Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

CalPERS hears cybersecurity threat‑landscape briefing; closed session follows for security update

5394630 · July 16, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

CalPERS received a public briefing on the modern cyber threat landscape — nation‑state and criminal actors, ransomware trends, and deep‑fake social engineering — then moved into a closed‑session information‑security update under the Bagley‑Keene exception; staff reported no action was taken.

A public briefing summarized the evolving cybersecurity landscape and operational implications for CalPERS. The outside firm partner and CalPERS’ CISO described threats driven by nation‑state actors, organized criminal groups and the rapid acceleration of attack automation aided by AI. Presenters said attackers now operate as structured enterprises, with monetization paths including ransomware, data theft, account takeover, business‑email compromise and laundering through jurisdictions that offer weak mutual‑legal‑assistance. Examples cited included weaponized supply‑chain or third‑party compromise, double‑extortion ransomware and “deep‑fake” social‑engineering attacks that impersonate executives in live video or phone calls.

The board then voted publicly to meet in closed session under the Bagley‑Keene exception for information security briefings (Gov. Code §11126(c)(18)). Staff reported in open session after that closed session only that they had met under that exception and that no public action was taken. Staff emphasized the need for layered controls, timely detection and incident‑response readiness, and noted ongoing work on monitoring, tabletop exercises and partner coordination. Several board members asked questions about fraud dynamics, liability, and bank/customer protections; staff responded that these areas are under active review and that the regulatory environment and insurance markets are changing to address cyber risk.