Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
DoIT outlines expanded cybersecurity program, launches bug-bounty and ISO assignments
Summary
Department of Information Technology Secretary Savage told the House Health and Government Operations Committee that DoIT has added staff and new programs — including a bug-bounty program, a vulnerability disclosure process and 15 information security officers assigned to agencies — to strengthen state and local cybersecurity.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Secretary Savage, head of the Maryland Department of Information Technology (DoIT), told the House Health and Government Operations Committee at its first briefing of the 2025 legislative session that the department has launched several new cybersecurity measures to strengthen state networks and help local governments.
Savage said DoIT is expanding its security operations and identity controls, and has introduced a bug-bounty program and a public vulnerability-disclosure program to surface problems before they become breaches. "A bug bounty is a scoped effort where we ask ethical security researchers to look at our websites and public facing assets and see if they can identify any vulnerabilities," Savage said.
DoIT described three concentric priorities: improving DoIT's internal cybersecurity posture; supporting statewide executive-branch agencies; and offering local governments technical assessments and services. As part of that work, Savage said DoIT has hired 15 information security officers (ISOs) to be assigned to executive-branch agencies to help remediate findings from the 2022 agency assessments and to centralize key protections such as endpoint protection, firewalls and centralized password management.
The department reported it has provided assessments for 35 local units of government under the federal DHS/CISA and FEMA state-and-local cybersecurity grant program and has completed three full local assessments since July. Savage also said DoIT has grown a local cybersecurity team of five (including contractors) and regularly augments the team with National Guard personnel — "at any given time have 7 to 8 National Guard members to augment that team of 5," she said.
Savage told committee members DoIT is exploring ways for counties and municipalities to "piggyback" on state software contracts so localities can adopt proven endpoint-protection or other tools under the state's procurement terms rather than negotiate separate contracts.
Committee members asked about coordination with federal cybersecurity agencies and protections for critical infrastructure. Savage said DoIT maintains regular communications with CISA and regional DHS staff and that DoIT mirrors CISA-recommended prohibited or high-risk vendors in state procurement reviews. She also said DoIT is creating a community-of-practice for utilities and has begun discussions to use grant funds for utility training.
Several delegates pressed DoIT on monitoring and centralization. In response to whether agencies without their own chief information security officers have 24/7 monitoring, Savage said DoIT has centralized a security operations center that receives agency data feeds and is working to ensure critical assets are observable there. She also said her office is upgrading identity and access management so that agency identity services flow through DoIT rather than each agency maintaining separate active directories.
Savage said the department is recruiting a state chief information security officer; in the interim the newly hired chief technology officer, Jason Silva, will serve as acting CISO and DoIT has a director of state cybersecurity on staff.
Nut graf: The department described an approach that mixes central tools (identity, SOC monitoring, procurement) with assigned personnel (15 ISOs) and local assistance (grant-funded assessments and National Guard augmentation). DoIT is also piloting procurement and contractual approaches that would reduce local governments' need to negotiate separate security software contracts.
DoIT provided numerical and program details: 15 ISOs assigned to executive-branch agencies; 35 local units requested assessments under the federal grant program; three full local assessments completed since July; a local cybersecurity team of five (including contractors) supplemented with 7–8 National Guard members; and work to allow counties to piggyback on state contracts. The department is recruiting a permanent state CISO and has expanded its SOC and identity-management investments.
Committee follow-up requests and next steps include: DoIT said it will continue recruiting a permanent state CISO, proceed to launch the vulnerability-disclosure program and bug-bounty scopes, and share inventories of legacy systems and permit/license data (requested by committee members) so legislators can better track modernization needs and risk.
Ending: DoIT framed the changes as a mix of people, process and procurement changes rather than a single fix: stronger centralized identity and monitoring, assigned ISOs to lift smaller agencies, grant-supported local assessments, and new procurement options for jurisdictions that want to adopt state‑negotiated security products.

