In 2024, a cyberattack on a major healthcare payments processor demonstrated how dependent the U.S. healthcare system had become on a small number of critical services that move money and information.
When the company took its systems offline in response to the attack, hospitals, clinics, and physician practices lost a key pathway for processing transactions. Those organizations faced operational and financial strain, while patients experienced delays and disruptions to care.
For those organizations, the affected service was essential to daily operations. With limited alternatives available, routine business processes slowed or stopped. The incident drew significant public and government attention.
This is cascading risk, and it's not unique to healthcare. Many U.S. federal agency missions operate in much the same way.
Behind every service—processing payments, verifying identity and eligibility, issuing benefits—sits a network of connected systems. Identity services, shared platforms, cloud environments, and partners within and outside of federal agencies all play a role in delivering the outcome.
That interconnectedness keeps missions running. It also determines how service disruption and compromise spread along with the level of risk that organizations may face.
When one system fails, the impact doesn’t stop at its boundary. The disruption adds further risk, following the same routes as data and access. By relying on trusted relationships and shared infrastructure, disruption impacts can amplify when things go wrong.
That’s where most cybersecurity programs fall short. They assess systems one at a time, verify controls, document compliance, and check individual assets against requirements. Those activities are necessary for risk management. But they aren’t sufficient to fully illuminate how the level of risk may change once something goes wrong or the potential to increase the risk to other connected systems, processes, and missions.
Under the Office of Management and Budget’s Memorandum M-19-03 and the Department of Homeland Security’s Binding Operational Directive 18-02, certain systems are designated as high-value assets (HVAs) because of their importance to agency missions and operations. Risks to these systems can have agency-wide consequences, making them a top priority for protection and oversight.
But HVAs don’t fail alone.
In practice, risk isn’t defined solely by the consequence to the asset itself. It’s shaped by the potential consequences to systems that connect to it and the impact to the missions and communities those systems support.
Cascading risk can be more difficult to manage precisely because systems are often viewed individually rather than as interconnected parts of a larger mission. Most teams understand the systems they own, including how those systems are configured, how controls are applied, and how they perform under normal conditions.
Data, identities, access, and shared services connect systems across organizational lines. Without mapping systems and risks in a way that shows how disruption in one system could affect another, agency leaders lose critical information necessary to their understanding of mission risk. Leaders may know that individual controls are functioning properly without understanding which mission outcomes could be affected by an incident and how consequences could compound.
Identifying where responsibility lies is equally challenging. Individual systems typically have defined owners, but the dependencies between them often don’t. Those connections cross teams and organizations, relying on relationships and expectations that may be informal or untested.
The consequences become clear during an incident. One team may contain a problem within its own environment while failing to recognize downstream effects. Another may detect signs of disruption without understanding where it originated or who should respond. Coordination slows precisely when rapid action is needed.
Managing this risk requires an end-to-end view of mission dependencies. Agencies must understand how critical systems, services, and partners interact, identify where disruption could spread, and establish clear responsibilities before an incident occurs. Holistic reviews can reveal vulnerabilities and coordination gaps that system-by-system assessments often miss.
Securing HVA systems begins with understanding the dependencies that enable critical mission outcomes and the risks that threaten them. That involves starting with a mission outcome and tracing the systems that support it. Agencies can use the five-step review process below to identify critical dependencies and potential points of failure.
Centrality shows how connected a system is; criticality shows what happens if it fails. Closing the gap between those measures will define the next generation of HVA prioritization. Until organizations weigh mission criticality alongside exploitability and exposure, even sophisticated models will continue to rank technology risk rather than mission risk.
Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets.