Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the State Cybersecurity topic

No spam. Unsubscribe anytime.

State officials report stepped-up cybersecurity defenses, flag continued risks

3511488 · May 23, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Representatives from Oregon’s branches and constitutional offices reported layered security improvements, increased monitoring, and expanded training at a May 23 joint committee hearing while warning of ongoing threats, staffing gaps and reliance on federal information-sharing programs.

Cochair Manning convened the Joint Committee on Information Management and Technology on May 23 for the statutory biennial cybersecurity reports required under state law following the 2016 legislation that created this reporting duty. Presenters from the Oregon Judicial Department, the Legislature, the Secretary of State’s office, the Oregon State Treasury, the Department of Justice and the state cybersecurity office summarized current posture, recent investments and continuing gaps.

The statewide theme from agency officials was upgraded detection and layered defenses paired with user training, but continued exposure from legacy systems, decentralized identity management and unpredictable external funding. "Cyber attacks keep increasing every year," Shane Walker, chief information officer for the Oregon Legislature, told the committee, urging agencies to keep legacy systems patched and staff trained. "We built a layered security architecture" was how Dan Teams, chief information security officer for the Secretary of State, described that office’s approach to monitoring and blocking malicious activity.

Why it matters: state agencies operate hundreds of mission-critical systems that serve millions of Oregonians and process high-risk financial and personal data. Committee members pressed officials on whether the partially decentralized model — with constitutional offices and the judicial branch outside an executive centralized IT structure — raises security risk and on plans to staff 24/7 monitoring.

Key points from presenters: - Oregon Judicial Department: Brian Baer, chief information officer for the Oregon Judicial Department, described documented change-management processes, encrypted data-sharing with partners and recent rollouts of secure texting for jurors and hearing notifications through a Twilio integration. Baer said the department operates case management, jury and related systems across 87 locations and about 1,800 staff and judges. - Legislature: Walker said the Legislature has increased detection and response tooling, tracks high volumes of email and video traffic tied to public sessions and reported several incidents (including command-and-control and credential-phishing attempts) that were contained with device wipes and password resets. He noted the Microsoft security score for legislative accounts had risen from the low 40s to about 69% and set a goal of 80% within a year. - Secretary of State: Chris Mullen (CIO) and Dan Teams (CISO) described managed endpoint detection, multifactor authentication with hardware tokens (YubiKeys), 24/7 scanning, a move toward zero-trust network access and formalizing vulnerability and assessment programs aligned to NIST and CIS controls. - Oregon State Treasury: Jerry Walker (CIO) and Dr. Donald Johnson (CISO) said Treasury aligns to the NIST framework, has a 24/7 managed detection capability, and is prioritizing detection and response, cloud security, and automation to reduce time to acknowledge incidents. Treasury reported a high transaction load and emphasized third-party risk management and staff training. - Department of Justice: Judah Kelber (Interim CIO) and Raymond Davis (CISO) reported large year-over-year increases in blocked attacks and web traffic, including a roughly 220% rise in phishing attempts blocked and vast increases in web-proxy blocks. Kelber said defenses reduced malware that reaches endpoints from thousands to just dozens when compared with the prior year. - State cybersecurity office: Ben Grasgeir, the state chief security officer and director of the state cybersecurity service, reviewed statewide visibility and initiatives. He said the state is investing in cloud guardrails, enterprise identity and access management roadmaps, network modernization and a managed 24/7 security operations capability (ESAC). Grasgeir emphasized the limits of perimeter-only defenses and said, "We are looking into zero trust implementations where every connection ... has to attest and verify identity." He also noted the state currently operates a 12-hour-on, 12-hour-off monitoring model and described a planned move to 24/7 monitoring via managed service.

Discussion and committee concerns: Members repeatedly raised decentralization and staffing. Several asked whether split identity management and agency-level procurement create avoidable security and cost problems. Officials agreed visibility and centralized governance for high-value identity and mission-critical assets would materially improve detection and response without eliminating necessary agency autonomy. Committee members also asked about federal information-sharing and the multi-state ISACs; agency speakers said MS-ISAC and FS-ISAC advisories and CISA bulletins feed rapid threat indicators to state operations but flagged uncertainty about future federal funding of those services.

Actions, direction and next steps: There were no formal votes. The committee scheduled a follow-up meeting for May 30 to continue cybersecurity discussion and to hear Western Oregon University on regional security operations support. Officials said they will continue maturing zero-trust and identity programs, expand managed detection and response, and pursue grant funding under the State and Local Cybersecurity Grant Program. The state office said it has submitted a waiver request for the federal grant match requirement and plans additional rounds of local-government funding outreach.

Ending note: Presenters emphasized that cybersecurity is an ongoing operational priority in Oregon government and that the state has strengthened detection and prevention controls, but gaps remain in around-the-clock monitoring, enterprise identity visibility and dependence on external information-sharing that could affect response in the event of a major incident.