Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

State consolidates cybersecurity functions, pursuing zero-trust model and insurance risk management

2250972 · February 5, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The state has centralized cybersecurity functions under SITSD and is pursuing a 'zero trust' security architecture. Officials said centralization reduced cyber insurance costs and that small vendors who cannot meet insurance requirements may be accepted through a director-signed assumption-of-risk process.

Kevin Gilbertson and DPHHS staff told the committee that the state consolidated security functions across executive-branch agencies to create full-time security teams, standardize controls and reduce insurance costs.

Gilbertson said the centralization effort started in 2023 and followed agency workshops that inventoried security controls and risks. "We are consolidating all security functions...we are in the process of final workshops and developing a transition plan," he said, adding that centralization helps with federal compliance and makes the state a better cyber‑insurance risk. He said centralized security and organization-wide awareness training helped lower insurance premiums.

On zero trust, Gilbertson explained the approach in plain language: current networks often give broad access once a user is on the state network; "zero trust" means assuming the network is already compromised and validating users and devices for every access. "If you imagine the Capitol Building ... if the front doors are locked and I can get in the front door, then I can get into every single office...zero trust means we trust no one," he said. He also described technical steps: device posture checks, segmentation and multifactor authentication, and said federal agencies are moving toward zero-trust requirements.

Insurance and small vendors: Gilberston said the state typically requires vendors to carry cyber insurance, but there is an exception process. "Some of these small firms can't afford that," he said; in those cases the director can sign an assumption-of-risk form acknowledging the decision to proceed without vendor insurance.

Ending

Lawmakers asked for a written migration plan and cost estimate for zero-trust implementation and for a list of vendors that have insurance requirements and how the state handles exceptions.