Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the State Cybersecurity topic

No spam. Unsubscribe anytime.

State cybersecurity officials outline threats, defenses and public training plans

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

State Chief Security Officer Jason Cavendish and Detective Lieutenant Jeff Hoffman briefed the Michigan House Communications and Technology Committee on rising cyber threats, the state—s 0-trust strategy, training for residents and volunteer rapid‑response teams.

Jason Cavendish, the Department of Technology Management and Budget deputy director and State of Michigan chief security officer, told the House Communications and Technology Committee on March 10 that the state is improving defenses against both nation‑state espionage and financially motivated cybercrime.

"Our mission is to enable the business to function securely while making security easier for customers and harder for hackers," Cavendish said, describing a strategy built around a 0‑trust architecture, stronger backups and expanded monitoring.

Cavendish summarized recent threat research and state actions. He cited the Verizon Data Breach Investigations Report to highlight human‑targeted attacks such as credential harvesting and pretexting, and said stolen credentials have been a factor in roughly one‑third of data breaches since 2013. He said the state deployed a web application firewall after the 2021 Log4j vulnerability and credited fiscal appropriations in fiscal 2021 and fiscal 2023 for enabling rapid responses and improved backup and recovery processes.

Detective Lieutenant Jeff Hoffman, who oversees the Michigan Cyber Command Center within the Michigan State Police, reviewed the command center—s partnerships and common attack vectors. "Business email compromises... that's number 1 in the nation," Hoffman said, adding that ransomware and advanced persistent threat groups are also regular threats and that AI‑driven deepfakes are an emerging concern.

The pair described current and planned programs to reduce statewide cyber risk. Cavendish said DTMB has updated its acceptable use and data classification standards, created AI use guidelines and launched an AI intake process reviewed by a cross‑functional AI core team. He announced that the state awarded a contract for an enterprise AI chatbot to BlueVector AI and that Boston Consulting Group will begin work on a statewide AI strategy.

Both officials described outreach to local governments, schools and the private sector. Cavendish said MiLogin will offer cybersecurity training for children, teens and adults beginning in September, covering password management, phishing, social engineering and what to do after a compromise. Hoffman said the Michigan Cyber Command Center conducts assessments for critical infrastructure and sends regular bulletins; MC3 can be reached at mc3@michigan.gov or by calling the hotline referenced in public materials.

Cavendish also discussed a volunteer technical rapid‑response unit enabled by state law that he described as providing on‑the‑ground assistance to cybercrime victims. "We deployed five times in the last year and had seven members deployed that were able to help victim recovery efforts," Cavendish said. He noted the unit was enabled by Michigan law in 2017 (amended in 2020), and that volunteers receive technical training to assist local responses.

Committee members asked about federal support and attribution. Cavendish said Michigan works with federal partners, including MS‑ISAC and CISA, but that the state frequently identifies and responds to incidents independently. On attribution to nation‑state actors, Hoffman said Russia, China, North Korea and Iran are commonly cited but cautioned that firm attribution can be difficult even for specialized incident responders.

The presentation closed with invitations for further engagement: Cavendish and Hoffman provided contact routes for reporting incidents and said they would return to the committee as requested for updates and follow‑up briefings.