Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
State expands cybersecurity operations, training and exercises; security operations center and 0‑trust pilots under way
Summary
Executive branch IT and security leaders described a multi‑pronged cybersecurity push including a 24/7 security operations center, real‑time vulnerability reporting, endpoint management on thousands of devices, privileged access management rollout, large workforce training programs and planned red/blue cyber exercises in August.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Kansas executive branch information security leaders told the Joint Committee on Information Technology they have expanded enterprise cybersecurity capabilities and workforce training while moving toward a more centralized detection and response posture.
John Godfrey, the executive branch chief information security officer, said the state held a cybersecurity summit in Wichita on April 25 that drew about 300 participants and a critical‑infrastructure exchange June 5 with roughly 70 active participants and 90 registrants. Godfrey said federal partners — including the Office of the National Cyber Director and CISA — participated in recent events.
Godfrey and Jeff Maxson reported progress on an enterprise security operations center (SOC) intended to provide 24/7 monitoring, investigation and coordination across executive‑branch agencies. The SOC has started to deploy monitoring tools; the team reported roughly 20,000 endpoints with the state’s agent installed and about 17,000 workstations covered by an enterprise endpoint management solution to speed patching.
State IT leaders described continued rollout of privileged access management (PAM) to control elevated credentials, expansion of automated vulnerability reporting (moving from monthly scans to real‑time reporting), and the use of security interns and reskilling programs that converted six interns to full‑time roles. Godfrey described an ongoing program of training classes, including SANS and local offerings funded by Homeland Security grant dollars and partnerships with TEEX (Texas A&M Engineering Extension). He said the state provides many of those classes at little or no cost to public entities to support rural counties and local governments.
Maxson and Godfrey described a planned two‑week red/blue cyber exercise for late August, funded in part by SGF and ARPA money and run in partnership with the Kansas National Guard. They reported about 70–80 registrations and a target of up to 200 participants and said the exercise will be free to cities, counties, school districts and universities who commit staff time.
Committee members asked whether large events such as the soccer World Cup (Kansas City region) were on the state’s cybersecurity radar; Godfrey said state staff are participating in planning meetings and will continue to coordinate as specific asks arise.
Security leaders told the committee they intend to pilot zero‑trust‑style capabilities (VPN replacement) and web‑content filtering, expand email security protections, add user‑level anti‑ransomware protections and strengthen backup and disaster‑recovery arrangements for higher availability and quicker failover in the event of incidents.

