IT Systems Annual Assessment: DOD Should Improve IT Fraud Risk Management Practices

This GAO assessment identifies critical gaps across DOD major IT business programs in fraud risk awareness, software development metrics, and cybersecurity/zero trust planning. DOD planned $10.3 billion for 18 major IT programs for FY 2024–FY 2026.…

Cabrillo Club

Cabrillo Club

Editorial Team · September 28, 2026 · 6 min read

Share:LinkedInX

Cabrillo Club Insights

IT Systems Annual Assessment: DOD Should Improve IT Fraud Risk Management Practices

Executive Summary

This GAO-flagged assessment identifies critical gaps across Department of Defense (DOD) major IT business programs in fraud risk awareness, software development metrics, cybersecurity strategy and zero trust planning. The Summary shows DOD planned to spend $10.3 billion on 18 major IT business programs for FY 2024–FY 2026, and GAO found uneven implementation of fraud risk practices (11 of 18 reporting training awareness; 10 of 18 assessing fraud risk), mixed adoption of Agile development (10 of 18 using Agile) with shortcomings in required metrics, and gaps in zero trust and cybersecurity strategy implementation (15 of 18 had an approved cybersecurity strategy; 12 of 18 reported implementing zero trust; a 2027 zero trust deadline is noted). Given the GAO findings and the scale of planned spending, contractors in the named segments should prioritize rapid assessment and alignment of offerings to help DOD close these gaps.

Contractors should pay attention now because the report highlights specific operational weaknesses that create near-term demand for services: fraud risk management and targeted IT security training, zero trust implementation planning ahead of the 2027 deadline, Agile/DevSecOps tooling plus metrics and analytics, and cybersecurity strategy and compliance support. The Tags list relevant NAICS codes, contract vehicles, agencies, and compliance surfaces that indicate where opportunities and procurement channels may concentrate. Promptly positioning capabilities against these needs can capture demand from programs remediating the GAO-identified issues.

Impact Matrix

Cybersecurity

  • Risk Level: High
  • Opportunity: Support for developing or maturing program cybersecurity strategies and implementing security frameworks consistent with the identified gaps. Specific NAICS codes: 541512, 541513, 541519, 541330, 541511, 518210, 541690, 611430. Contract vehicles: SEWP, OASIS+, ITES-SW2, CHESS. Agencies: DOD, GSA (General Services Administration). Specific opportunities TBD pending solicitation language.
  • Timeline: Programs reported planned spending for FY 2024–FY 2026; DOD zero trust deadline of 2027 is relevant for cybersecurity work.
  • Action Required: Offer assessments of existing cybersecurity strategies, gap analyses against DOD guidance and listed compliance surfaces, prioritized remediation roadmaps, and support for implementing zero trust elements.
  • Competitive Edge: Package compliance-focused cybersecurity strategy services that map to the listed compliance surfaces (CMMC (Cybersecurity Maturity Model Certification), NIST 800-171 (NIST Special Publication 800-171), Zero Trust Architecture, FedRAMP (Federal Risk and Authorization Management Program), FISMA, NIST CSF, DoD (Department of Defense) Instruction 8500.01) and combine them with rapid zero trust planning modules aligned to DOD 2027 expectations.

IT Services

  • Risk Level: Medium
  • Opportunity: Delivery of managed services, engineering, and program support to address shortfalls in program execution and metrics tracking. NAICS codes and contract vehicles listed above apply. Specific opportunities TBD pending solicitation language.
  • Timeline: FY 2024–FY 2026 planned spending window; other timelines TBD pending source review.
  • Action Required: Prepare staff and service offerings to support program-level assessments, metrics collection, system modernization efforts, and cybersecurity integration.
  • Competitive Edge: Emphasize integrated service packages that tie IT operations to performance metrics and cybersecurity posture, lowering program-level risk for prime contractors.

Defense

  • Risk Level: High
  • Opportunity: Programs within the DOD enterprise are explicitly affected; services that reduce fraud, improve cybersecurity, and demonstrate measurable performance will be in demand. Agencies: DOD, GSA. Specific opportunities TBD pending solicitation language.
  • Timeline: FY 2024–FY 2026 spending; zero trust implementation target 2027.
  • Action Required: Align offerings to DOD program needs described in the GAO findings — particularly fraud risk assessments, cybersecurity strategy support, and Agile development metrics.
  • Competitive Edge: Demonstrate prior DOD program experience and an approach that reduces GAO-identified exposure (fraud awareness, metrics, and zero trust planning).

Software Development

  • Risk Level: High
  • Opportunity: Help programs adopt disciplined Agile/iterative practices that include required metrics and management tools. NAICS and vehicles from Tags are relevant. Specific opportunities TBD pending solicitation language.
  • Timeline: FY 2024–FY 2026 spending; ongoing program execution timelines per DOD programs.
  • Action Required: Propose Agile delivery models with embedded performance and customer-satisfaction metrics and QA practices to address GAO findings that eight of 10 Agile-reporting programs lacked required metrics/tools.
  • Competitive Edge: Offer integrated development + metrics-as-a-service that ties Agile sprints to measurable program KPIs and GAO-friendly reporting.

Agile Development

  • Risk Level: Medium–High
  • Opportunity: Provide Agile transformation, training, toolchains, and governance to ensure Agile adopters meet required metrics and reporting expectations. Specific opportunities TBD pending solicitation language.
  • Timeline: FY 2024–FY 2026 spending window; program-specific schedules TBD.
  • Action Required: Supply Agile coaching, tool integrations for metrics, and governance frameworks that align iterative development outputs to customer satisfaction and financial performance measures.
  • Competitive Edge: Deliver demonstrable artifact pipelines that produce the required reporting and KPI evidence GAO reviewers expect.

Artificial Intelligence

  • Risk Level: Medium
  • Opportunity: Support secure use of AI for system protection and operations; help programs that use AI to align with cybersecurity strategies (the Summary notes five programs reported using AI tools to secure systems). NAICS/vehicles listed in Tags apply. Specific opportunities TBD pending solicitation language.
  • Timeline: FY 2024–FY 2026 spending; other timelines TBD pending source review.
  • Action Required: Position AI offerings with integrated risk assessment, explainability, and cybersecurity alignment; ensure AI-driven tools fit within program cybersecurity strategies.
  • Competitive Edge: Combine AI capabilities with governance and security controls that map to the compliance surfaces listed in Tags to reduce adoption friction.

Fraud Risk Management

  • Risk Level: Critical
  • Opportunity: High demand for training, program-level fraud risk assessments, and controls for software development and cybersecurity-related fraud (GAO found 7 of 18 programs reported staff unaware of or without training to recognize/report IT fraud; only 10 of 18 assessed fraud risks).
  • Timeline: FY 2024–FY 2026 spending window for affected programs; remedial actions are immediate given GAO critique.
  • Action Required: Offer targeted fraud risk assessments for IT systems, tailored training for program staff, and integration of fraud detection into development and security lifecycles.
  • Competitive Edge: Deliver domain-specific fraud training and tooling for software supply chain and DevSecOps contexts that can be rapidly applied to the 18 major IT programs cited.

IT Security Training

  • Risk Level: High
  • Opportunity: Rapidly deployable training programs focused on recognizing and reporting IT-system fraud and tampering; GAO notes DOD currently provides general fraud awareness but lacks required targeted training in some programs.
  • Timeline: Immediate need; FY 2024–FY 2026 program window.
  • Action Required: Develop and offer role-based, hands-on training for program staff and developers focused on fraud indicators, secure development practices, and reporting protocols.
  • Competitive Edge: Offer modular, measurable training with post-training assessments and integration into program performance metrics to document improved awareness.

Performance Metrics and Analytics

  • Risk Level: High
  • Opportunity: Provide metrics design, analytics, dashboards, and reporting services to help programs meet GSA-required minimum metrics across customer satisfaction, strategic/business results, financial performance, and innovation (GAO found two programs lacked the minimum; many Agile adopters lacked required measurement tools).
  • Timeline: FY 2024–FY 2026 program spending window.
  • Action Required: Help programs define, collect, validate, and report the minimum required performance metrics; implement automated dashboards and audit-ready reporting aligned to GAO expectations.
  • Competitive Edge: Offer turnkey KPI frameworks that map program activities to the four GSA-required metric categories and produce evidence suitable for GAO review.

Zero Trust Implementation

  • Risk Level: High
  • Opportunity: Support planning and implementation of zero trust architecture — GAO noted six of 18 programs had not developed plans to implement zero trust by DOD’s 2027 deadline.
  • Timeline: DOD zero trust deadline of 2027; program spending FY 2024–FY 2026 context.
  • Action Required: Provide zero trust maturity assessments, phased implementation roadmaps, and technical integration services that align with DOD zero trust expectations.
  • Competitive Edge: Deliver a modular zero trust migration playbook that prioritizes high-value controls and produces demonstrable milestones aligned to a 2027 compliance timeline.

Business Systems

  • Risk Level: Medium
  • Opportunity: Modernization and investment management support as DOD revises business systems investment guidance and continues modernization efforts (GAO references ongoing DOD efforts).
  • Timeline: FY 2024–FY 2026 planned spending; further timelines TBD pending source review.
  • Action Required: Offer business systems modernization services that embed performance metrics, cybersecurity controls, and fraud risk management.
  • Competitive Edge: Position integrated offers that connect business system modernization with measurable performance outcomes and cybersecurity compliance.

Cross-Segment Implications

  • Fraud risk management and IT security training have direct cascading effects into software development, Agile adoption, and AI use: programs that lack staff awareness and targeted training are more likely to introduce vulnerabilities during development and to misuse or inadequately secure AI tools.
  • Zero trust implementation is tightly coupled to overall cybersecurity posture; gaps here increase exposure across Defense, IT Services, and Business Systems segments and will drive demand for cross-disciplinary services (architecture, identity, network segmentation, and continuous monitoring).
  • Performance metrics and analytics act as an enabling layer: poor metrics reduce program visibility into customer satisfaction and financial performance and hinder GAO remediation. Conversely, better metrics will support cybersecurity and fraud-reduction efforts by providing measurable outcomes.
  • Contractors that can combine capabilities across cybersecurity, zero trust, Agile-aligned development with embedded metrics, and targeted fraud training will be better positioned to capture opportunities created by DOD efforts to address GAO-identified weaknesses.

Stop missing federal opportunities

Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.

Start Free Trial

or see Intelligence Dashboard →

Cabrillo Club

Cabrillo Club

Editorial Team

Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.