Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity State Programs topic

No spam. Unsubscribe anytime.

New Mexico Office of Cybersecurity outlines FY26 expansion: more scans, playbooks and a push for centralized standards

Science, Technology & Telecommunications · September 23, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Office of Cybersecurity told the Science, Technology & Telecommunications committee it plans to expand attack-surface monitoring and vulnerability services, roll out policy templates based on NIST 800-53, strengthen third-party vendor oversight and seek funding in October to scale backups and incident-response services.

The Office of Cybersecurity (OCS) presented its FY26 priorities to the Science, Technology & Telecommunications committee, outlining a push to expand external monitoring, strengthen incident response and create standardized policies for state and local public entities.

OCS State Chief Information Security Officer Raja Samidam told legislators the office aims to expand participation in services such as attack-surface management and vulnerability management as a service (VMASS), citing a target of roughly 420 participating entities in FY26 that would include state agencies, higher-education institutions, school districts and local governments. "We are increasing our VMASS," Samidam said, noting planned growth from about 118 to 156 VMASS customers.

Samidam and his team described a layered approach: attack-surface monitoring to detect external probes, VMASS and third-party penetration testing to verify vulnerabilities, a hybrid security operations center for active monitoring, and user training as the front line of defense. "We are not interested in the operational business data of any entity," Samidam told the committee, stressing OCS inspects system connections rather than stored business content.

OCS highlighted standardized incident-response templates and ransomware playbooks it has issued to K—612, higher education and local governments. The office said one pressing weakness is inadequate isolated backups; Samidam proposed centralized backup-as-a-service options using state data-center capacity to preserve isolated copies in case of ransomware.

On policy, OCS is developing templates using NIST 800-53 to provide auditable, persistent practices across agencies, Todd Baron (general counsel) said. The templates aim to preserve institutional knowledge when staff leave and to provide minimum control baselines. Samidam added OCS lacks clear authority to mandate AI controls for voluntary participants such as local school systems and tribal entities, a gap the office plans to address through advisory guidance and legislative requests.

Third-party risk management (TPRM) was a prominent theme. Todd Baron and others warned that many critical public services are delivered by private vendors and New Mexico currently has no uniform vendor assurance program. OCS said it is working with consultants and leveraging procurement mechanisms (statewide price agreements, GSA, NASPO) and existing contracts with firms such as Mandiant and Securin to expand vendor assessments and accountability.

OCS also reported accomplishments in data analytics: three years ago the state lacked comprehensive cybersecurity data; now the office collects and reports agency risk profiles using a NIST-based maturity approach to inform oversight and data-driven decisions. Samidam said the judiciary and legislative branches do not currently participate in that dataset.

OCS asked the committee for continued support and pledged to return in October with detailed funding requests and legislative language to shore up authority, procurement details and vendor lists.

The committee pressed OCS on vendor selection, statewide pricing agreements, end-of-life software risks and the feasibility and cost of backups. Samidam cited examples of scale: one vendor supports about 7,000 devices statewide and OCS identified more than 5,000 devices running soon-to-be end-of-life software in the past 30 days. Samidam said Windows 10 end-of-life (October 14) is a pressing source of required upgrades.

OCS said workforce development work is underway (two RFQs using federal and state funds) to perform a needs assessment and create a centralized resource hub for training and retention.

OCS will return in October with FY26 funding asks, procurement details and additional information requested by the committee.