top of page

Risk Identification and Classification: 
The Door Nobody Checked 

In the private sector, a missed risk eventually shows up on a balance sheet. Fraud, waste, or an unmanaged vendor relationship erodes profit, and profit erosion gets noticed fast, by shareholders, by a board, by a quarterly review that happens whether anyone wants it to or not. That built-in feedback loop forces governance discipline, because the consequence of weak identification is immediate and personal to the people running the business.

Government does not have that loop. The money is not the institution's own, it is the taxpayer's, and the entity spending it does not experience the loss the way a business owner experiences a loss. There is no earnings call where an agency must explain to shareholders why millions walked out the door. The consequence is diffuse. It lands on taxpayers broadly, later, and often invisibly, not on the people who owned the identification failure at the time it happened. This is not a claim that public servants care less. It is a structural observation. When the entity spending the money and the entity absorbing the loss are not the same, the pressure that normally forces sharper governance, tighter communication, and stronger accountability relationships is missing by design, not by neglect.

I saw this firsthand at the Department of Justice, on an audit involving a physician in California who had filed sixty Medicaid claims from sixty different locations on the same day. Nobody caught it in the ordinary course of business. It surfaced only when an auditor discovered it. The doctor almost certainly understood the same thing an adversary understands: that a system without a working identification mechanism will not stop you, because it cannot see you.

That is where this pillar's real subject lives. Fraud is one expression of a weak identification system. In information technology and cybersecurity, the same weak system is what an adversary is actively looking for, right now, across both government and private infrastructure.

Since late July of 2026, the FBI and the Environmental Protection Agency have been warning that malicious actors are targeting water and wastewater utilities by exploiting programmable logic controllers that were left exposed directly to the internet. Utilities in at least seven states reported break-ins within days of each other. Attackers changed passwords and locked operators out of their own systems, forcing some utilities to issue boil-water notices and run equipment by hand. That footprint has since expanded to at least twelve states, and investigators are examining a possible link to Iran in connection with the Minnesota incidents. A state security official summarized the pattern precisely: the attackers are not doing anything sophisticated. They are rattling doorknobs nationally, looking for whichever system has a weak configuration.

Healthcare has seen the same failure play out on a longer timeline. In 2023, three Hudson Valley facilities operating under the Westchester Medical Center Health Network, HealthAlliance Hospital, Margaretville Hospital, and Mountainside Residential Care Center, were hit by a cyberattack that went undetected for roughly two months before it was discovered. The network had to shut down all connected IT systems and divert ambulances to other hospitals while it worked to recover. Two months is not a brief lapse. It is a system that had no mechanism actively watching for the intrusion until the damage was already done.

Neither of these examples is a technology failure in a narrow sense. A PLC left open to the internet and a network breach that ran undetected for two months are both identification failures. The systems existed. The visibility in them did not.

This is also where foreign ownership, control, and influence enter the picture, an area I worked directly through my role on GSA's Section 889 Prohibited Equipment Committee. A vendor relationship can carry risks long before any technical vulnerability is exploited, simply through who owns, controls, or has undisclosed influence over a company supplying government or critical infrastructure systems. Identification here means asking a question most procurement processes are not built to ask: not just does this product work, but who is behind it, and what access does that ownership structure create.

The same discipline applies at the device level. During my work supporting CWMD, devices entering the mission space, including CBRN detection equipment, required identification before anyone could reasonably act on their risk. A piece of hardware sitting in a warehouse is not yet a risk anyone can manage. It becomes manageable only once someone has identified what it is, where it came from, and what it touches.

Identification, across every one of these examples, answers a single question: what exists, and where is it exposed. Classification answers the next one: now that we have found it, what do we do with it.

This is where the CWMD consequence analysis methodology became the clearest structure I have worked with. Every item entering the environment moved through a dual intake process, evaluated from two directions at once rather than a single checklist. From there, it was classified across five layers: the device itself, the system it operated within, the applications running on it, the mission it supported, and the vendor who supplied it. A device might look low risk in isolation and high risk once you account for the mission it touches. A vendor might look acceptable on paper and become a concern once mapped against the system architecture it would sit inside. Classification only works when it is layered this way. A single-dimension checklist will pass things a five-layer taxonomy would catch.

Identification without classification produces a pile of flagged risk with no way to prioritize it. Classification without broad identification produces a well-organized blind spot, a tidy taxonomy applied to only the risks someone happened to notice. Both halves must function together, and in that order, or the pipeline breaks exactly where the California doctor, the exposed water utility controllers, and the undetected hospital breach all broke: at the point where nobody was looking in the right place.

Section 889 and supply chain risk management exist for a reason that follows directly from the opening argument. Government will not generate identification discipline organically, because it lacks the feedback loop that forces a private company to police itself. That discipline must be imposed from outside, through statute, through committee oversight, through frameworks like C-SCRM that mandate the kind of scrutiny a shareholder would otherwise demand. This is not criticism of the people doing the work. It is a recognition of what structure is missing and what must replace it.

All this matters more, not less, as artificial intelligence expands across both sectors. AI does not create a new category of risk so much as it multiplies the surface area of every category already discussed here, more systems, more vendors, more integrations, more data flowing through applications nobody has fully mapped yet. Whether the organization is a federal agency or a private company, the vulnerability is enormous and will only grow unless it is addressed the same way this pillar has laid out: through disciplined governance, clear procedures, structured processes, and vendor relationships that are vetted rather than assumed. Locking down systems and applications is not a one-time project. It is the ongoing work of making sure nothing sits exposed simply because nobody thought to check the door.

This is Pillar 2 of 8 in the IT Risk and Cybersecurity Governance Framework series. Read the full Framework at MVWConsultants.com/framework.

footer-logo_edited.png

Service-Disabled Veteran-Owned Small Business

TS/SCI

Mikes logo2.png

Mobile: (908)230-7301

  • LinkedIn
Subscribe 

Thanks for submitting!

©2020 MVW CONSULTANTS All Rights Reserved

bottom of page