Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Committee hears cybersecurity assessment and prepares for licensing software migration as current system nears end-of-life

Finance and Risk Management Committee, State Board of Nursing · September 12, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A presenter summarized a cybersecurity assessment and said the agency's 'MyLicense' product will reach end-of-life on June 30, 2027, prompting planning for migration to the 'Evo' platform or possible state consolidation under Senate Bill 291.

The committee heard an overview of a recent LPA cybersecurity assessment and an update on the agency’s licensing software lifecycle. The presenter said the assessment required two rounds of documentation collection—267 items in the first round and 125 in the second, about 392 pieces in total—and that most findings are straightforward fixes.

The presenter cited an out-of-state technology outage (Nevada) that left some licensing services offline for weeks and used it to underscore the operational risk of relying on aging systems. On the licensing side, the presenter said the agency’s current public-facing licensing product (referred to as "MyLicense" or eGov) is scheduled to reach end-of-life on June 30, 2027; the agency is planning to migrate the licensing portion to the Evo automation platform and will need procurement approvals, security and ADA testing, and budget estimates. The presenter also noted Senate Bill 291, included in the packet, which contemplates IT consolidation into a state platform; staff said consolidation could increase concentration-of-risk and they expressed caution about moving agency data into a single state-managed system.

Next steps include reporting the assessment results to the full committee, continuing technical remediation with internal information security staff, and scheduling follow-up to check progress—possibly in six months—after the vendor roadmap and procurement steps proceed.