Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Committee advances bill to centralize state cybersecurity functions under a single office

2703215 · March 19, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

House Bill 1549 would create a centralized cybersecurity office to align cabinet‑level cybersecurity efforts, add active monitoring, incident response capability and support for agencies; the committee moved the bill after agency testimony said the state’s attack surface is growing and practice—not policy—needs more consistent implementation.

Representative Scott Richardson presented House Bill 1549, described as the "Cybersecurity Act of 2025," proposing a centralized state cybersecurity office to align cyber functions across cabinet‑level agencies. Richardson said the office would oversee active monitoring, incident response, governance, compliance and training, and would align with prior work and the governor’s Arkansas First initiative.

Gary Vance, identified as the state cybersecurity officer (TSS), testified in support and told the committee the state faces malware, ransomware and broad attack risks and that while policies exist, practices and maturity vary among agencies. Vance said the bill is intended to create consistent standards, use existing agency cyber staff in a collaborative working group and deploy a cyber response team to assist agencies after incidents.

Committee members asked whether the proposal required hiring new staff or replacing agency roles. Vance and Richardson said initial implementation would rely on existing agency cybersecurity resources and liaisons; the bill provides for functional reporting and coordination rather than immediate large‑scale hiring. Members asked about support for municipalities and counties; witnesses said the office would be positioned to share standards and, where necessary, provide assistance.

Representative Richardson characterized the bill as the next step after prior session work to develop cybersecurity standards for the state and said the measure improves resilience, incident response and centralized oversight. After discussion the committee voted to pass the bill.