Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Public Defender Cybersecurity topic
No spam. Unsubscribe anytime.
State Public Defender seeks cybersecurity funding after malware incident, aims to qualify for insurance
Summary
The Office of the State Public Defender reported a malware incident in February that forced a multiweek recovery; the office asked the Joint Budget Committee for supplemental funding to implement security controls and to meet cybersecurity-insurance requirements.
Get email alerts on the Public Defender Cybersecurity topic
No spam. Unsubscribe anytime.
Megan Ring, the state public defender, told the Joint Budget Committee the office experienced a malware event in February that forced extended recovery and heavy use of outside forensic experts and support from risk management and the Office of Information Technology. Ring said the office was told initially it might be down "for months" but was largely back in operation in closer to two months with staff working long hours to restore operations.
Ring said the event underlined the constitutional importance of continued functioning for an office that represents an estimated 80% of defendants in Colorado criminal cases; the public defender’s office asked the JBC to approve a supplemental to implement security recommendations, acquire controls, and help the office qualify for cybersecurity insurance. "What we were told was it is a when it's gonna happen, not if it's gonna happen," Ring said.
Kyle Hughes, the office’s chief information officer, told the committee the spending authority requested would cover software licenses, security services, and other items that are largely one-time procurement costs with ongoing license fees. The office acknowledged much of the immediate response and recovery costs were borne by risk management and said the supplemental would shift the focus from recovery to prevention and insurability. Hughes said the requested tools are intended to close audit-identified gaps and satisfy insurer requirements so the office can obtain a policy.
Committee members asked how the cybersecurity request should be prioritized among other SPD budget items. Ring and staff said they were balancing a large IT storage request tied to discovery workflows and the cybersecurity funding; they described the security request as critical to prevent another disruptive event and to reduce future recovery costs to risk management and the state.
The committee did not vote on the SPD cybersecurity comeback during the Jan. 27 comebacks hearing and asked the office and staff for further prioritization and cost details as the committee completes supplemental figure setting.
