our fiscal years 2023 and 2024 Federal Information Security Modernization Act assessments that SBA did not have multifactor authentication enabled for users to access the agency’s secure network. Relying on usernames and passwords alone greatly increases the risk of SBA data being accessed and exploited by cyber criminals and other bad actors. We also determined personally owned devices could access the SBA network from foreign locations, which is prohibited by SBA information technology policy.

We made five recommendations, and SBA management agreed with all five. All of the recommendations have been closed or resolved.

Download .pdf
File size: 630KB
Effective: April 22, 2025
Owned by: Office of Inspector General
Related Programs: Related programs: Agency Management
Last updated April 22, 2025