Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Sen. Talo Tadegree and OTEC outline $6.87M modernization plan to strengthen Guam’s cybersecurity

Committee on Economic Investment, Military Buildup, Regional Relations, Technology, Regulatory Affairs, Justice Election, and Retirement · May 27, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At a May 27 oversight hearing, the Office of Technology (OTEC) sought roughly $6.87 million for 2027 to centralize IT governance, fund an IBM upgrade, bolster backups and subscriptions, establish a 24/7 security operations capability (likely outsourced), and build cyber workforce pipelines; lawmakers urged faster emergency procurement authority and a safer data-center location.

Chairwoman Sen. Talo Tadegree convened an oversight hearing on May 27 to review modernization and cybersecurity needs at the Office of Technology (OTEC), hearing a presentation from acting chief technology officer Bea Santos and senior OTEC staff on an approximately $6,870,000 2027 budget request and a multi-phase plan to harden Guam’s digital infrastructure.

OTEC told the committee the office was created by Public Law 34-75 (October 2018) and later implementing material described under Public Law 34-76; its statutory mandate is to centralize IT authority and coordinate infrastructure across executive branch line agencies. "When OTEC experiences an outage or suffers from a cyber attack, the impact ripples across the government agencies and immediately is felt by our people," Chairwoman Tadegree said, arguing the territory must invest to attract and keep cyber talent.

Bea Santos, who identified herself as OTEC’s IT manager and acting chief technology officer, described the agency’s recommendations: creation of a Digital Transformation Council to prioritize strategic IT initiatives; an IT-as-a-service operational model with central purchasing for enterprise network hardware; enterprise backup hardware; unified APIs and data-governance standards; and oversight for ethical AI use. Santos said OTEC currently supports roughly 350 virtual servers across about 25 physical servers and serves roughly 3,000 users.

Santos also laid out cybersecurity priorities after two recent incidents, including a widely visible website defacement reported April 29–30. She told the committee that to their knowledge no sensitive government data were stolen in the event, that a vendor applied a cPanel fix from a vendor and found backups that restored most sites, and that OTEC did not pay any ransom. "The good news is that there's no connection to our Government of Guam data," Santos said, adding that some sensitive live systems remain on legacy Power7 hardware that is end of life.

OTEC identified specific capital and recurring costs in its 2027 proposal: a roughly $500,000 request to upgrade an IBM Power7 to Power11 that currently hosts public-health applications and other mission systems; continuing subscriptions for Google Workspace and Microsoft 365 that together cover about 3,000 users; an enterprise backup refresh; and recurring VMware subscription licensing for virtual-server management. In OTEC’s breakdown, about 49% of the $6.87 million request is for personnel, 32% for contractual services, 12% for capital outlay and 7% for network utilities and travel.

Committee members sought technical clarification and operational detail. Jerry Calvo, an OTEC systems administrator introduced by Santos, explained that OTEC’s physical servers host multiple virtual machines that collectively support file servers and applications for many departments. Calvo said the virtual environment includes roughly 350 virtual servers and serves about 3,000 users across agencies.

Lawmakers pressed OTEC on procurement and response timelines. Santos recommended an agile procurement approach, using group-purchasing vehicles such as NASPO or the GSA and a prequalified vendor roster for cyber emergencies, and she suggested outsourcing a 24/7 managed SOC as a quicker route than standing up an in-house center. "We do not have dedicated cybersecurity personnel at the moment," Santos said; OTEC currently employs 21 people, about 16 in technical roles, and handles approximately 7,000–8,000 help-desk tickets per year.

Several senators urged giving OTEC clearer, faster procurement authority so the agency can patch or bring in responders within hours of a cyber incident rather than wait weeks for procurement processes. Sen. Wright proposed drafting legislation that would allow OTEC or a designated authority to declare a cyber emergency and trigger expedited procurement; committee members agreed to work together on options.

Members also raised facility and resilience concerns. Chairwoman Tadegree and others said OTEC’s primary data center is in a building in a flood-prone area with aging infrastructure and reported generator failures during past storms. "The data center is on the first floor," a member said; Santos acknowledged the risk and said OTEC is exploring alternative locations and will update the committee before budget enactment.

On AI and vendor risk, OTEC staff warned against unvetted contracts and use of consumer AI services that could expose government data. Santos said enterprise agreements with Google and Microsoft restrict AI model training on government data and that some consumer AI applications are blocked on the government domain. Michael Ford, an OTEC systems programmer, urged agencies to "read the fine print" in vendor policies after OTEC found one app that recorded IP addresses and shared input data with affiliates and subsequently blocked it.

Next steps described at the hearing included OTEC finalizing job descriptions and submitting them to DOA for new cyber positions, working with the legislature on procurement authorities and potential legislative fast-track options for creating positions, continuing discussions with federal partners (including FBI, CISA and the National Guard) for incident support, and pursuing campus partnerships (University of Guam, Guam Community College) for internships and cyber residency pipelines.

The oversight hearing concluded with Chairwoman Tadegree thanking OTEC staff and instructing members and the administration to pursue facility and procurement fixes before finalizing the FY2027 budget. The committee adjourned around 11:17 a.m.