Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Committee hears bill to move Nevada cyber‑defense office to governor’s CIO and combine cybersecurity functions
Summary
Carson City — The Senate Committee on Government Affairs heard Senate Bill 467, which would transfer Nevada’s Office of Cyber Defense Coordination from the Department of Public Safety to the Office of the Chief Information Officer and merge it with the Office of Information Security.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Carson City — The Senate Committee on Government Affairs heard Senate Bill 467, which would transfer Nevada’s Office of Cyber Defense Coordination from the Department of Public Safety to the Office of the Chief Information Officer and merge it with the Office of Information Security to form a single Office of Information Security and Cyber Defense.
Timothy Galuzzi, State Chief Information Officer, introduced the bill as enabling legislation for an already approved budget decision unit. Galuzzi said the text largely carries forward existing statutory language for the Office of Cyber Defense Coordination in NRS and makes conforming changes to place the office within the OCIO. "This legislation solves that and creates a cohesive cybersecurity unit to enhance collaboration and communication with the Executive Branch and externally as cyber threats do not stop at our boundaries," he told the committee.
Galuzzi described functional differences between the two entities: the Office of Information Security (OIS) has historically focused inward, supporting executive‑branch agencies, while OCDC has focused on external coordination with municipal and county partners. The bill would merge the two offices, establish leadership and rulemaking authority for the new office, require a public strategic plan and incident‑reporting provisions, and repeal duplicative provisions from NRS chapter 480 that currently govern OCDC.
Committee members probed provisions that reference private entities and public‑private partnerships. Senator Neal asked what private entities the bill envisions working on strategic planning; Galuzzi said the language is intended to enable advisory relationships with private vendors and industry partners that provide cybersecurity consulting, research and advisory services, and to allow the state to learn from better‑resourced private actors such as the gaming industry. He emphasized the bill is not intended to mandate private investment or to prescribe which investments entities must make. "There is no intent in section 13 … to prescribe the investments that entities may make," Galuzzi said.
Senator James Daly sought clarification that the bill’s reference to public‑private partnerships does not imply revenue‑backed PPPs (for example, a private partner paid back over time). Galuzzi agreed and said the provision is intended to permit vendor relationships and advisory partnerships rather than long‑term revenue contracts.
Speakers from local government and business testified in support. Randy Robinson, director of government affairs for the City of Las Vegas, said the state should centralize cybersecurity coordination to improve defensive posture and information sharing with local jurisdictions and the private sector. "We were particularly concerned … that when the state makes recommendations for investments, that it is vendor neutral," Robinson said, urging vendor neutrality in guidance. Nick Schneider, director of government affairs for the Vegas Chamber, also voiced the Chamber’s support for SB 467.
No callers testified in opposition or neutral on the phone line. The committee closed the hearing on SB 467 without taking a vote during this session.
If enacted, SB 467 would combine the existing enterprise services of the OCIO with the externally focused coordination functions of OCDC to create a single office intended to reduce overlap, centralize rulemaking, and publish statewide cybersecurity guidance and incident‑reporting requirements.

