Does the federal government face a higher risk of catastrophic cyberattacks if it relies on a single vendor for all its digital systems? Or is it safer to have a diverse array of vendors and products within federal networks?
Experts have debated this issue for years. Proponents of a single vendor liken it to storing all gold reserves in Fort Knox, where protection is centralized and can be more robust. However, recent cyberattacks by hackers from China and Russia on federal agencies and critical infrastructure have exploited vulnerabilities in systems provided by a single large-scale technology vendor. This has raised significant concerns among government advisors.
To explore the risks associated with vendor concentration, the Center for Cybersecurity Policy and Law (CCPL) conducted a real-time tabletop exercise in April. This exercise involved security experts simulating an attack on two fictional U.S. agencies, each with different levels of IT vendor diversity. The goal was to see how these varying system architectures impacted the adversaries’ success.
The exercise mirrored recent real-world cyberattacks and featured an adversarial team, teams for the two fictional agencies, and a team representing the executive branch. The adversarial team had compromised signing keys for “OmniCorp-Ident,” a core identity and access management suite from OmniCorp. This gave them access to critical systems, enabling data exfiltration and destructive attacks.
As the exercise progressed, the agency with more technology from OmniCorp experienced a higher penetration rate. The attackers moved swiftly through the system, causing extensive damage. Conversely, the agency with a more diversified technology setup sustained less damage, demonstrating that a varied IT environment can mitigate the impact of cyberattacks.
The exercise revealed a clear advantage for the agency with a diversified IT infrastructure. Based on these findings, the CCPL drafted a report with several recommendations:
- In collaboration with industry, the National Institute of Standards and Technology (NIST) should further define IT monoculture types and boundaries. Organizations should be able to measure the risks associated with IT monoculture in their purchasing and implementation decisions. These findings should be included in the Cybersecurity Framework and other NIST risk management guidelines.
- To understand the scope and risks of IT monoculture in the federal government, the Office of the National Cyber Director should direct relevant agencies, including the Cybersecurity & Infrastructure Security Agency, the Defense Department, and the General Services Administration, to identify IT consolidation across departments and agencies.
- Congress, particularly the Committee on Homeland Security and Governmental Affairs, should investigate and oversee the risks of IT consolidation within federal government departments and agencies.
The study clearly indicates that federal services and citizen information are better protected when using a variety of vendors with diverse products. We urge both government and industry to diversify their systems to enhance resilience against future cyberattacks.
Ari Schwartz is the coordinator of the Center for Cybersecurity Policy and Law and a former special assistant to the President and senior director for cybersecurity on the National Security Council.



