Wyden Calls for Federal Phase‑Out of Legacy Edge Devices in Favor of Zero‑Trust Architecture
What Happened — U.S. Senator Ron Wyden urged the federal government to retire legacy, public‑facing remote‑access gateways within two years and replace them with a zero‑trust model. He cited recent campaigns that compromised Cisco, Fortinet, Ivanti and Check Point edge devices, arguing that these “whack‑a‑mole” fixes are no longer acceptable.
Why It Matters for Compliance & Audit Readiness
- Legacy edge devices are a classic control‑gap that SOC 2 audits flag under CC6.1 – System Operations and CC7.1 – Change Management; continuous evidence of decommissioning and replacement is required.
- Mapping the removal of insecure devices to a zero‑trust framework provides defensible audit artifacts for Security and Availability trust principles.
- Verisq’s Control Mapping capability can automatically capture the lifecycle of edge‑device remediation, generating real‑time evidence for auditors and regulators.
Who Is Affected – Federal agencies, contractors, and any organization that relies on legacy network firewalls, NAC, or remote‑access appliances.
Recommended Actions
- Inventory all public‑facing edge devices and tag any that are end‑of‑life or unsupported.
- Map the decommissioning of each legacy device to SOC 2 control CC6.1 and CC7.1, capturing evidence in a continuous‑compliance repository.
- Deploy a zero‑trust network access (ZTNA) solution that enforces outbound‑only remote access and isolates key management.
- Validate the new architecture against emerging NIST zero‑trust standards and update audit evidence accordingly.
Source: DataBreachToday – Wyden Calls for Edge Device Annihilation in US Government
Technical Notes – The letter references the “Arcane Door” campaign against Cisco devices, the “FortiBleed” credential‑harvesting operation on Fortinet gear, and breaches of Ivanti and Check Point appliances. A March 2026 VulnCheck report found ≈ 42 % of exploited vulnerabilities targeted end‑of‑life devices, underscoring the systemic risk of outdated edge hardware.