Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Vulnerability Remediation topic
No spam. Unsubscribe anytime.
N.D. IT agency seeks $3 million ongoing for code-scanning tool after large vulnerability run
Summary
North Dakota Information Technology (NDIT) told a Senate committee that last biennium—unding reduced thousands of vulnerabilities but advocates ongoing investment, including a $3 million ongoing request to deploy Static Application Security Testing (SAST) to catch application code flaws earlier.
Get email alerts on the Cybersecurity Vulnerability Remediation topic
No spam. Unsubscribe anytime.
NDIT officials told the Senate appropriations committee that a mix of staffing, process and technology investments funded last biennium reduced a large backlog of vulnerabilities but that application security remains a persistent, growing challenge.
"Last year our teams were able to patch 596,000 system vulnerabilities, and in addition to that, we also remediated 326 application vulnerabilities," Chris Gergen, Director of Cyber Operations at North Dakota Information Technology, said in testimony. He said application fixes require code changes, testing and quality assurance and therefore take far more developer time than system patching.
The agency reminded lawmakers that the 2023 biennium included a $1 million appropriation for vulnerability reduction. NDIT used that money across people, process and technology: contractors to remediate agency applications, a Guidehouse consulting engagement to redesign vulnerability management, and tools to speed patching. Gergen said the state still faces an accelerating stream of new vulnerabilities (he cited more than 40,000 unique vulnerabilities published in 2024) and difficulties remediating problems that affect legacy, unsupported technology.
NDIT asked the committee for an ongoing $3,000,000 appropriation to license a Static Application Security Testing (SAST) platform and related operational costs. Gergen described SAST as a tool that scans code during development so developers can fix security defects before code reaches production; he said NDIT developers spent more than 35,100 hours in 2024 remediating application vulnerabilities and that SAST would reduce that reactive workload.
Senators asked clarifying questions about whether the $3 million would be a one-time purchase or an ongoing subscription and whether costs would be borne in NDIT rates (chargebacks). Deputy CIO Greg Hoffman said the $3 million request is for subscription-based toolsets and is entered as ongoing funding; the cost would be included in application-development chargeback rates rather than an added general-fund payroll cost. Hoffman and others also acknowledged the difficulty of quantifying precisely how much staff time a given tool would reduce.
Gergen and other NDIT staff described complementary process work: Guidehouse led a multi-phase redesign of vulnerability management, including automating risk-based prioritization, establishing a Cyber Risk Review Board for critical exceptions, and piloting the program with the Bank of North Dakota. NDIT said those process changes plus SAST would reduce incident response burden and lower the risk and cost of reactive breaches. Gergen noted the operational cost of incidents: his team averages about 50,000 cybersecurity events per year and cited Log4j remediation as an example that required 27 weeks of dedicated effort.
The testimony emphasized that some agencies lack funds to replace aging servers and applications, which makes remediation harder. When asked whether NDIT's services duplicate private security products, Gergen said some protection (automatic updates, endpoint tools) overlaps with vendor products but the state's work includes coordination, configuration changes and enterprise-scale prioritization that private tools alone do not address.
The committee did not take a vote during the hearing. The requests and program descriptions will be considered as part of the budget process.
Ending: NDIT framed the SAST request and the Guidehouse-driven process improvements as proactive measures intended to reduce the frequency and severity of incidents and to shift developer time from reactive fixes toward new work.
