GovKM
Cyber Detection and Institutional Learning

The Event Happened. Detection Never Turned It Into Evidence.

FDIC OIG found that some emulated cyber tests did not generate notable events and recommended stronger detection engineering, access controls, and incorporation of testing lessons into response plans. The case demonstrates both a Source-to-Evidence detection failure and a Record-to-Institutional-Memory learning failure.
Governance Architecture showing how observable cyber activity must become evidence, inform response decisions, and feed lessons into institutional memory.
Expand image

Cybersecurity monitoring is an evidence pipeline. If an event occurs but detection controls do not surface it, the organization cannot reliably place that event into decision context.

On August 31, 2026, the Federal Deposit Insurance Corporation Office of Inspector General issued an audit of the FDIC's incident detection and response program. Among its recommendations, the OIG called for updating detection-content development based on emulated tests that did not generate notable events, reviewing permissions that could allow endpoint detection and response services to be disabled or interfered with, improving access revocation after involuntary separations, and incorporating lessons from incident-response testing into the Incident Response Plan and Cybersecurity Event Recovery Plan.

The OIG's public recommendation tracker continued to list the four recommendations as unimplemented as of September 8, 2026.

An event must become evidence before it can become context

In the GovKM Continuity Topology, a real-world occurrence begins as a Source. Monitoring and detection controls transform observable activity into Evidence that can enter Context and support a Decision. If that transformation fails, the institution may experience an event without achieving institutional awareness of it.

The first continuity break therefore appears at Source → Evidence: emulated activity occurred, yet some tests did not generate the notable events needed for detection and response.

Testing must also change future behavior

The second continuity issue appears later in the topology. Incident-response exercises create records of what worked, what failed, and what should change. Those records should become Institutional Memory and alter Future Reuse through updated plans, procedures, and controls.

A test whose lessons remain in a report but do not alter the next response has not completed the continuity cycle.

GovKM interprets the FDIC findings as evidence for two connected propositions: security monitoring is evidence creation, and security testing is institutional learning. Both require governed propagation across the topology.

Source

Federal Deposit Insurance Corporation Office of Inspector General, “The FDIC’s Incident Detection and Response Program,” Report AUD-26-03, August 31, 2026.

FDIC OIG report

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.