XIX. IT, Cybersecurity, and Operational Resilience
The 2030 Census will depend on a large network of interconnected systems to collect responses, manage fieldwork, link administrative records, process data, and produce census results. Census is intentionally moving away from building every capability solely for the decennial census. Instead, the 2030 IT solution will combine enterprise systems used across the Bureau, decennial-specific systems, contracted services, and cloud-based technologies.
For most advocates, the details of this architecture are outside the central scope of census oversight. The important questions are whether the systems work at peak scale, whether sensitive information is adequately protected, and whether Census can continue operating when something goes wrong.
A. Enterprise and Cloud-Based Systems
Census plans to rely much more heavily on shared enterprise capabilities rather than maintaining a largely separate set of systems that exist only for the decennial census. The Operational Plan says most 2030 operations will be supported by automated systems, many of which serve the Census Bureau as a whole. Its enterprise “Business Ecosystem” includes shared capabilities for data collection, frames, data storage and processing, and dissemination.
The IT Strategy similarly calls for maximizing reuse and expanding use of secure cloud technologies, including cloud-native development and managed services. It nevertheless anticipates a mixed environment: the final 2030 system will integrate enterprise, purpose-built, and contractor-provided systems rather than eliminating decennial-specific technology altogether.
That approach makes sense for an agency that conducts surveys continuously. But it also means that the decennial census increasingly depends on systems, priorities, and technical organizations that are not controlled exclusively by the 2030 Census Program.
B. Potential Benefits
Greater use of enterprise and cloud systems could produce significant benefits.
Reusable systems can be improved and maintained between censuses rather than rebuilt every ten years. Costs can be shared across Census programs, and staff can develop continuing expertise with systems that remain in regular use. Census explicitly identifies reuse and lifecycle cost savings as benefits of the enterprise approach.
Earlier and more continuous testing is also possible when systems operate outside the decennial census. The IT Strategy calls for beginning decennial-specific integration testing early and iteratively maturing systems through field tests.
Cloud infrastructure can scale more easily between ordinary workloads and the enormous temporary demand surrounding Census Day. Census plans to phase capacity up for production and then reduce it as demand falls.
Finally, shared and remotely accessible systems can support more flexible staffing and operations, including work performed across headquarters, field offices, and approved work-at-home environments.
These are real advantages if enterprise systems can also satisfy the unusual scale, security, and timing requirements of the decennial census.
C. Risks
The same consolidation that creates efficiency can concentrate risk.
A failure in a widely shared enterprise service could affect several Census programs at once. The IT Strategy itself identifies a challenge in adapting enterprise systems designed for long-term, lower-volume work to the short-term, extremely high-volume demands of the decennial census. It also identifies the need to ensure that enterprise systems meet decennial requirements on the 2030 schedule.
Other issues deserve continued attention:
Decennial requirements may compete with enterprise priorities. Systems serving many programs must still be capable of meeting the census’s unusual performance and statutory deadlines.
Contractor dependence can create operational risk. Census must retain sufficient federal expertise, access to systems and data, and transition rights if a vendor performs poorly or fails.
Data concentration increases consequences of a breach. Combining large datasets and linking information about people and addresses can make the resulting environment especially sensitive.
Cyberattacks could disrupt enumeration as well as expose information. Census specifically identifies denial-of-service and malicious attacks as threats capable of shutting down census services or exposing sensitive data. Its planned protections include a Security Operations Center, continuous monitoring, penetration testing, threat hunting, incident response, and encryption.
Internal access matters as well as outside attack. The IT Strategy expressly identifies both insider and outsider threats. Access controls should protect census information from unauthorized employees, contractors, or political officials as well as external attackers.
That last issue deserves particular attention in the current environment. Title 13 places strong legal restrictions on disclosure of identifiable census information. Technical architecture should reinforce those protections by limiting who can access linked data, recording access, separating functions where appropriate, and making unauthorized or politically directed use difficult to carry out without detection.
Why advocates should care
The key question is not whether Census uses the cloud or a particular technical architecture. It is whether modernization creates new points of failure or access that could interfere with the count, expose sensitive information, or undermine public confidence.
D. Person Characteristic Frame Security
The Person Characteristic Frame warrants special scrutiny because it concentrates some of the most sensitive information used in the 2030 Census.
The PCF will contain administrative and supplemental information about people linked to specific addresses, their characteristics, household composition, and associated quality measures. It will draw from the Bureau’s enterprise Demographic Frame along with additional data obtained specifically for the decennial census, and it will support person matching and In-Office Enumeration.
This makes the PCF valuable for census operations, but it also raises the consequences of unauthorized access. A collection of separate administrative records may reveal limited pieces of information. A linked frame connecting people, addresses, household relationships, and characteristics can reveal substantially more.
Census states that the PCF will operate as a secure service and will comply with Title 13, Title 26 (where relevant), protections for personally identifiable information, and applicable information-security policies. It also says systems will collect only information necessary for the 2030 Census mission and legal requirements.
Advocates do not need access to detailed cybersecurity configurations, which could themselves create security risks. But Census should be able to explain publicly:
who and which systems are permitted to access PCF data;
whether access is limited to particular approved uses;
how access and data transfers are logged and audited;
how contractor access is controlled;
how unnecessary data are removed or access terminated after use; and
what safeguards prevent information assembled for the census from being repurposed for enforcement or other nonstatistical uses.
The final point is particularly important for public trust. Strong legal protections remain essential, but protections should also be built into the technology. The more detailed and interconnected the PCF becomes, the more important it is that improper access be technically difficult, auditable, and subject to clear consequences.
Priority issue
The PCF should receive heightened privacy, security, access-control, and auditing requirements because it brings together person, address, household, and characteristic information that may be especially sensitive when linked.
E. Continuity Planning
The census cannot simply stop and wait for normal service to return if Census encounters a significant IT issue. Enumeration occurs within a short statutory and operational window, and some disruptions could occur at the worst possible moment.
The Operational Plan says IT infrastructure will include backup, restoration, recovery, system monitoring, and Continuity of Operations Planning. Census also plans centralized incident response and cybersecurity monitoring.
Advocates do not need the confidential details of those contingency plans. But Census should demonstrate that it has credible plans for several foreseeable disruptions.
Major cyberattack or ransomware. Can Census isolate affected systems, continue critical response channels, recover from trusted backups, and determine whether census information or operational data were altered?
Cloud or network interruption. Are critical services redundant, and can fieldwork or other operations continue temporarily when workers cannot reach central systems?
Contractor failure. Does Census retain the data, documentation, technical rights, and federal expertise necessary to transition a critical function to another provider or bring it under government control?
Natural disaster. Can workloads, staff, equipment, and response resources be shifted rapidly when a hurricane, wildfire, earthquake, or other disaster interrupts operations in part of the country?
Sudden funding reduction. Has Census identified which capabilities must be protected first to complete the constitutionally and statutorily required census, and which planned functions could be scaled back without destabilizing the rest of the operation?
Court-ordered design change. Can Census modify a questionnaire, enumeration rule, data-processing procedure, or other contested component without rebuilding interconnected systems on an impossible schedule?
The last scenario connects IT resilience directly to the issues discussed elsewhere in this guide. A system can be technically reliable but operationally brittle if changing one rule requires extensive redevelopment across multiple tightly connected components. The IT Strategy recognizes this concern, stating that architects intend to avoid overly coupled systems and design for flexibility.
Central question
Can Census keep conducting an accurate and secure census when a major assumption fails, or has efficiency made the operation too dependent on a small number of systems, vendors, and fixed technical choices?
Where to Look: See sections 4.2, “Provide Solutions,” and 4.3.2, “Information Technology Infrastructure,” plus Appendix B on Security, Privacy, and Confidentiality in the 2030 Census Operational Plan. These sections describe enterprise-system reliance, IT operations, continuity planning, cybersecurity, and incident response.
The 2030 Census IT Strategy and Roadmap, especially sections 3.4.6–3.5, provides the clearest discussion of enterprise reuse, cloud technology, cybersecurity, contractor and enterprise dependencies, and known IT challenges.
For the most sensitive data infrastructure, see section 3.2.12, “Person Characteristic Frame Management,” of the Operational Plan, particularly its descriptions of PCF contents, matching, data-source quality, privacy, and confidentiality.
****