Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Minnesota cybersecurity commission hears MNIT on rising threats, GovRamp and LoginMN; members consider extending commission
Summary
Members of the Legislative Commission on Cybersecurity discussed priorities for the 2026 session — including extending the commission’s sunset or creating a standing committee — and heard Minnesota IT Services present statewide threat metrics, MS-ISAC membership shifts, GovRamp vendor requirements and LoginMN deployment timelines.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Members of the Legislative Commission on Cybersecurity met Oct. 27 to outline legislative priorities for the 2026 session and to hear Minnesota IT Services (MNIT) present updated threat metrics and planned security programs.
The commission’s chair opened the meeting, confirmed a quorum and asked members to raise priorities they plan to pursue in the coming session. Representative Bonner called attention to a bill on state and local cybersecurity grants and urged making it a top priority following cyber incidents in Saint Paul that triggered National Guard support and emergency powers. Several members urged the commission to extend or remove the panel’s current statutory sunset (the commission expires 12/31/2028) so oversight and coordination can continue.
"We do very likely, if we want to continue to do this good work, need to extend our expiration date," Representative Bonner said, urging at least a four-year extension and offering to start a drafting request.
Senator Lucero and others argued that technology, data privacy and cybersecurity have grown into cross-cutting topics on par with transportation and education and suggested creating a permanent standing committee or subcommittee. Senator Kuran and other members noted existing assets — the Tactical Advisory Council, subcommittees and the commission’s ability to hold closed sessions — and proposed a third path that preserves the commission’s sensitive-session authority while creating additional standing legislative capacity.
MNIT commissioner Tarek Toombs and state chief information security officer John Israel then presented the agency’s view of the state’s cybersecurity posture and planned initiatives. Toombs described ransomware as an ongoing risk and highlighted MNIT’s managed detection and response (MDR) metrics.
"Over the past 12 months, Minnesota's managed detection and response capabilities detected over 222,000,000 events that triggered 650,000 automated investigations," John Israel said, attributing those numbers to MNIT monitoring of participating entities. He added that roughly 107,000 events had the potential to affect government services and that MNIT estimates prevented incidents represented almost $300 million in avoided costs.
Israel also outlined changes in federal partner resources and national information-sharing structures: staffing from the Cybersecurity and Infrastructure Security Agency (CISA) assigned to Minnesota has decreased, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) has shifted from a free model to membership fees effective Oct. 1. He said Minnesota is evaluating models that range from entity-by-entity membership (fees scaled to an entity’s noncapital budget) to a state-level buy-in that would cover many entities on behalf of the state.
Toombs described MNIT’s GovRamp partnership to raise vendor risk-management standards and said MNIT will require GovRamp compliance clauses in new state cloud contracts that handle "high" categorized data, with a compliance date for existing contracts of April 1, 2027. He also introduced LoginMN, the state's constituent identity and access-management platform, which MNIT expects to expand to many public-facing services and which will use adaptive AI capabilities and identity-proofing standards (including NIST identity assurance level 2 for higher-sensitivity services).
Members pressed MNIT on implementation details: what ‘‘high’’ categorized data covers (Toombs/Israel said it generally means the most sensitive records, such as Social Security numbers and PII), how LoginMN will integrate with the Paid Family and Medical Leave rollout, and what options exist for residents without digital access. MNIT said PFML will be among the largest applications joining LoginMN and that the agency is working with counties and partners to accommodate non-digital access needs.
On MS-ISAC fees, Israel described a range of entity-level bands (previously roughly $995–$17,000 per entity before changes in federal funding) and said a state-only model to cover executive-branch entities would cost Minnesota about $190,000 per year; an earlier whole-of-state model was estimated at about $795,000 but officials said those figures shifted after federal funding changes.
The chair closed the meeting by asking staff to gather more information on commission extension options, to arrange follow-up briefings (including a planned presentation by National Guard cyber units), and to circulate a topics list for a near-term meeting before the 2026 session. The commission adjourned with no formal votes on bills reported during the meeting.
Next steps: staff will research legal and drafting implications of removing or extending the commission’s sunset, MNIT will continue LoginMN onboarding and report timelines for key agency migrations, and members signaled intent to consider letters to legislative leaders encouraging permanent committee structures.

