Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
State IT chief outlines AI guardrails, 24/7 security operations and data governance push
Summary
Jeff Maxson told the Joint Committee on Information Technology that the executive branch has stood up a 24/7 Security Operations Center, deployed endpoint detection across thousands of devices and adopted an AI acceptable-use policy requiring human review and vendor disclosure; a formal cyber maturity program and data governance standards will follow under HB 2574.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Jeff Maxson, chief information technology officer for the executive branch, told the Joint Committee on Information Technology that the state is focusing on enterprise visibility and incident prevention after recent legislative changes.
"We have have almost 18,000 endpoints in terms of users across executive branch, give or take, and then about 3,000 servers on top of that," Maxson said, describing the scope of systems the Office of Information Technology Services (OITS) now monitors from a 24/7 Security Operations Center. He said enterprise tools include endpoint detection and response for real-time containment and an endpoint-management tool to accelerate patching and aggregate agency reporting.
Maxson also described an executive-branch artificial-intelligence acceptable-use policy intended to keep a human reviewer in the decision loop. "Humans have to review whatever is produced, whether that is using it for cogeneration, using it for a summarization of a report that is turned into some other summary that is shared amongst staff," he said. The policy requires contractors to disclose AI use and forbids vendors from using state information to train private models outside state purposes.
Officials said the state will follow HB 2574'mandated maturity reporting next calendar year: OITS will measure agency maturity levels and report to legislative oversight committees. Maxson emphasized that data governance (defining ownership, standardizing formats and limiting retained data) is a prerequisite to safe AI adoption and better cross-agency interoperability.
Committee members asked how OITS will measure realized savings from enterprise procurements and how mandates or opt-in models would be enforced; Maxson said platforms are offered as a "fast path" rather than a forced mandate and that projected savings were based on comparing current agency spend against enterprise contract pricing.
AI generated
The text on this page is AI generated. Summaries, highlights, analysis, and video transcripts are all produced from the original source material.
AI can make mistakes, so if you spot one, and we will fix it for everyone.
Note: the source content is unaltered by us. Any content source we link to, be it a video, an audio recording, or a document, is presented exactly as its publisher released it. That publisher is usually a government body, sometimes an individual official or another organisation.

