# DoD Strengthens Cybersecurity Procurement Practices

Federal agencies, notably the Department of Defense (DoD), are confronting persistent challenges in safeguarding personally identifiable information (PII), highlighted by historical breaches such as the 2015 Office of Personnel Management (OPM) incident and recent exposures. These issues stem from outdated processes, insufficient encryption measures, and concerns over vendor selections for cybersecurity monitoring services. Budget constraints and workforce reductions have further impacted cybersecurity effectiveness. This situation underscores an urgent need for enhanced cybersecurity procurement strategies, including rigorous vendor vetting and stronger enforcement of PII protection policies to mitigate risks and rebuild trust.

- Agencies like DoD and CISA are prioritizing improvements in cybersecurity procurement to address systemic vulnerabilities affecting PII protection.
- Procurement professionals should anticipate stricter requirements for cybersecurity vendors, emphasizing advanced encryption and compliance capabilities.
- Budget and staffing challenges highlight the importance of selecting vendors who can deliver efficient, scalable cybersecurity solutions.
- Contractors specializing in cybersecurity monitoring and PII protection may find increased opportunities as agencies seek to strengthen defenses and update legacy systems.

**Jurisdictions:** federal
**Industries:** Defense & Military
**Topics:** Cybersecurity
**Published:** September 26, 2026

### Government Entities
- Department of Defense (DoD)
- Cybersecurity and Infrastructure Security Agency (CISA)
- Office of Personnel Management (OPM)

### Vendors
- Unnamed cybersecurity monitoring company (awardee)

### Key Quotes
> My - and my spousePII data has been breached in Fed and DoD incidents so many times that itis no longer rational or defensible to call it private anymore. DoD investigates spouses and cohabitants without their consent, violating PII policies.
> — Commenter

> About two years ago the head of security for our command emailed me a 20+ year old form for me and my employees to fill out. It had about every piece of PII imaginable. After months of pushback, the form was finally updated to remove unnecessary PII.
> — Original poster

### Sources
- [The incompetence is mind blowing](https://www.reddit.com/r/FedEmployees/comments/1wqvj39/the_incompetence_is_mind_blowing) - reddit-fedemployees