A recent audit report has sharply criticised NASA’s cybersecurity risk management, describing it as “half-baked” and insufficient to counter today’s sophisticated threats. Released by the Office of Inspector General (OIG), the report highlights serious deficiencies in how NASA identifies, assesses, and responds to cyber risks across its complex digital infrastructure.
Key issues include inconsistent application of cybersecurity protocols, weak oversight, delayed implementation of controls, and a lack of real-time visibility into network vulnerabilities. The audit found that multiple NASA centres failed to meet federal standards for risk-based decision-making, leaving critical systems—including those linked to spacecraft and mission operations—exposed.
Despite having a cybersecurity framework in place, the report notes that NASA’s approach is reactive rather than proactive, with fragmented accountability and outdated tools.
The findings have prompted calls for urgent reforms, including better governance, enhanced threat intelligence, and centralised risk management. In an era of increasing cyber threats to national assets, the report underscores the need for cybersecurity to be a strategic, agency-wide priority.