Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Information Security topic
No spam. Unsubscribe anytime.
CalHFA reports no security incidents in 2025, outlines SIEM/SOC and training upgrades
Summary
CalHFA Chief Information Officer Ashish Kumar told the agency’s Audit & Risk Management Committee that the agency had no information security incidents in 2025, has onboarded a security information and event management system with a security operations center, ran 19 phishing campaigns and improved its cybersecurity maturity score to 2.65.
Get email alerts on the Information Security topic
No spam. Unsubscribe anytime.
Ashish Kumar, chief information officer at the California Housing Finance Agency (CalHFA), told the Audit & Risk Management Committee that CalHFA had “no information security incident on CALH based systems during 2025” and outlined technical, organizational and training work intended to reduce enterprise cyber risk.
Kumar said the agency has onboarded a 24/7 security information and event management (SIEM) system and established a security operations center (SOC) to improve detection and response. He described upgrades to data encryption, network segmentation and data‑labeling efforts across cloud and on‑premises environments.
Kumar also described ongoing training and user‑awareness work: “We conducted 19 phishing campaigns, delivered 18 information security modules,” he said, and added that employees who repeatedly fall for simulated phishing receive additional training and reeducation. When committee members asked whether board email addresses were included in exercises, Kumar said he would confirm the details and report back.
On external validation, Kumar said CalHFA completed an information security audit with the California Military Department and that the audit produced no major findings; prior audits had been conducted by third‑party vendors. He said CalHFA has rigorous backup and patch management practices and maintains incident response playbooks supported by external retainers for rapid expert support.
The CIO reported progress on artificial intelligence controls and pilots, stating the agency rolled out Copilot tools and ran a proof of concept for Microsoft 365 Copilot under an acceptable‑use policy introduced in September 2024.
Kumar highlighted measurable gains in the agency’s cybersecurity maturity: CalHFA’s score improved from 2.1 to 2.65, placing the agency above state averages and earning recognition from state technology leadership. “This achievement and formal recognition from state leadership,” Kumar said, referenced commendations from the state’s CIO, Liana Bailey Crimmins, and the state chief information security officer, Vitali Penich.
When asked about funding, Kumar said initiatives have been aligned to the budget and that required funding has been secured but that he did not share a total dollar figure during the meeting and would provide it later. He gave a projected completion date of March 2026 for the SIEM/SOC deployment and clarified that CalHFA is transitioning its disaster‑recovery site from Roseville to a cloud‑backed facility with a physical location in Las Vegas.
The committee praised the information security team’s remediation work and ongoing monitoring. The presentation concluded with Kumar outlining an action plan extending beyond 2026 and a commitment to provide the committee a comprehensive update in fiscal year 2026‑27.
The committee also recorded a motion to approve the minutes from the Sept. 18 meeting; the chair noted the committee’s protocol is to approve minutes when a motion and second are recorded on the record. The meeting adjourned with no public comments.

