The Postal Regulatory Commission exists to keep an eye on the U.S. Postal Service. It reviews rate cases, audits service performance, and generally plays the part of the adult in a building full of trucks that don’t show up. So there is a certain poetry in the fact that, for the third consecutive year, the federal government’s own auditors have looked at the Commission’s cybersecurity and concluded, gently but repeatedly, that nobody is minding the store.
The latest FISMA compliance audit, performed by KPMG under contract to the USPS Office of Inspector General, rates the PRC’s information security program as “Defined,” which is a polite way of saying Level 2 out of 5, which is a polite way of saying “Not Effective.” This is not a scandal in the sense of missing money or a whistleblower with a grudge. It is something more diagnostic of how the federal government actually runs, a quiet, well documented, thoroughly bureaucratic failure to do the basics, year after year, at an agency too small to notice and too obscure for anyone else to either.
Groundhog Day in Arlington
Start with the scorecard. In FY2024, the PRC scored Ad-hoc, the bottom rung, across all five cybersecurity functions then in use. In FY2025, it climbed to Defined, still “Not Effective,” but at least off the floor. This year, the agency improved further in three of six functions (Protect, Detect, and Recover all reached “Consistently Implemented”), while a newly added function called Govern, covering leadership and accountability for the whole program, opened at Ad-hoc, dead last, on its very first outing.
That last detail is the one worth sitting with. The PRC has now had three straight audits, and the one category that measures whether the agency’s leadership has actually organized itself to manage cybersecurity risk is doing worse than areas the agency has had years longer to fix. Progress is real. It is also lopsided in a way that suggests the operational fixes are outrunning the institutional ones, which is what happens when an agency patches whatever the last audit complained about without building a structure to catch the next problem before an auditor finds it.
There is also a quieter trick in the recommendation tracking. KPMG’s own appendix shows several findings “closed” in one year only to be “reissued” the next under a new recommendation number covering essentially the same gap. The FY2025 finding on cyber governance policy, for instance, gets closed in FY2026 and immediately reborn as a new recommendation about “cybersecurity current and target profiles,” a rename more than a resolution. Closure, in this accounting, means the paperwork changed forms, not that the underlying problem went away.
The Chair Nobody Sat In
If there is a single character in this story, it is the Chief Information Security Officer position, or rather its absence. The PRC’s first CISO departed in April 2024. The role sat vacant through the entirety of FY2025, run in the interim by the Chief Information Officer wearing a second hat, until a replacement finally started in August 2025, nearly a year and a half later. For a stretch in mid-2024, the Commission’s entire cybersecurity function, for an agency that hosts a public facing system processing regulatory filings, cost data, and PII, was staffed by one person.
PRC management’s own explanation, offered without much embellishment across three consecutive audits, is that it is “a small agency with limited resources.” That is true as far as it goes. It also happens to be the same sentence, more or less, that management gave auditors in 2024 and again in 2025. A justification repeated for three years starts to function less like an explanation and more like a policy.
Whose Money Is It, Anyway
Here the story gets structurally interesting rather than merely sad, because the PRC does not control its own budget. By statute, the Commission submits its funding request to the USPS Board of Governors, which is to say, the leadership of the agency the PRC regulates, and the Governors may unilaterally cut the total by unanimous vote. The regulator’s paycheck is signed by the regulated.
In September 2023, that is precisely what happened. The Commission requested roughly $22.6 million for FY2024; the Governors approved $21.1 million. Chairman Michael Kubayanda’s public statement on the cut warned it risked “eliminating positions in the understaffed agency” and “stopping long overdue technology upgrades,” and specified that the Commission was, at that moment, in the process of “establishing centralized databases, information management systems, and cybersecurity monitoring.” FY2024, recall, is the year the Commission’s cybersecurity program bottomed out at Ad-hoc across the board and the CISO walked out the door.
The following year tells a more complicated story, and honesty requires including it. For FY2025, the Governors approved the Commission’s full $25.4 million request, no cut at all. Yet the CISO seat remained empty for the entire year regardless, filled only as FY2025 was closing out. So the money explains the disaster year reasonably well. It does not fully explain the second straight failing grade, which looks less like a budget problem and more like the ordinary friction of hiring a specialized federal position, a separate and more mundane kind of government dysfunction, but dysfunction all the same.
Grading on a Curve
None of this amounts to negligence or coverup. The PRC agreed with all nine of KPMG’s new recommendations this year, as it agreed with all of them the previous two years, and the underlying trend, Ad-hoc to Defined to a mix of Defined and Consistently Implemented, is genuine improvement by any honest reading. The agency went from a two person cybersecurity operation to six people in about two years. That is not nothing.
What it is, instead, is a small case study in how “Not Effective” becomes a permanent institutional address rather than a temporary embarrassment. The fixes keep arriving with implementation dates a year or more out (several of this year’s nine recommendations are not due until September 2027), the governance layer keeps testing worse than the operational layers built under it, and the agency tasked with holding the Postal Service accountable spends its own compliance report explaining, once again, that it is small, understaffed, and doing its best. It probably is. The report just keeps saying so anyway.
Sources: USPS OIG / KPMG, FY2026 Federal Information Security Modernization Act Audit of the Postal Regulatory Commission (Report 26-016-R26, September 2026); PRC Chairman Kubayanda statement on FY2024 budget cut.
