Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
State cybersecurity chief outlines defenses, staffing needs and ransomware strategy
Summary
Ben Groszgeir, State Chief Information Security Officer, briefed the General Government Subcommittee on Oregon’s cybersecurity posture, describing the enterprise SOC, staffing levels, threats (including AI-assisted attacks), and the need for funding to reach full 24/7 monitoring and other initiatives.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Ben Groszgeir, the State Chief Information Security Officer and Director of Cybersecurity Services in Enterprise Information Services, told the General Government Subcommittee that the state has built multiple defensive capabilities but still has staffing and coverage gaps that need funding.
Groszgeir said Enterprise Information Services’ cybersecurity organization includes about 64 FTEs across six service verticals and that the state security operations center (SOC) has roughly 12 people who “are looking at the glass” during a daytime 12-hour shift. He said the state is working toward fuller 24/7 active monitoring and asked the committee to consider funding for a managed 24/7 service so people — not only automated tools — can triage alerts overnight.
On threats and tactics: Groszgeir described four high-level attacker categories — nation-state actors, financially motivated ransomware groups, insider threats and criminal hackers — and said bad actors are adopting AI to scale automated attacks. “If you have an automated bot attempting [phishing], it could be in millions. And one of them will succeed,” he warned. He listed phishing and social engineering as the top recurring vectors and said the agency tracks credential compromise closely.
Ransomware and recovery: Groszgeir said state infrastructure uses immutable backups to avoid paying ransoms and to restore systems after incidents. “Ransom payments are not in our books,” he said, and described immutable, air-gapped backups at the state data center. He urged agencies to verify their own backups are recoverable and immutable.
Statistics and scope: In his briefing Groszgeir cited published industry statistics — for example, identity-related breaches and ransomware targeting are widespread — and said the state sees daily attempts. He noted that the majority of successful attacks target the United States and that attacks often occur at night when staffing is reduced.
Capacity, supply chain and priorities: Groszgeir raised supply-chain risk (third-party vendors and contractors) as a significant and ongoing concern and said the state is inventorying vendors and connectivity to identify risk and require attestations. He described other ongoing initiatives including enterprise identity and access management and work with Gartner on identity governance, endpoint management to bring 60,000+ endpoints into managed service and DDoS protections routed through cloud filtering.
Budget and staffing requests: Committee members asked whether existing staffing is sufficient. Groszgeir said the team needs additional funding to expand active human monitoring to 24/7 and to scale incident response capabilities. He noted challenges recruiting and retaining experienced cybersecurity analysts and said training and internships are part of his workforce plan.
Process and interagency boundaries: Groszgeir said his office has jurisdiction over most executive-branch agencies (about 81 agencies, boards and commissions) but that some offices — for example, the Secretary of State, elements of the Department of Justice, Treasury and the judiciary — maintain separate authority; he said they nonetheless coordinate on shared standards and sometimes serve on advisory groups.
The presentation was informational. Committee members thanked agency staff and said the budget committee will weigh the requests for expanded monitoring and identity governance work as it considers expenditures.
