Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Vermont ADS CISO briefs House committee on state IT cybersecurity, cites monitoring, recent incidents

3216626 · May 7, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

John Toney, chief information security officer for the Agency of Digital Services (ADS), told the House Energy and Digital Infrastructure Committee on May 7 that ADS now monitors hundreds of billions of IT events a year and has published the state’s first cybersecurity foundations policy to standardize protections across executive-branch agencies.

John Toney, chief information security officer for the Agency of Digital Services (ADS), told the House Energy and Digital Infrastructure Committee on May 7 that ADS now monitors hundreds of billions of IT events a year and has published the state’s first cybersecurity foundations policy to standardize protections across executive-branch agencies.

Toney said the agency “will monitor 358,800,000,000 events” and detailed other metrics, including identifying more than 52,000 phishing attempts over nine months and 16 phishing messages that reached users’ inboxes before additional protections were tuned. He also said ADS reduced known vulnerabilities across the enterprise footprint by 75.3% in the past nine months and improved mean resolution speed by 56.3% since he joined the agency.

The policy work is the core of ADS’s strategy, Toney said: “That foundation's policy enables me and my team to roll out configuration management standards … so we have consistency. We have accountability across ADS and across all of our vendors, suppliers, and partners.” He said ADS signed an initial configuration management policy on April 28 and will publish it on the ADS security website.

Why it matters: ADS supports systems that handle federal program funds, employee and constituent data, and services for multiple agencies. Toney told the committee that half of his team focuses on compliance reporting required by federal funders and agencies, listing the IRS, FBI, Department of Justice, Health and Human Services, Social Security Administration, FEMA, the Department of Veterans Affairs and the Centers for Medicare & Medicaid Services as recipients of IT-control reports.

Committee members asked how those protections operate in practice. Toney described endpoint defense as a small agent installed on devices that flags anomalous behavior and said ADS’s critical-alert response time fell from about nine minutes to under a minute. “If the flag is severe enough … we just contain the machine,” he said, describing containment as a step that isolates a device so it cannot communicate while investigators determine whether it is compromised.

Toney described several incidents ADS has handled while coordinating with state and federal partners. He said ADS responded to a ransomware event that disrupted a Vermont health system, in which ADS temporarily segregated that health system’s connections to state systems to prevent spread and then coached the health system’s leadership as they engaged an outside incident-response firm. He also described a “watering hole” compromise in which a Burlington restaurant’s online menu was infected and could have exposed state users who visited the site.

On emerging threats, Toney named organized-crime groups, advanced persistent threats tied to nation-states, hacktivists, and unknown actors operating from cloud providers’ infrastructure. He described concerns about impersonation and the role of AI in improving the realism of fraudulent messages. He also noted challenges when malicious activity originates from accounts hosted by large cloud providers, which he said sometimes prioritize protecting their platforms over tracking attackers.

Several committee members pressed for follow-up information. Representative Dara Torrey asked whether ADS had a role in the PowerSchool incident; Toney said he was briefed but had limited ability to affect a third-party breach and added he believed PowerSchool’s public report lacked detail. Committee leadership asked the Agency of Education to provide details about what student data were compromised and how many districts were affected; the committee noted that AOE had not yet provided that information and created a follow-up request.

The committee requested that ADS share the newly published cybersecurity foundations policy and the configuration management policy link. Committee staff agreed to post Toney’s materials and the policy links with the committee’s testimony.

The exchange ended with committee members and Toney discussing coordination with external partners including the Vermont Intelligence Center, the state attorney general’s office, the state treasurer (for bond-rating implications), the Vermont National Guard and Vermont Emergency Management, and private-sector entities including cloud providers and utilities. Toney said ADS participates in a cybersecurity advisory council to coordinate with utilities and other critical infrastructure owners.

The committee did not take any formal votes during Toney’s testimony; it recorded requests for information and document sharing as next steps.