Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Digital Infrastructure Cybersecurity topic
No spam. Unsubscribe anytime.
Legislative IT outlines cybersecurity posture, pushes MFA enrollment and ongoing training
Summary
Legislative IT staff briefed the House Energy and Digital Infrastructure Committee on the legislature’s cybersecurity posture, describing defenses, metrics and plans to enroll more legislators in multifactor authentication and expand training.
Get email alerts on the Digital Infrastructure Cybersecurity topic
No spam. Unsubscribe anytime.
Legislative IT officials briefed the House Energy and Digital Infrastructure Committee on their cybersecurity posture, metrics and planned actions, and urged legislators to enroll in multifactor authentication to protect access to legislative systems.
The briefing matters because legislative email and internal systems contain official records and constituent contact information; weak access controls or successful phishing could disrupt legislative business or expose sensitive information.
Kevin Moore, director of IT for the General Assembly, said the office focuses on “building resilience, not just the stop threats — to adapt and recover quickly in the event that there is an incident.” Moore described core safeguards in place — encryption of devices and data in transit and at rest, multifactor authentication, next-generation firewalls, network segmentation, extended detection and response (XDR) tools and automated threat-intelligence feeds — and outlined metrics showing active threats to the legislature’s internet-facing footprint.
Moore said the team ingests external feeds such as the Multi-State Information Sharing and Analysis Center (MS‑ISAC) and other commercial feeds and uses tools that Microsoft brands as advanced threat protection to sandbox suspicious attachments. He summarized periodic, consultant-led security posture reviews that assess architectural maturity and inform continuous improvements to policies and tooling.
Moore reported specific operational metrics to the committee: his team maintains a blocklist of “over 9,000 malicious IPs,” and said the network blocked “over 95,000 attempts” to contact those IPs in the past 70 days. He also reported roughly “191 phishing messages detected and handled daily” and said proactive phishing simulations have a roughly 95% success rate (that is, users who did not fall for the simulated phish) over the last three years. Moore also said that multifactor authentication (MFA) adoption among legislators was highlighted at 43% and that staff MFA is enforced.
Moore stressed workforce awareness and training: Delia Gillen, the legislature’s IT trainer, is drafting flyers and the office plans quarterly cybersecurity awareness training for legislators; staff already receive training and simulations that include follow-up training for users who fail simulations. Moore said hardware tokens or authenticator apps are available for legislators who prefer them and that some hands-on help from the help desk is required for token enrollment.
On policy and partnerships, Moore described coordination with federal and peer organizations — NIST, CISA (Cybersecurity and Infrastructure Security Agency), DISA (Defense Information Systems Agency), the Center for Internet Security (CIS), the National Conference of State Legislatures (NCSL) and the National Association of Legislative Information Technology (NAILIT) — and said the office works with the FBI’s Albany field office when needed. He said the office removed a downloadable public directory of legislators’ contact information after an FBI briefing raised concerns about easy automated harvesting; requests for contact lists will now be handled case-by-case.
Committee members asked operational questions about automatic updates, outbound blocks, and targeting methods. Moore and network security administrator Rain Torres explained that many threat lists update as often as hourly, some protections are automatic and some updates are applied manually by staff where intentional control is required, and that attacks range from broad “spray” campaigns to targeted messages based on district or role.
Moore said the team is actively pursuing a budget-friendly managed security operations center (SOC) to improve 24/7 monitoring and mentioned that security posture reviews are ideally done at least annually with rotating consultants. He emphasized a “security-first mindset” while noting the need to avoid creating barriers to legislative work.
The presentation did not include formal committee motions or votes; the briefing recorded staff directions and planned actions but no ordinances, resolutions or formal approvals. Moore’s office will proceed with planned training, increased MFA enrollment efforts, continued posture reviews and evaluation of an external SOC provider.
Committee members thanked staff for the briefing; staff said they will follow up with enrollment materials and training notices for legislators and staff.

