Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Information Technology topic

No spam. Unsubscribe anytime.

Committee advances IT and cybersecurity statute updates but preserves Secretary of State’s authority

State and Local Government Committee · March 11, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The committee voted 8–1 to report LD2092 as amended, keeping Secretary of State concerns intact while adding federal GSA purchasing access and an option for the chief information officer to procure retained cybersecurity services for incident response.

The State and Local Government Committee on Tuesday advanced LD2092, a bill to update references and terms in state information technology and cybersecurity statutes, after DAS and the Secretary of State reached a compromise on wording.

Committee staff and the Department of Administrative and Financial Services urged the changes as technical updates and to provide the state statutory authority to participate in federal General Services Administration (GSA) IT purchasing programs and to allow the chief information officer to procure cybersecurity services on a retainer for quicker incident response. “We’re looking to have the appropriate responsiveness by having that ability to procure that specific type of service on retainer,” said Ana Trendy, deputy commissioner for the Department of Administrative and Financial Services.

That retainer approach, Trendy told members, would be executed through a competitive procurement and is intended to reduce emergency costs and improve speed of response during cybersecurity incidents. The markup also standardizes definitions for “cyber attack,” “cyber security” and “information security,” and updates internal references to modern divisions and titles.

The Secretary of State’s office signaled it had worked productively with DAS and that the changes do not alter the office’s constitutional responsibilities. “Our ability to choose the appropriate technologies, cyber security protections for the data with which we are entrusted and required to keep secure … needs to rest with our department,” said Emily Cook, deputy secretary of state and senior policy director, adding that the offices agreed to remove or revise language that raised concerns.

Some members expressed concern about how delegation and procurement authority would operate in practice and whether the chief information officer role is currently filled. Committee staff said the CIO has been serving in an acting capacity for roughly two years and noted the statutory language clarifies delegation to qualified designees within a larger OIT organization.

On a roll-call vote the committee reported the bill out as amended, eight in favor and one opposed (Senator Martin). Staff will circulate final language for review and print the amended bill for future floor action.

The committee also recorded related language edits in the markup and will continue regular oversight of statutory alignment between administrative agencies and constitutionally separate offices.