• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

3 leadership lessons from the U.S. government’s data hack

By
S. Kumar
S. Kumar
Down Arrow Button Icon
By
S. Kumar
S. Kumar
Down Arrow Button Icon
July 13, 2015, 11:08 AM ET
Katherine Archuleta
Office of Personnel Management Director Katherine Archuleta testifies before the Senate Homeland Security and Governmental Affairs Committee on Capitol Hill in Washington, Thursday, June 25, 2015, during a hearing on Federal Cybersecurity and the OPM Data Breach. (AP Photo/Susan Walsh)Photograph by Susan Walsh — AP

The U.S. government’s Office of Personnel Management chief Katherine Archuleta resigned last week in the wake of a massive data breach involving social security numbers and other personal information of nearly 21.5 million people. Despite the seriousness of the breach, the Obama administration was supportive of Archuleta even while Republicans wanted her gone. While it’s impossible to tell how much autonomy Archuleta really had in handling the aftermath and in revealing information to the public, as the keeper of the records, her responsibility was heavier than anyone else’s.

The following are 3 areas where Archuleta failed as a leader.

Ignoring a credible threat

The primary function of the OPM is to serve as the human resources office for the federal government. As part of this function, it gathers and maintains mountains of sensitive information on prospective candidates and current employees, and securing that data should be a priority for the agency. Cybercrime is neither a new phenomenon nor is it obscure anymore. It’s a major threat to all organizations and especially one like the OPM that is a treasure trove of personal information.

Despite this, the agency showed a shocking insouciance toward cybersecurity. Its computer systems reportedly lacked even basic security procedures like two-factor authentication and encryption of social security numbers. Even the Department of Homeland Security’s intrusion detection system, called EINSTEIN, apparently failed to detect data breaches until it was too late.

Ignoring a credible threat is a sign of bad leadership. While the DHS might deserve some of the blame, it was ultimately Archuleta’s responsibility to maintain the integrity of the OPM’s database, and she failed at doing that.

Not sounding the alarm

The OPM’s computer vulnerabilities were not unknown. The agency had been warned about the risks of its outdated technology as early as 2007, but no remedial steps were seemingly taken, according to The New York Times. To be fair, it’s certainly possible that Archuleta asked for funds to upgrade the OPM’s systems and was denied, or was thwarted by inter-governmental politics, but nothing has surfaced so far to indicate that.

A good leader would have acknowledged that something was very wrong and sounded the alarm. Had the OPM moved proactively to modernize its cybersecurity eight years ago, the current breach might never have taken place. Sounding the alarm might have pitted Archuleta against those who didn’t consider a hack of this magnitude to be likely or had budgetary concerns, but that was no reason for her to stay silent. She could also have taken her concerns to the press to force action on the issue. It was Archuleta’s job to be bold and take the lead in fixing an obvious problem.

Downplaying the problem

Once the breach had been discovered, Archuleta should have acknowledged the full scope of the hack, but instead she tried to downplay it. According to a Wall Street Journal report, the OPM at first denied that security clearance forms, known as SF-86s, were stolen in the hack, even though the FBI had informed the OPM of that fact. Once it came out, the agency hid behind semantics, claiming that they had agreed with the White House to treat the breach of security clearance forms as a separate incident from that of personnel files and therefore not addressed it initially. Bad politics, but also bad leadership.

The result of this seeming obfuscation was that initial reports of the hack greatly underestimated the number of people who were affected. Given that it wasn’t just social security numbers that were compromised but fingerprint records, financial and mental health histories as well, Archuleta should have shown more empathy with the victims and come clean about the scope of the problem from the beginning.

S. Kumar is a tech and business commentator. He has worked in technology, media, and telecom investment banking.

About the Author
By S. Kumar
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

gen z
CommentaryGen Z
Gen Z is using ChatGPT to practice salary negotiations and tough conversations before they happen
By Phillip MillerMarch 22, 2026
15 hours ago
world
CommentaryCapitalism
Our economy has been living in an Adam Smith world since 1776. Something different is coming
By Ravi ChaudhryMarch 22, 2026
16 hours ago
david
CommentaryScience
The one skill that separates people who get smarter with AI from everyone else
By David Rock and Chris WellerMarch 21, 2026
2 days ago
war
CommentaryMiddle East
Companies are now on the front lines of war. They need to act like it
By Jeremy BashMarch 21, 2026
2 days ago
powell
CommentaryFederal Reserve
The Strait of Hormuz is the fourth large supply shock this decade. Welcome to the new era of global disorder
By Jon HilsenrathMarch 21, 2026
2 days ago
gen z
CommentaryCareers
The entry-level job market is the worst it’s been in 37 years. Stop blaming Gen Z
By Janelle Jones and Nia LawMarch 21, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.