Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Information Technology topic
No spam. Unsubscribe anytime.
DoIT's FY26 request elevates IT investment fund use and cybersecurity; DLS flags project oversight and an ITIF balance discrepancy
Summary
DoIT asked for a FY26 increase driven by ITIF projects; DLS flagged oversight and a large ITIF balance discrepancy.
Get email alerts on the Information Technology topic
No spam. Unsubscribe anytime.
The Department of Information Technology (DoIT) presented its fiscal 2026 budget to the House Appropriations Committee Transportation and the Environment Subcommittee; the department’s requested operating allowance increases $65.9 million (20.3%), much of which is budgeted to the Information Technology Investment Fund (ITIF). DLS analysts and DoIT officials clashed over project oversight, the timing and size of fund balances in ITIF and the new expedited‑project category.
DLS concerns: ITIF balances and oversight DLS analyst Yashoda Rai told the committee the fiscal 2026 allowance adds roughly $67.6 million to the ITIF, and pointed to a large discrepancy between the governor’s projected year‑end ITIF balances and DLS’s internal calculations. DLS calculated multihundred‑million‑dollar balances remaining in the ITIF at the end of FY25 and FY26; the governor’s budget book projected a smaller end‑of‑year balance (DLS reported the governor’s FY25 projected fund balance as about $17,000 and zero in FY26). DLS asked DoIT to explain timing assumptions and the expected schedule for disbursing existing fund balances against project spend plans.
Expedited projects and proposed BRFAA language DoIT’s FY26 request contains a new expedited‑project category and the governor’s budget would move the 20% statutory set‑aside for expedited projects. The administration’s BRFAA language would repeal the required 20% set‑aside and the budget bill included contingent language reducing the FY26 expedited appropriation by $13.8 million if that repeal takes effect. DLS recommended deleting the $28.8 million general fund amount for expedited projects and asked the subcommittee to require a report and clearer criteria before funding the category.
Cybersecurity, audit findings and AI DoIT acknowledged a 2024 Office of Legislative Audits (OLA) compliance report that included 16 findings for the period reviewed; four findings were repeat findings and four redacted findings related to cybersecurity. DoIT described remediation work underway, noted a planned cyber RFP to cover assessments and remediation, and said some cyber‑related contracts previously used would be reprocured. DoIT also described progress on state cybersecurity programs: the Office of Security Management (OSM) has onboarded 15 agency information security officers, initiated a “Hack the State” bug‑bounty program and expanded local‑government cybersecurity assistance to 35 jurisdictions.
AI governance and enterprise services DoIT described work under the state AI Governance Act (Chapter 496 of 2024) and the governor’s AI subcabinet: interim generative‑AI guidance was published March 9, 2024; an AI roadmap and pilot work are underway. DoIT said it created a Maryland Digital Service team to improve digital accessibility, produce plain‑language content and modernize web services; the department also consolidated the state chief data officer and data/GIS teams into an Office of Enterprise Data to improve data governance and access.
Why it matters The ITIF funds major systems projects for multiple agencies and DoIT’s decisions about which projects to fund affect long‑running modernization efforts, cybersecurity posture and operating costs across state government. DLS emphasized that stronger project oversight, clearer expedited‑project criteria and transparent fund‑balance accounting are necessary to reduce cost overruns and delays.
Speakers and sources - Yashoda Rai (DLS), fiscal 2026 analyst for DoIT, presented the DLS analysis and asked for clarifications on ITIF timing and expedited projects. - Melissa Lehman, Acting Secretary, Department of Information Technology, described organizational changes, cybersecurity investments and the Maryland Digital Service. - Lance Cleghorn, State Director of Cybersecurity (DoIT), described OSM accomplishments, local‑government onboarding and identity/access management work.
Clarifying details - DLS reported DoIT’s fiscal 2026 request increases ITIF funding substantially; the budget book shows an ITIF share of the FY26 allowance of roughly 37%. - DLS reported and requested explanation for a discrepancy between its calculated ITIF unobligated balances (hundreds of millions in DLS calculations) and the governor’s projected small or zero balances in the budget book; DoIT said the budgets reflect in‑flight transfers and agency spend plans and agreed to provide timing detail. - DLS recommended deleting $28.8 million in general fund ITIF money for expedited projects until the committee receives defined criteria and a report.
Audit follow‑up and staffing DoIT said it has hired 46 employees since early 2024 and expects to onboard another 39 by the end of the fiscal year. DoIT also requested a CISO and reported three recent interviews for the chief information security officer role; staff said they expect to fill the CISO role soon. DLS recommended deleting two DoIT positions that had been vacant for more than a year as a technical reduction.
Provenance and next steps DLS requested agency responses clarifying the ITIF invoicing and spend plan timing and asked for a report defining expedited‑project criteria. The OLA audit remains a workstream; DoIT said remediation is in progress and that it expects to complete scheduled remediation actions by July 2025.
Ending The subcommittee asked DoIT for precise reconciliations of ITIF balances and clearer criteria and reporting for expedited projects before releasing additional general funds for new IT investments. DoIT agreed to provide the requested documentation and to continue remediation work identified in the audit.
proper_names [{"name":"Department of Information Technology","type":"agency"},{"name":"Information Technology Investment Fund","type":"other"},{"name":"Office of Legislative Audits","type":"agency"},{"name":"Maryland Digital Service","type":"program"},{"name":"Office of Security Management","type":"program"}]
clarifying_details [{"category":"fiscal_change","detail":"DoIT FY26 allowance increase","value":"65,900,000","units":"USD","approximate":true,"source_speaker":"Yashoda Rai"},{"category":"itif_share","detail":"ITIF share of FY26 allowance","value":"37","units":"percent","approximate":true,"source_speaker":"Yashoda Rai"},{"category":"expedited_project_request","detail":"Governor's FY26 expedited projects appropriation","value":"28,800,000","units":"USD","approximate":true,"source_speaker":"Yashoda Rai"},{"category":"dls_recommended_reduction","detail":"DLS recommended deletion of expedited projects funding until criteria defined","value":"28,800,000","units":"USD","approximate":true,"source_speaker":"Yashoda Rai"},{"category":"cyber_remediation_cost_estimate","detail":"DNR/DoIT estimated cost to implement cyber remediations from maturity assessment","value":"22,700,000","units":"USD","approximate":true,"source_speaker":"Yashoda Rai"}]
speakers [{"name":"Yashoda Rai","role_title":"Budget Analyst, DoIT (DLS)","affiliation_type":"government","affiliation_name":"Department of Legislative Services","first_reference":{"timecode":"02:06:00","transcript_line_range":[1,6]}},{"name":"Melissa Lehman","role_title":"Acting Secretary, Department of Information Technology","affiliation_type":"government","affiliation_name":"Department of Information Technology","first_reference":{"timecode":"02:20:15","transcript_line_range":[1,4]}},{"name":"Lance Cleghorn","role_title":"State Director of Cybersecurity (DoIT)","affiliation_type":"government","affiliation_name":"Department of Information Technology","first_reference":{"timecode":"02:20:30","transcript_line_range":[1,2]}},{"name":"Marcy Jacobs","role_title":"Deputy Secretary & Digital Experience Officer (DoIT)","affiliation_type":"government","affiliation_name":"Department of Information Technology","first_reference":{"timecode":"02:20:30","transcript_line_range":[2,3]}}]
authorities [{"type":"other","name":"AI Governance Act","citation":"Chapter 496 of 2024 (AI Governance Act)","referenced_by":["doit-itif-cyber-ai-oversight"]},{"type":"other","name":"Oversight commission (chapter 243 of 2022)","citation":"Chapter 243 of 2022 (modernized oversight commission referenced by DLS)","referenced_by":["doit-itif-cyber-ai-oversight"]},{"type":"other","name":"Information Technology Investment Fund (ITIF)","citation":"State ITIF holdings and statute governing major IT project funding","referenced_by":["doit-itif-cyber-ai-oversight"]}]
actions [{"kind":"other","identifiers":{"agenda_item_id":"DOIT_ITIF_EXPEDITED"},"motion":"BRFAA provision to repeal the required 20% set‑aside of ITIF for expedited projects and associated contingent reduction to the FY26 expedited appropriation; DLS recommended deleting the FY26 expedited appropriation ($28.8M) until criteria and reporting are established.","mover":"Administration (BRFAA)","second":"not specified","vote_record":[],"tally":{"yes":0,"no":0,"abstain":0,"absent":0,"recused":0},"legal_threshold":{"met":false,"notes":"No committee vote taken during hearing; DLS proposed deletion."},"outcome":"no_action","notes":"Committee requested criteria and timing details before funding expedited projects."}]
provenance {"transcript_segments":[{"block_id":"block_188","local_start":0,"local_end":320,"evidence_excerpt":"Thank you, madam chair and committee members. I am Yashoda Arai and I'll be presenting the fiscal 26 budget analysis for the Department of Information Technology or DOIT. The cover chart on page 1 shows that DOIT's fiscal 26 budget increases by $65,900,000 or 20.3%.","global_start":7557385,"global_end":7597965,"tc_start":"02:06:00","tc_end":"02:06:40","text_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855","reason_code":"topicintro"},{"block_id":"block_255","local_start":0,"local_end":180,"evidence_excerpt":"Thank you, Mr. Stegman. And I believe we do not have any other people here to in closing this part of the hearing. I will say that, I have a lot of confidence in this committee... That closes the DNR hearing and we're gonna move on to MVA now, the Motor Vehicle Administration.","global_start":10047900,"global_end":10070900,"tc_start":"02:47:00","tc_end":"02:47:40","text_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855","reason_code":"topicfinish"}]}
searchable_tags:["DoIT","ITIF","cybersecurity","AI","audit"],
salience:{"overall":0.72,"overall_justification":"Major IT funding and audit findings affect many state projects and cybersecurity posture across agencies.","impact_scope":"regional","impact_scope_justification":"Statewide technological infrastructure and agency operations are affected.","attention_level":"high","attention_level_justification":"Large fund amounts, audit findings and cybersecurity risks are high‑priority topics.

