Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Information Security topic
No spam. Unsubscribe anytime.
CalHFA audit committee hears cybersecurity update; agency reports zero incidents and strong maturity scores
Summary
CalHFA's audit committee received the agency's annual information security update: staff reported zero incidents on CalHFA systems for fiscal year 2023-24, cited state and national cybersecurity maturity benchmarks, and outlined remediation, audits, AI governance and FY24-25 priorities.
Get email alerts on the Information Security topic
No spam. Unsubscribe anytime.
Delilah Sotelo, chair of the California Housing Finance Agency (CalHFA) Audit Committee, opened Tuesday's meeting by introducing the agency's annual information security update and inviting the deputy chief information officer to present.
Puja Deshmukh, deputy chief information officer, said the information security program aims to protect CalHFA's sensitive data and maintain compliance with mandatory state guidance. "We have had 0 information security incidents at, on CalHFA systems in the fiscal year 2324," Deshmukh told the committee, and she added that two external business partners reported breaches that had no direct financial or operational impact to CalHFA and that those partners are undertaking remediation and breach notifications.
Deshmukh outlined a mix of achievements and ongoing remediation: the agency ran 10 phishing campaigns, deployed 15 information-security training modules, and created multiple new or updated policies to address gaps identified by the California Department of Technology (CDT) Office of Information Security (OIS).
On measurement, Deshmukh presented two benchmarks. She said CalHFA received a 2.02 score on the OIS cybersecurity maturity scale (0 to 4) from the state evaluation and reported a 6.36 score on the Nationwide Cybersecurity Review (NCSR) self-assessment (1 to 7). "This is a first-year benchmark for us," she said, and committee members praised those results as strong compared with many peer agencies.
Deshmukh also summarized external assessments and next steps: CalHFA completed its first OIS audit cycle in October 2023, is participating in a CMD (California Military Department) on-premises assessment scheduled for December 2024, and expects preliminary CMD results by February with final results in the second quarter of next year. She said the CalHFA security strategy for FY24-25 includes technology upgrades, vulnerability assessments, ongoing policy work and continued coordination with CDT on threat advisories.
When asked about staffing, Russell (chief information security officer) said the security team is "myself plus 3 full time employees, and we do have 1 student." Committee members pressed on scheduling and implementation details: Deshmukh acknowledged that some projects (for example, a Wi-Fi network upgrade) were late due to equipment delivery delays but said work had started once hardware arrived.
The presentation closed with an FY24-25 action plan and a reminder that the ISO team will monitor weekly threat notifications from CDT; Deshmukh said the next audit committee update is expected in 2025.
The committee opened the floor for public comment; Tina Johnson Hall praised the team's performance in transitioning to the new state audit methodology.
The audit committee did not take a formal vote on policy or procurement actions during the meeting; it approved routine meeting minutes by unanimous consent earlier in the session.

