Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Maryland DoIT describes cybersecurity expansion, bug‑bounty program and local assistance
Summary
Secretary Katie Savage told the Education, Energy, and the Environment Committee that the Department of Information Technology has increased cybersecurity staff, launched a bug‑bounty program and is deploying 15 information security officers to assist executive branch agencies while piloting local government assessments and remediation.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Secretary Katie Savage told the Education, Energy, and the Environment Committee that Maryland’s Department of Information Technology (DoIT) has expanded cybersecurity capacity at the state and local level and will relaunch a bug‑bounty program to find vulnerabilities before adversaries do.
DoIT has reorganized and added staff in 2024–25 to focus on three lanes of work: DoIT‑managed asset security, statewide cybersecurity solutions for executive agencies, and a local cybersecurity assistance program. "We recently expanded our Google Security and Microsoft Security offerings to be able to provide things like mobile device management," Savage said, describing new services the department has rolled out for agency email and device protection.
DoIT announced several concrete changes intended to address gaps identified in prior assessments. The department has hired 15 information security officers (ISOs) who will be embedded with executive branch agencies to work on remediation from the 2022 security assessments, Savage said. On the local side, DoIT said 35 local units of government have signed up for a security maturity assessment program; DoIT has completed three local assessments so far and has added five state staff to support local remediation work. The department also reported a rotational support arrangement with the Maryland National Guard that places about seven to eight Guard cybersecurity personnel at a time to assist local units.
Savage described the department’s bug‑bounty effort as an innovation carried over from her previous work at the Department of Defense. "We had a successful bug bounty program this summer, and are set to launch the next round of it this spring," she said. The program places public‑facing state assets in scope for vetted security researchers to report vulnerabilities.
Committee members pressed for timetables and scale. Senator Clarence Hester asked whether the biannual statewide assessments were delayed; Savage said an RFP for follow‑on assessment work is in progress and that the department will run remediation in parallel with the onboarding of the 15 ISOs. On local coverage, senators raised outreach and uptake: DoIT told the committee it had partnered with the Maryland Municipal League and Maryland Association of Counties but that the federal/state grant application process limited participation; Savage said DoIT would work with senators and local organizations to boost participation.
DoIT also described identity and access management consolidation as a security and cost priority. Savage said DoIT expanded its Microsoft contract in November to centralize agency Active Directory users into a single state directory, and it has engaged a firm to map a consolidation roadmap. She characterized the program as a multi‑month to year‑long effort: "It's a big lift, but hopefully in this calendar year it's something we can accomplish," she said.
Why it matters: DoIT framed the changes as addressing both security risk and prior project shortcomings noted in audits by increasing hands‑on support, centralizing services such as identity management, and establishing repeatable processes for agency remediation. Local governments, school systems and executive branch agencies were identified as primary beneficiaries of the new staffing and grant activity. The committee’s questions made clear senators expect progress updates on implementation, the timeline to complete identity consolidation, and greater outreach to small municipalities that lack technical staff.
Ending: DoIT asked committee members to help amplify outreach for local cybersecurity grants and said it would follow up with timing on identity consolidation and the RFP schedule for statewide reassessments. The department signaled it would provide more detailed status reports as the ISO placements and local remediation efforts progress.

