The Times Australia
The Times World News

.

Cyber security experts on giving Elon Musk and DOGE the keys to US government IT systems

  • Written by Frank den Hartog, Professor of Information Systems, Research Chair in Critical Infrastructure, University of Canberra



A few weeks ago, word started to come out that the newly minted United States Department of Government Efficiency (DOGE)[1] had acquired unprecedented access to multiple US government computer systems[2].

DOGE employees – tech billionaire Elon Musk and his affiliates – have been granted access to sensitive personal and financial data, as well as other data critical for national security[3]. This has created a national and international outcry[4], and serious concerns have been raised about data security, privacy and potential influence.

A group of 14 state attorneys-general attempted to have DOGE’s access to certain federal systems restricted, but a judge has denied[5] the request.

Questions of trust

What are the deeper reasons behind this outcry? After all, Musk is far from the first businessman to gain political power.

There is, of course, US President Donald Trump himself, alongside many more on both sides of politics. Most of them kept running their businesses at arm’s length and went back to them after a stint in Washington.

So why are so many people alarmed now, but not before? The key word here is trust. Surveys suggest many people don’t trust Musk[6] with this kind of access.

Does that mean we trusted the others? The foundation of modern cyber security is not to trust anything or anybody[7] in the first place.

So while a lack of trust in Musk is one reason for disquiet, another is a lack of trust in the current state of cyber security in US government systems and procedures. And for good reason.

An insider threat

The situation in the US raises the spectre of what cyber experts call an “insider threat”. These concern cyber security incidents caused by people who have authorised access to systems and data.

Cyber security relies on controlling the so-called “CIA triad[8]” of confidentiality, integrity and availability. Insider threats can compromise all three.

Authentication and subsequent authorisation of access has traditionally been an important measure to prevent cyber incidents from occurring. But apparently, that is not sufficient any more.

Perhaps the most famous insider incident in history is Edward Snowden’s leak of classified documents[9] from the US National Security Agency in 2013. Australia too has had its share of insider breaches – the 2000 Maroochy Shire attack[10] is still a textbook example.

Musk and his DOGE colleagues have now become insiders.

How to reduce the risk of insider threat

There are plenty of strategies organisations can follow to reduce the risk of insider threats:

  • more rigorous vetting of employees

  • giving users only the bare minimum access and privileges they need

  • continuously auditing who has access to what, and restricting access immediately when needed

  • authenticating and authorising users every time they access a different system or file (this is part of what is called a “zero trust architecture[11]”)

  • monitoring for unusual behaviour regarding insiders accessing systems and files

  • developing and nurturing a cyber-aware culture in the organisation.

In government systems, the public should be able to trust these procedures are being rigorously applied. However, when it comes to Musk and DOGE, it seems they are not. And that’s where the core of the problem lies.

Clearances and a lack of care

DOGE employees without security clearance reportedly[12] have access to classified systems which would normally be considered quite sensitive.

However, even security clearances offer no iron-clad guarantees.

Security clearances assume someone can be trusted based on their past. But past performance can never guarantee the future.

Photo of protesters, one holding a placard reading 'GET YOUR PAWS OFF OUR DATA DOGE'.
Not all Americans are happy with DOGE access to government computer systems. John G. Mabanglo/EPA[13]

In the US, obtaining and holding a security clearance has become a status symbol[14]. A clearance may also be a golden ticket to high-paying jobs and power, and hence subject to politics rather than independent judgement.

And it seems little care has been taken to keep users’ access and privileges to a minimum.

You might think DOGE’s employees, tasked with seeking out inefficiency, would only need read-only access to the US government IT systems. However, at least one of them temporarily had “write” access to the systems of the treasury, according to reports, enabling him to alter code controlling trillions in federal spending[15].

It all comes down to trust

Even if all possible access control and vetting procedures are in place and working perfectly, there will always be the problem of how to declassify information.

Or to put it another way: how do you make somebody forget everything they knew when their clearance or access is revoked or downgraded?

What Musk has seen, he can never unsee. And there is only so much that can be done to prevent this knowledge from leaking.

Even if all procedures to protect against insider threats are followed perfectly (and they aren’t), nothing is 100% secure.

We would still need a certain level of public trust that the obtained data and information would be dealt with responsibly. Has trust in Musk and his affiliates reached that level?

According to recent polling[16], public opinion is still divided.

References

  1. ^ United States Department of Government Efficiency (DOGE) (www.abc.net.au)
  2. ^ multiple US government computer systems (therecord.media)
  3. ^ national security (www.theverge.com)
  4. ^ outcry (www.politico.com)
  5. ^ denied (www.nytimes.com)
  6. ^ don’t trust Musk (today.yougov.com)
  7. ^ not to trust anything or anybody (www.cyber.gov.au)
  8. ^ CIA triad (www.techtarget.com)
  9. ^ leak of classified documents (en.wikipedia.org)
  10. ^ Maroochy Shire attack (link.springer.com)
  11. ^ zero trust architecture (www.cyber.gov.au)
  12. ^ reportedly (www.theverge.com)
  13. ^ John G. Mabanglo/EPA (photos.aap.com.au)
  14. ^ status symbol (www.pbs.org)
  15. ^ controlling trillions in federal spending (www.wired.com)
  16. ^ recent polling (www.cbsnews.com)

Read more https://theconversation.com/insider-threat-cyber-security-experts-on-giving-elon-musk-and-doge-the-keys-to-us-government-it-systems-250046

Times Magazine

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Decline of Hyper-Casual: How Mid-Core Mobile Games Took Over in 2025

In recent years, the mobile gaming landscape has undergone a significant transformation, with mid-core mobile games emerging as the dominant force in app stores by 2025. This shift is underpinned by changing user habits and evolving monetization tr...

Understanding ITIL 4 and PRINCE2 Project Management Synergy

Key Highlights ITIL 4 focuses on IT service management, emphasising continual improvement and value creation through modern digital transformation approaches. PRINCE2 project management supports systematic planning and execution of projects wit...

What AI Adoption Means for the Future of Workplace Risk Management

Image by freepik As industrial operations become more complex and fast-paced, the risks faced by workers and employers alike continue to grow. Traditional safety models—reliant on manual oversight, reactive investigations, and standardised checklist...

From Beach Bops to Alpine Anthems: Your Sonos Survival Guide for a Long Weekend Escape

Alright, fellow adventurers and relaxation enthusiasts! So, you've packed your bags, charged your devices, and mentally prepared for that glorious King's Birthday long weekend. But hold on, are you really ready? Because a true long weekend warrior kn...

Effective Commercial Pest Control Solutions for a Safer Workplace

Keeping a workplace clean, safe, and free from pests is essential for maintaining productivity, protecting employee health, and upholding a company's reputation. Pests pose health risks, can cause structural damage, and can lead to serious legal an...

The Times Features

Tricia Paoluccio designer to the stars

The Case for Nuturing Creativity in the Classroom, and in our Lives I am an actress and an artist who has had the privilege of sharing my work across many countries, touring my ...

Duke of Dural to Get Rooftop Bar as New Owners Invest in Venue Upgrade

The Duke of Dural, in Sydney’s north-west, is set for a major uplift under new ownership, following its acquisition by hospitality group Good Beer Company this week. Led by resp...

Prefab’s Second Life: Why Australia’s Backyard Boom Needs a Circular Makeover

The humble granny flat is being reimagined not just as a fix for housing shortages, but as a cornerstone of circular, factory-built architecture. But are our systems ready to s...

Melbourne’s Burglary Boom: Break-Ins Surge Nearly 25%

Victorian homeowners are being warned to act now, as rising break-ins and falling arrest rates paint a worrying picture for suburban safety. Melbourne residents are facing an ...

Exploring the Curriculum at a Modern Junior School in Melbourne

Key Highlights The curriculum at junior schools emphasises whole-person development, catering to children’s physical, emotional, and intellectual needs. It ensures early year...

Distressed by all the bad news? Here’s how to stay informed but still look after yourself

If you’re feeling like the news is particularly bad at the moment, you’re not alone. But many of us can’t look away – and don’t want to. Engaging with news can help us make ...