Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the State Cybersecurity topic
No spam. Unsubscribe anytime.
Committee hearing on HB 2574 centers on how to enforce and fund state cybersecurity standards
Summary
Lawmakers heard testimony on House Bill 2574, which would continue and reshape 2024 cybersecurity reforms by removing some statutorily fixed maturity targets, creating a judicial technology oversight council, strengthening executive CISO authority, and adding legislative accountability through reporting to budget committees; concerns focused on audit clarity, funding and KPERS carve-outs.
Get email alerts on the State Cybersecurity topic
No spam. Unsubscribe anytime.
A legislative committee held a hearing on House Bill 2574 on Feb. 25 to consider extending and revising 2024 cybersecurity reforms and to set how state agencies will be assessed and held to account.
The bill, introduced by the reviser’s office, would remove statutory expiration dates on parts of 2024’s Senate Bill 291, create a Judicial Branch Technology Oversight Council and change how chief information security officers (CISOs) and cybersecurity programs are assessed, reported and audited. The committee heard proponents, neutral testimony from the legislative post audit office and questions from multiple representatives about funding, audit frequency and the limits of legislative authority.
"House bill 25 74 removes the expiration on certain cybersecurity requirements that you put in place as the chair indicated in Senate Bill 2 91 in 2024," the reviser said, summarizing the bill’s principal aim to preserve and refine elements of SB 291. The reviser added the bill would "require assessment of each executive branch agency with compliance with their cybersecurity requirements" and "create the judicial branch technology oversight council."
Representative Kyle Hoffman, who led the Joint Committee on Information Technology last year, urged flexibility in statutory language. He told the committee that fixed maturity tiers based on NIST could be overly prescriptive for some agencies, saying the bill should allow agencies and CISOs to set appropriate targets: "Those three and four might not be the right maturity tiers for all agencies across the state." Hoffman also recommended creating a formal legislative technology oversight committee to mirror the bill’s new judicial council.
Jeff Maxson, the executive branch chief information technology officer, testified in support of HB 2574 and emphasized continuity of consolidation and oversight. Maxson noted prior appropriations and budgeting: "Senate Bill 291 also did appropriate an amount of $15,000,000 for the security office," and said the administration has included funds in the base budget to continue the work. He counseled a hybrid audit model, recommending a mix of internal assessments and third-party audits to manage cost and capacity.
The legislative post audit office flagged several issues in neutral testimony delivered by IT audit manager Catherine Osterhaus. She said the bill’s current language appears to shift audits to program-level reviews rather than agency compliance checks, lacks defined frequencies for those evaluations and may expose sensitive findings by not specifying confidentiality protections. "That ambiguity may lead to inconsistent interpretations and audit schedules across the state," Osterhaus said.
KPERS raised a separate concern. Alan Connery, speaking for the retirement system, said KPERS already maintains cybersecurity staff and reported a draft assessment finding the system roughly "80% NIST compliance." He asked for clarification of a carve-out in section 11 and cautioned against language in section 15 that he said could allow KPERS-funded cybersecurity staff to be reassigned: "Because of that fiduciary responsibility, they have a high level of responsibility ... the trust fund can only be used for the direct benefit of KPERS," Connery said.
A notable enforcement mechanism in HB 2574 would require the executive branch CSO to report agencies that are not making progress to the legislative budget committee starting in October 2028; during the budget process the committee could consider lapsing 10% of an agency’s IT spend for continued noncompliance. Supporters said the October pre-session notification is intended to give agencies time to correct deficiencies before any budget penalty is considered.
Lawmakers asked practical questions about implementation costs, staffing and audit cadence. Witnesses said the scale of audits could vary widely — Maxson estimated large third-party audits might range from about $100,000 to $500,000 per engagement — and that a staggered schedule and prioritized risk list would be needed. The bill also removes a prior requirement that agencies achieve specific maturity scores by fixed dates and instead emphasizes reporting on maturity levels and corrective-action plans.
The committee took no formal vote on HB 2574. It approved meeting minutes earlier in the session by motion of Representative Simmons, seconded by Representative Howerton, and then closed the hearing on HB 2574 with committee leaders saying they would continue work in a follow-up meeting scheduled for next Wednesday.
Next steps: the committee will reconvene to work the bill, with staff and the reviser’s office expected to draft amendment language addressing audit clarity, confidentiality protections and funding implications.

