It’s no secret that cybersecurity threats loom over federal agencies. According to the most recently published FISMA Annual Report to Congress, federal agencies reported 32,211 information security incidents in a single fiscal year — a 9.9 percent increase over the year before.
We are talking about the security of content held by federal agencies. Content that concerns and belongs to all of us.
And few offices sit closer to that content than FOIA programs. Request files concentrate exactly what attackers want: personal information, law enforcement records, procurement details, and internal deliberations — all gathered in one place, moving through search, review, redaction, and release.
So the question isn’t whether FOIA systems are worth attacking. It’s whether they’re built to withstand it.
Why FOIA Agencies Fail To Protect Themselves From Cyber Security Threats?
Cyber risks can manifest in different ways, but they all strongly affect the security of FOIA agencies. And very often, these agencies can do nothing to protect themselves when data theft is under way. This incapability comes from the fact that they don’t always have all the necessary means to respond to the threat.
Let’s take a look at some of the reasons why FOIA agencies fail to protect themselves from cyber attacks:
- FOIA agencies are not always equipped appropriately to determine how perpetrators find their way into their information systems. Their IT tools are often outdated and unsupported. Many FOIA offices are still running on legacy systems that predate modern federal security requirements entirely.
- Another vital reason why FOIA agencies fall short on protecting themselves from cyber attacks is the lack of standardization of common operating procedures. Malicious links, emails, and attachments can easily infect unsuspecting users’ machines with malware.
- The defense-ability of FOIA agencies has largely stagnated while perpetrators become more sophisticated and advanced in their techniques to attack and compromise information systems — and generative AI has made convincing phishing campaigns easier to produce than ever.
All of these gaps add up. They create enterprise-wide weaknesses in network security and operating procedures — and they are a big part of why federal agencies report tens of thousands of security incidents every single year.
These numbers emphasize the dire need for change across agencies. Federal agencies working with FOIA requests need immediate, highly effective improvements that dramatically raise their level of security.
The solution? A FedRAMP Authorized FOIA software solution.
What Is FedRAMP And Why Do FOIA Agencies Need It?
The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide program that provides a standardized, reusable approach to security assessment, authorization, and continuous monitoring for cloud computing products and services.
FedRAMP started as an OMB policy initiative. Today, it’s the law. In December 2022, Congress passed the FedRAMP Authorization Act, formally establishing the program within the General Services Administration (GSA). And in July 2024, OMB issued Memorandum M-24-15, replacing the original policy with an updated vision, scope, and governance structure built for today’s cloud marketplace.
The core idea hasn’t changed: “do once, use many times.” When a cloud service completes a FedRAMP authorization, federal agencies can leverage that assessment package instead of starting their own security evaluation from scratch. M-24-15 goes even further — it directs agencies to treat an existing FedRAMP authorization as presumptively adequate.
For FOIA agencies, that matters in two ways. First, choosing a FedRAMP Authorized platform means the records moving through your FOIA workflow are protected by security controls that have been independently assessed and are continuously monitored. Second, it saves the enormous time, money, and effort your agency would otherwise spend running those security assessments itself.
How FedRAMP Authorization Works Today
The authorization process follows the NIST Risk Management Framework, tailored specifically for cloud offerings. At a high level, it comes down to four stages:
- Documentation of security controls. The provider categorizes the information system, selects and implements the required security controls, and documents them in a System Security Plan (SSP).
- Independent assessment. A third-party assessment organization examines the system to determine whether the documented controls are actually implemented and effective.
- Based on the full security package, an authorizing official makes the authorization decision.
- Continuous monitoring. Authorization isn’t a one-time stamp. The provider must maintain an acceptable risk posture under ongoing monitoring — or the authorization doesn’t hold.
And the program is getting faster. In March 2025, GSA announced FedRAMP 20x — a modernization initiative that cuts documentation burden, automates evidence validation, and streamlines decision-making. The results came quickly: by mid-2025, FedRAMP had completed a record 114 authorizations for the fiscal year — more than double the total from the year before.
The FedRAMP Marketplace is growing. But here’s what hasn’t changed since we first wrote about this topic: purpose-built FOIA and case management platforms that carry FedRAMP authorization remain rare. Which brings us to the part we’re proud of.
The FedRAMP Authorized ArkCase Platform
ArkCase — the platform behind the Armedia FOIA solution — is now FedRAMP Authorized.
What does this mean?
It means the security controls protecting every FOIA request, every responsive record, and every redaction decision in ArkCase have been independently assessed under FedRAMP’s standards — and are subject to continuous monitoring, year after year.
It means agencies evaluating ArkCase don’t start their security review from zero. They inherit an authorization package that has already done the heavy lifting — exactly the head start M-24-15 tells agencies to take. (FedRAMP authorization doesn’t eliminate your agency’s own ATO work entirely; we wrote about what that process really looks like in FedRAMP + ATO Reality Check.)
And it means the technologies underneath carry the same pedigree. The Armedia FOIA solution is built on ArkCase together with Hyland Alfresco for governed content storage, Tungsten Automation’s Ephesoft Transact for document capture and digitization, and AWS infrastructure that has anchored FedRAMP-authorized workloads for years.
Role-based access control, case-level security, and complete audit trails are part of the platform’s architecture — because in a FOIA program, knowing exactly who touched which record, and when, is the difference between a defensible process and an indefensible one.
You can find Armedia’s authorized offering on the FedRAMP Marketplace.
Security Is Now Part of the FOIA Conversation
Sixty years into FOIA’s history, transparency and security are no longer separate conversations. Security requirements now sit front and center in FOIA solicitations — and FedRAMP authorization is increasingly the gate, not the bonus.
If your agency is evaluating FOIA platforms, start with the question that decides everything else: is it FedRAMP Authorized?
Ready to see what a FedRAMP Authorized FOIA platform looks like in practice? Book a call today: Meet with Ray Azarm







0 Comments