Security ratings firm BitSight recently released a report citing a gap in cybersecurity performance between the U.S. Government and contractors. 

The report was the result of a comparative security assessment between 1,212 randomly selected government contractors and 122 federal agencies. The assessment found that federal agencies were at least 15 points better than the mean for government contractor security ratings, albeit on a broad scale of 250 to 900.

The study found that almost half of all contractors were graded “below C” for Protective Technology countermeasures recommended by the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework. The overall highest scoring industries were aerospace and defense, business services, and health care; while the technology, engineering, and manufacturing sectors were the lowest. Specific to data breaches, the health care industry fared the worst among all sectors with 8 percent reporting a breach since 2016. This was closely followed by the aerospace and defense industry with 5.6 percent reporting a breach.

The report attributed low cybersecurity scores in part to deficient network encryption, lack of email protection, and outdated internet browsers.  

Of potential interest to contractors, the report also made recommendations to federal agencies regarding cybersecurity gaps existing in industry. BitSight encouraged agencies to conduct cybersecurity audits of potential contractors, as well as requiring prime contractors to more strictly monitor subcontractors’ adherence to cybersecurity requirements beyond mere “flow down” requirements of current contract clauses. Lastly, BitSight cautioned government to closely monitor risks posed by technology services and cloud computing services. 

These findings may further sharpen the U.S. Government’s focus on enhancing cybersecurity among its supply chain, and highlight the importance of assessing cybersecurity risk within contractors’ business operations.