Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Judicial It Security topic

No spam. Unsubscribe anytime.

Judicial branch outlines IT and security upgrades, .gov migration under SB291 compliance

2344541 · February 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Judicial branch IT leaders told the Committee on Legislative Modernization they have completed several security and availability upgrades — including endpoint detection, a disaster recovery site and a move to .gov domains — and scheduled a CISA assessment as part of Senate Bill 291 compliance.

Alex Wong, the judicial branch’s chief information technology officer (SITO), told the Committee on Legislative Modernization that the judicial branch implemented a suite of IT and cybersecurity upgrades over the last year and is continuing major projects in 2025.

Wong said the branch has deployed endpoint detection and response tools (CrowdStrike and a related endpoint application referred to as Scribe) across servers and workstations, established a disaster recovery site in Johnson County to complement the Topeka Judicial Center, upgraded its electronic filing system, and completed a migration of public-facing websites and email addresses from kscourt.org to kscourt.gov to meet Senate Bill 291 requirements. He said the migration and email changes were completed in the previous three months.

Why it matters: the measures are intended to reduce the risk of cybersecurity incidents and to meet statutory requirements from 2024’s SB291. Wong said projects underway include upgrades or replacements for the digital evidence management system, jury management system and the public access portal, as well as a refreshed judicial website and internal budget dashboard.

Wong described the branch’s security work as multi‑layered: network segmentation to contain incidents, change-control processes and training, multifactor authentication, vulnerability management, asset intelligence, real‑time network scanning and a separate “air gap” secondary backup system. He said the branch also established standardized security language for procurement contracts and is tracking security spending in a dedicated budget line.

Wong identified two senior hires in the last year: Evan Burt, hired February 2024 as the branch’s chief information security officer (CISO) with roughly 21 years’ experience in cybersecurity incident response, and Wong himself, who joined in November 2021 as SITO and said he had 20 years in state IT roles prior to that. Wong said the SITO (applications, servers and service delivery) and the CISO (networking and security monitoring) operate as complementary checks on each other’s work.

Wong said the branch invited the Cybersecurity and Infrastructure Security Agency (CISA) for an external assessment; the audit was scheduled for the week that included Wednesday through Friday. He closed by standing for committee questions.

Committee members asked clarifying technical questions, including the relation between the disaster‑recovery site and continuity‑of‑operations planning, and whether the CISA audit covers physical security as well as systems; Wong said both are included.

Ending note: Wong and CISO Evan Burt framed the work as ongoing. Several project upgrades remain in procurement or vendor-selection stages, and the CISA assessment was set to begin the week of the committee hearing.