The Internal Revenue Service's cybersecurity program was found to be "not effective" for fiscal year 2026, according to a warning from the agency's watchdog, potentially leaving taxpayer data vulnerable to unauthorized access and modification, as reported by Fedscoop.The Treasury Inspector General for Tax Administration (TIGTA) assessed the IRS's information security program against the Federal Information Security Modernization Act (FISMA) framework. While the IRS met standards in governance, response, and recovery, it fell short in identifying, protecting, and detecting threats. This deficiency means taxpayer data could be at risk of inappropriate use, modification, or disclosure. Although the IRS has made some improvements since fiscal year 2025, including better system identification and risk management tools, critical issues remain.For instance, the agency has not fully implemented corrective actions for outstanding plans, lacks an inventory of critical software, and has failed to remediate critical vulnerabilities within the required 30-day timeframe. On the detection front, updates to security procedures and a recent reorganization have hindered the development of an agencywide Information Security Continuous Monitoring strategy. The IRS stated it is implementing new tools and remains committed to strengthening its cybersecurity, but TIGTA's findings highlight ongoing risks, following previous reports on data platform access controls and security issues with other IRS initiatives.Source: Fedscoop