Video & Transcript Research : 'ransomware'
Page 1 of 7
OK
Oklahoma 2026 Regular Session
Appropriations and Budget Public Safety Subcommittee Apr 8th, 2026 at 04:30 pm
Public Safety
FL
Florida 2026 Regular Session
Appropriations Committee on Agriculture, Environment, and General Government Feb 18th, 2026
Appropriations Committee on Agriculture, Environment, and General Government
Keywords:
payment stablecoin, financial regulation, anti-money laundering, state oversight, digital currency, financial services, Florida lottery, state lottery, lottery tickets, lottery retailer, Department of the Lottery, Division of Security, ball machine, lottery vending machine, instant tickets, online lottery tickets, major procurement, vendor disclosure, performance bond, retailer bond
Summary:
The committee heard and advanced several bills related to engineering regulation, cybersecurity, financial services, and state administration. CS/SB 800 would increase penalties for repeated unlicensed engineering practice and create an engineering student loan assistance program funded by licensure fees and fines; it was reported favorably after questions about whether it would reimburse victims of unlicensed practitioners, with the sponsor noting it would not and that affected individuals would need to pursue complaints and private legal action. CS/SB 576 created a local government cybersecurity protection program administered by Florida Digital Service, with state purchasing of cybersecurity services and priority for fiscally constrained counties; it received support from local government and industry groups and was reported favorably. CS/SB 1078 set transition requirements for gubernatorial administrations, including liaisons, briefing books, office space, IT access, and controlled access to agency records under a memorandum of understanding, and it also passed favorably.
The committee also approved CS/SB 314, which creates a regulatory framework for payment stablecoin issuers in Florida, and CS/SB 530, which updates lottery operations, security, retailer rules, and bonding requirements. CS/SB 1614, after adoption of a technical substitute amendment, would limit local governments’ eligibility for certain state funding if they have excess funds, have recently been audited by the legislative audit committee, or fail to affirm expenditure of prior funds; the sponsor said it would give the Joint Legislative Auditing Committee more enforcement leverage, and the bill was reported favorably. CS/SB 990 authorizes protective cell captive insurance companies to expand insurance market capacity and potentially lower premiums, while CS/SB 1588 is a step toward implementing last session’s gold and silver legal tender law; both were reported favorably.
Additional bills passed included CS/SB 1440, which adds cybersecurity-related exemptions and reporting provisions for financial institutions, loan originators, and money service businesses, and CS/SB 1568, which creates a Florida Stable Coin Pilot Program allowing DFS fees to be paid with approved stablecoins. The stablecoin bill was amended to add guardrails, including fee limits, website notice requirements, and restrictions if no approved issuers are available. The committee also received a brief budget overview highlighting major funding items such as Florida Forever, Everglades restoration, water quality, Farmers Feeding Florida, citrus recovery, school lunches, state parks, and law enforcement and staffing items, and members later recorded additional votes before the committee adjourned.
FL
Transcript Highlights:
- had a major threat when our tax collector had their whole database hacked, and they were held by ransomware
Keywords:
child welfare, negligence, settlement, injury compensation, Department of Children and Families, motorcycle accident, compensation, Department of Transportation, legal claim, autism, autism spectrum disorder, ASD, special education, exceptional student education, ESE, teacher preparation, educator certification, micro-credential, loan forgiveness, student loan repayment
Summary:
The Appropriations Committee met and considered a large agenda of bills, reporting several measures favorably. Early action included SB 6, a settled claim bill involving the Department of Children and Families and the estate of Leila Estrada and Sapphire Williams, which was approved for $3.8 million. The committee also passed a cybersecurity internships bill creating a Department of Commerce program with Cyber Florida, and SB 532, which lets clerks of court retain the full amount of certain excess revenue and clarifies foreclosure-sale procedures. Veterans housing measures, CS for CS for SB 1602 and SB 1604, were approved to create a pilot program and a related trust fund for vacancy relief and risk mitigation for veteran housing. The committee also favorably reported SB 1110 on Medicaid and insurance coverage for orthotics and prosthetics, with emotional testimony from a student and family describing the high cost and importance of activity-specific prosthetics.
Members also approved CS for CS for SB 1012 after adopting an amendment that removed inmate emergency and specialty medical service compensation provisions while retaining changes to the contractor-operated institutions inmate welfare trust fund. Another bill, CS for CS for SB 1614, was narrowed by a delete-all amendment to focus on limiting the use of excess fees for new building construction by local governments. All of these measures were reported favorably after brief debate, with some support testimony submitted in writing or waived.
The most extensive discussion centered on CS for CS for SB 17, a major Medicaid and public assistance overhaul. The bill would create a Joint Legislative Committee on Medicaid Oversight, allow the Legislature to retain its own actuary, tighten Medicaid program oversight, update encounter-data reporting, set performance standards for managed care plans, revise pharmacy benefit manager rules, and require DCF to implement SNAP fraud-reduction and payment-accuracy reforms, including photo IDs on EBT cards and updated work requirements. It also would direct agencies to seek federal waivers for Medicaid work requirements for able-bodied adults and expanded behavioral health services. After lengthy questioning and testimony, the committee adopted amendments adding a transitional medical benefits glide path for people who gain employment and later lose Medicaid eligibility, and exempting hospice patients with six months or less to live. Supporters argued the bill would improve accountability, reduce fraud, and save money, while opponents warned it would create administrative burdens, increase paperwork, and cause eligible people to lose coverage or food assistance. The committee ultimately reported the bill favorably as amended.
FL
Florida 2026 Regular Session
Governmental Oversight and Accountability Feb 11th, 2026
Governmental Oversight and Accountability
Keywords:
public records, public meetings, property rights, transcripts, settlement negotiations, Veterans Day, K-12 schools, holiday observance, education, Florida statutes, cybersecurity, local government, grant program, data-sharing, Florida Digital Service, ransomware protection, county administrators, city managers, exemption, privacy
Summary:
The committee first heard a committee substitute for SB 332, which creates a narrow public meetings and public records exemption for certain pre-suit settlement communications in Bert Harris claims involving local governments and private property rights. The sponsor said the change is intended to allow confidential legal strategy and negotiation during the 90-day pre-suit period while keeping settlements and outcomes public. The strike-all amendment was adopted, supportive testimony was waived in, and the bill was reported favorably.
Members then approved several other measures, including SB 464 requiring K-12 schools to formally observe Veterans Day as a school holiday; SB 984 on firefighter cancer benefits and prevention, which was amended to add a statement of important state interest and reported favorably after testimony from firefighters both supporting the bill and urging a longer benefit window; SB 576 on local government cybersecurity, which was amended to route the program through the Florida Digital Service and strengthen state-local coordination; SB 964 clarifying how certain gift and honoraria disclosures are filed with the Commission on Ethics; SB 1612 requiring local governments to accept electronic payments with a delayed effective date; SB 830 creating public records exemptions for certain local government administrators and their families; SB 1096 clarifying the filing deadline for employment discrimination complaints; and SB 1656 designating the SS American Victory as Florida’s official state flagship. All were reported favorably.
The committee also considered a slate of appointments, including a separate vote on Jeffrey Aaron to the Public Employees Relations Commission, which was recommended favorably after Senator Polsky objected to the appointment and cited concerns about political ties and prior work. The remaining appointees on tabs 12 through 30 were also recommended favorably. After a recess, the committee took up SB 1296 on the Public Employees Relations Commission, as substituted by a committee PCS. The PCS would change union certification and recertification rules, require stronger showing-of-interest and voting thresholds, limit paid union leave in some cases, require equal access to employer communication spaces, and speed up impasse procedures for state-funded salary increases. The bill drew extensive testimony, with supporters arguing it would improve accountability, transparency, and taxpayer fairness, and opponents—many of them teachers, bus drivers, and other public employees—saying it would weaken collective bargaining, burden workers, and function as union busting. Members raised constitutional concerns about the single-subject rule and collective bargaining protections, and debate was ongoing at the end of the transcript.
OK
Bills:
SB1189, SB1295, SB1297, SB1330, SB1333, SB1338, SB1341, SB1344, SB1355, SB1377, SB1378, SB1546, SB1859, SB1946, SB1990, SB1998
Keywords:
school security, funding, public schools, security enhancements, resource officers, domestic violence, fatality review, revolving fund, database, public safety, Oklahoma, census accuracy, Oklahoma Department of Commerce, federal census, grassroots outreach, marketing campaign, water infrastructure, Oklahoma Water Resources Board, grants, environmental compliance
WA
Washington 2025-2026 Regular Session
JLARC I-900 Subcommittee for SAO Performance Audits Sep 17th, 2025
JLARC I-900 Subcommittee for SAO Performance Audits
Transcript Highlights:
- Attackers continue to use ransomware to cripple organizations, like the state of Nevada, currently with
- For those audits, we have completed 83 critical infrastructure and nine ransomware resiliency audits.
- In January 2025, we completed seven cybersecurity safeguard audits, six ransomware resiliency audits,
- was published by the Joint Ransomware Task Force.
- May 2023 to April 2024, there were 95 ransomware incidents nationally.
Summary:
The Joint Legislative Audit and Review Committee held a public hearing on the State Auditor’s Office cybersecurity performance audits for fiscal year 2025, covering both state agencies and local governments. SAO staff explained that the audits are conducted independently under Initiative 900 and are kept confidential at the entity level, with detailed findings shared directly with the audited organizations. They reported that state agency audits found nearly one-third of assessed safeguards fully implemented on all systems and 227 vulnerabilities across seven agencies, including three critical and 21 high-severity issues. For seven local government cybersecurity audits, nearly a quarter of safeguards were fully implemented on all systems, and auditors identified nearly 300 vulnerabilities, including nine critical and 47 high-severity issues.
SAO also summarized its ransomware resiliency audits and critical infrastructure audits for local governments. In six ransomware audits, a little over 35% of assessed safeguards were not in place, while about 60% were at least partially in place. In 39 critical infrastructure audits, focused largely on water and sewer providers, auditors found over 260 vulnerabilities and said more than 10% were critical or high. Staff highlighted that these audits have led to improvements, including one vendor making security changes after SAO testing that were later echoed in a federal advisory. They also described related services such as cybersecurity checkups, policy guidance, and other cyber-related work by the office.
Washington Technology Solutions’ state chief information security officer, Ralph Johnson, praised the audits and said they help protect essential public services. He cited a sharp national rise in ransomware incidents against governments and said Washington has used more than $11 million in federal and state cybersecurity grant funds for over 200 projects. In response to questions from Representative Scott, SAO and WOTEC discussed options for addressing urgent vulnerabilities, including compensating controls, grant funding, and low-cost mitigation steps. The committee also discussed how Washington’s program compares nationally, with Johnson saying Initiative 900 is unusually comprehensive and that local governments often seek audits voluntarily. No votes were taken, and the hearing adjourned after public testimony was offered but none was given.
MN
Minnesota 2025-2026 Regular Session
Legislative Commission on Cybersecurity 01/08/26
Minnesota House Floor Meeting
Transcript Highlights:
- And that includes ransomware incident response, like what happened in St.
- ransomware shutdown of a K12 district? ransomware shutdown of a K12 district?
- <00:42:37.200>
Um, from overseas to include ransomware. - Um, from overseas to include ransomware.
- <00:42:43.520>
and you're thinking about ransomware and you're thinking about ransomware and
Summary:
The Legislative Commission on Cybersecurity met remotely on January 8, 2026, approved the minutes from October 27, 2025 by voice vote, and confirmed a quorum was present. The main presentation came from the Minnesota National Guard’s cyber coordination cell, with Lieutenant Colonel Brian Morgan describing the unit’s mission to prepare Guard cyber forces for state or federal cyber support, including domestic emergencies like the St. Paul ransomware incident and broader federal activations.
Morgan outlined three main lines of effort: optimizing cyber force training for likely threats, building relationships with state, federal, academic, and local partners, and equipping deployable incident-response tools. He said the coordination cell is not itself the incident response team, but serves as the planning and coordination office for military cyber response, maintaining equipment at Cedar Street Armory that can provide out-of-band connectivity and be deployed quickly. He also described partnerships with Minnesota IT Services, CISA, the FBI, Metro State University, and international/state partners such as Norway and Croatia, along with participation in major exercises and conferences.
The presentation emphasized the St. Paul response as a model for coordination, noting the Guard’s role in mission coordination, operational support, public affairs support, and lessons learned. Morgan said the Guard has conducted more than 200 engagements with partner institutions in 2024-2025 and uses outreach to educate counties and other entities on how to request Guard cyber support, comparing the process to requesting assistance for a fire or flood. In response to a question from Representative Bonner, he highlighted the long-standing relationship with Metro State University and its practical role in training cyber personnel, including operational technology training and a credit-transfer pathway toward a master’s degree.
UT
Utah 2025 2nd Special Session
Public Utilities, Energy, and Technology Interim Committee - November 19, 2025
Public Utilities, Energy, and Technology Interim Committee
Transcript Highlights:
- Ransomware is almost exclusively paid in cryptocurrency.
- Ransomware is the number one issue for cities and counties.
- And what we found is a lot of the entities that are being hit by ransomware report that the ransomware
- ... ...around is a lot of the entities that are being hit by ransomware report the ransomware incident
- Ransomware, if we can get better at some of these things.
MN
Minnesota 2025-2026 Regular Session
Committee on State and Local Government - 02/20/25
State and Local Government
Transcript Highlights:
- :03:30.640>
cyber <00:03:31.040>attacks <00:03:31.640>and <00:03:31.799>ransomware - <00:03:32.519>
in from cyber attacks and ransomware in from cyber attacks and ransomware in - attacks uh so just to give ransomware attacks uh so just to give you<00:09:59.160>
a <00:09:59.480 - We're seeing more data breaches, more ransomware attacks, and more unauthorized access to networks.
- We're seeing more data breaches, more ransomware attacks, and more unauthorized access to networks.
OK
Oklahoma 2026 Regular Session
Senate Legislative Session Feb 18th, 2026 at 01:30 pm
Oklahoma Senate Floor Meeting
Bills:
HCR1006, SB1226, SB1239, SB1309, SB2132, SB1189, SB1344, SB1295, SB1355, SB1998, SB1330, SB1297, SB1338, SB1546, SB1378, SB1859, SB1333, SB1341, SB1377, SB1990
Keywords:
campaign finance, election spending, political spending, money in politics, constitutional amendment, Citizens United, free speech, ballot measures, elections, corruption, dark money, outside spending, foreign influence, special interests, corporations, unions, federalism, self-government, political equality, term limits
TX
Keywords:
Cow Creek Groundwater Conservation District, groundwater, water wells, domestic well, livestock well, exempt well, metering device, well meter, groundwater conservation district, Special District Local Laws Code, Water Code, Section 36.117, groundwater regulation, water rights, aquifer management, municipal utility, retail public utility, groundwater export, water supply contract, election
Summary:
The Committee on Natural Resources heard testimony on a series of water, utility, and groundwater-related bills. Early items included HB 5693, which would let Drainage District 7 hold board elections in November of odd-numbered years when a countywide election is occurring, and HB 5671, which would update the Johnson County Special Utility District by clarifying board eligibility, allowing bond issuance, and removing redundant TCEQ approval language to reduce costs and delays. Both bills were left pending after brief testimony from bill sponsors and local witnesses.
The committee also heard SB 1504, which would update the Gulf Coast Authority to allow video-conference participation in meetings, and SB 1302, aimed at closing a TCEQ permitting loophole that allowed dischargers with prior denials or suspensions to reapply through an automated process without meaningful review. SB 2692 drew substantial discussion: it would change the signature threshold for outside-city-limits customers appealing municipal utility rates to the PUC by customer class. Valero supported the bill as a way to avoid requiring large-volume users to gather signatures from unrelated residential customers, while the City of Corpus Christi opposed it, arguing that lowering the threshold to one customer could trigger expensive appeals costing $500,000 to $1 million. A PUC witness said such cases are increasing and that the agency would need additional staff under the fiscal note. SB 790, creating a simplified PUC complaint process for small water and wastewater billing disputes, and SB 1663, expanding TCEQ notice requirements for nearby residents when groundwater contamination is discovered, were also heard and left pending.
Additional bills included HB 3115, clarifying that the Cow Creek Groundwater Conservation District cannot require meters on exempt domestic or livestock wells; SB 1055, raising the Southeast Texas Groundwater Conservation District’s production fee cap from 1 cent to 7 cents per 1,000 gallons; and SB 1625, requiring private water and wastewater utilities to report cybersecurity incidents to TCEQ and DIR. The committee then took up pending business and adopted a substitute for SB 7, which made several changes to water fund use, eminent domain coordination, and EDAP-related provisions, and voted 10-0 to report it favorably. The committee also adopted a substitute for HB 2347, a county water conservation program bill, and reported it favorably 9-1. HB 5675 and SB 2476 were each reported favorably 10-0. The meeting concluded with adjournment.
TX
Keywords:
Cow Creek Groundwater Conservation District, groundwater, water wells, domestic well, livestock well, exempt well, metering device, well meter, groundwater conservation district, Special District Local Laws Code, Water Code, Section 36.117, groundwater regulation, water rights, aquifer management, municipal utility, retail public utility, groundwater export, water supply contract, election
MN
Minnesota 2025 1st Special Session
Local government cybersecurity grant bill, HF140, heard in state government committee 2/27/25
Transcript Highlights:
- manage a lot of sensitive data for our residents, which has made them more and more a target for ransomware
- manage a lot of sensitive data for our residents, which has made them more and more a target for ransomware
- ><00:08:41.880>
to in uh cyber security claims due to in uh cyber security claims due to ransomware - c> attacks<00:08:42.959>
we're <00:08:43.080>seeing <00:08:43.320>more ransomware - attacks we're seeing more ransomware attacks we're seeing more data<00:08:43.760>
breaches <00
MN
Minnesota 2025 1st Special Session
Legislative Commission on Cybersecurity 8/27/25
Minnesota House Floor Meeting
Transcript Highlights:
- As you know, cyberattacks are a global issue, and specifically ransomware attacks are a global issue.
- Ransomware is designed to lock you out of your own systems and then demand payment.
- Paul is not unique in being confronted by ransomware actors.
- <00:15:39.279>
Enhanced ransomware and data loss. Enhanced ransomware and data loss. - But we couldn't begin ransomware attack.
MN
Minnesota 2025-2026 Regular Session
Cmte on Agriculture, Veterans, Broadband and Rural Development - Subcommittee on Veterans - 03/09/26
Transcript Highlights:
- We're looking at ransomware response and vulnerability assessment.
- So this is what we use for the City of Saint Paul during a ransomware event.
- Ransomware event.
- In July of 2025, the City of Saint Paul had a ransomware attack.
- This allowed them to directly support the City of Saint Paul during the ransomware incident.
Summary:
The Minnesota Senate Subcommittee on Veterans heard a Department of Military Affairs presentation on bonding, tuition benefits, and cyber response. The department requested $3.5 million in design funding for a new hangar at the 148th Fighter Wing in Duluth, citing safety problems with the aging 1950s-era hangars and the need to improve the wing’s competitiveness for future federal military construction funding. It also sought $2.5 million for asset preservation at Army facilities statewide, emphasizing that state dollars are often matched by federal funds. A National Guard lieutenant also testified about the State Tuition Reimbursement Program, describing how it helped pay for her undergraduate and doctoral education and reduce student debt.
The committee also received an update on Minnesota National Guard cyber operations, including the response to the July 2025 ransomware attack on the City of Saint Paul. Testimony described the cyber coordination cell’s role in planning, interagency coordination, and support during the incident, including helping re-image about 500 computers and assisting with network recovery. Members heard that the Guard’s cyber teams conduct extensive partner engagement and are prepared to support state and local entities when civil resources are exhausted and the incident exceeds local capacity.
Three bills were then heard and advanced. Senate File 4075, as amended, would implement recommendations from the task force on Special Guerrilla Unit and regular forces veterans from the Secret War in Laos, including eligibility and benefit changes; the committee adopted an amendment and passed the bill to the full committee. Senate File 3956, as amended, would clarify that the Department of Veterans Affairs may partner with veteran-serving organizations using nonmonetary resources to address food insecurity, homelessness, and suicide prevention; it was also referred onward. Senate File 4056, as amended, would add veteran or military status as a protected class under the Minnesota Human Rights Act; testimony supported the change, including concerns about service members losing educational opportunities while on state active duty, and the bill was passed to the full committee.
TX
Transcript Highlights:
- Hostile nation-states, ransomware syndicates, and hacktivist collectives will launch well over 2 million
- When a city hall suffers... a ransomware attack at 3 in the morning, the unit rolls out, containing the
- It says to respond to, which again was my question about paying off ransoms—for instance, ransomware
- , so many of our small counties and companies are out there doing just that: they're paying the ransomware
- Functions other than the, you know, I had a county when I represented Jackson County where ransomware
Bills:
HB146, HB150, HB1500, HB1545, HB1562, HB2067, HB2520, HB2818, HB3214, HB3250, HB3466, HB3512, HB3623, HB4063, HB4395, HB4464, HB4668, HB4690, HB5331, HB3833, HB146, HB150
Keywords:
HB 146, Texas Capitol, State Capitol, State Preservation Board, Congress Avenue, Travis County, traffic lanes, lane closure, road closure, municipal authority, local control, Capitol area, downtown Austin, special events, construction traffic plan, pedestrian safety, public works, transportation policy, government code chapter 443, cybersecurity
TX
Transcript Highlights:
- While I speak here this morning on this bill today, hostile nation-states, ransomware syndicates, and
- While I speak here this morning on this bill today, hostile, nation states, ransomware syndicates, and
- When a city hall suffers a ransomware attack at 3 in the morning, the unit rolls, containing the malware
- It says to respond to, which again was my question about paying off ransomware ransoms, for instance.
- They're paying the ransomware.
Bills:
HB146, HB150, HB1500, HB1545, HB1562, HB2067, HB2520, HB2818, HB3214, HB3250, HB3466, HB3512, HB3623, HB4063, HB4395, HB4464, HB4668, HB4690, HB5331, HB3833
Keywords:
HB 146, Texas Capitol, State Capitol, State Preservation Board, Congress Avenue, Travis County, traffic lanes, lane closure, road closure, municipal authority, local control, Capitol area, downtown Austin, special events, construction traffic plan, pedestrian safety, public works, transportation policy, government code chapter 443, cybersecurity
Summary:
The committee took up several pending business items and reported a series of House bills out of committee, including HB 2467, HB 2468, HB 2518, HB 4310, HB 4386, HB 4490, HB 5323, and HB 149. Most of these were advanced on committee substitute motions and sent to the local and uncontested calendar or reported favorably to the full Senate. HB 2467 drew one nay vote, while the others were approved without opposition. HB 4310 and HB 4386 were described as committee-substitute versions with changes narrowing disclosure requirements and preserving attorney-client privilege in certain circumstances.
A major portion of the meeting focused on HB 149, an AI governance bill. The substitute was explained as addressing biometric identifier capture and storage, exempting certain AI uses for security and fraud prevention, clarifying definitions, restricting AI systems that simulate explicit child sexual content, adjusting Attorney General investigative authority, refining sandbox program waivers, reducing Texas AI Council powers and membership, and adding DIR coordination provisions. The committee adopted the substitute and reported the bill favorably.
The committee then heard extensive testimony on HB 1500, the DIR sunset bill. The author said the bill would continue DIR for 12 years, restructure its board, update advisory committees, require regular cybersecurity assessments and penetration testing for state agencies, improve IT procurement training, and transfer the e-grants program to the Comptroller. A Texas 2036 witness supported the bill as a way to strengthen governance, procurement, and cybersecurity. Members asked detailed questions about the bill’s structure and then left HB 1500 pending.
The committee also heard a lengthy presentation on HB 150, which would create the Texas Cyber Command as a component of the University of Texas System, administratively attached to UTSA and located in San Antonio. The author argued the command would centralize cyber threat intelligence, incident response, and digital forensics, and would be able to support state and local entities, with optional services for local governments. Members raised concerns about university mission drift, governance, security, chain of command, procurement authority, gifts and donations, and civil liberties implications of proactive cyber monitoring. Witnesses from UTSA/NSCC and SecurityScorecard testified in support, emphasizing the security of the downtown San Antonio facility, the existing cyber ecosystem there, and the need for a dedicated cyber capability. The bill remained under discussion with no final committee action announced in the excerpt.
TX
Transcript Highlights:
- So that ransomware campaigns hitting multiple jurisdictions are linked, not treated as isolated thefts
- fusion centers, sinks will feed the command's attribution data into DPS fusion centers so that ransomware
Summary:
The Senate Business and Commerce Committee met with a quorum and considered several House bills. House Bill 111 was taken up as a committee substitute; members briefly discussed what entities the bill would apply to, and the committee substitute was adopted and reported favorably to the full Senate by a 6-5 vote. House Bill 150, relating to the Texas Cyber Command, received extensive explanation of a revised committee substitute that made the command a standalone state agency, allowed flexible state partnerships, preserved vendor neutrality, added emergency purchasing guardrails and reporting, protected existing confidentiality laws, limited monitoring to contracted entities, and clarified coordination with law enforcement rather than direct prosecution. The substitute was adopted and HB 150 was reported favorably 11-0.
The committee also reported House Bill 2517 favorably without debate, 10 ayes and 1 present not voting. House Bill 2963 was considered with a committee substitute that added a definition of “power sports vehicle” and exempted those items from the right-to-repair bill; the substitute was adopted and the bill was reported favorably, with a recommendation for the local and uncontested calendar. House Bill 3520 was reported favorably by a 7-4 vote, and House Bill 5435 was reported favorably 11-0 and also recommended for the local and uncontested calendar.
After completing the votes, the committee recessed subject to the call of the chair.
ND
North Dakota 2025-2026 Regular Session
Information Technology Committee Mar 26th, 2026
Transcript Highlights:
- But in April of 2025, we actually got threat intelligence from one of our partners that a ransomware
- So we are aware that there's a critical infrastructure entity that had experienced a ransomware attack
- So we are aware that there's a critical infrastructure entity that had experienced ransomware attack.
- So ransomware, again, it's about whether or not they made payment, but if you're talking about business
- So, of these, I am not aware of—so in the ransomware incidents, I'm not aware of any ransoms that have
Summary:
The committee received several informational reports from NDIT and DPI. Justin Data reviewed the quarterly major IT project portfolio, noting the portfolio was slightly under budget and behind schedule overall, with three red schedule items: Bed Management System and Vital Records were essentially complete and being closed out, and the Roadway Capital Planning Project was delayed by vendor bug fixes after testing. He also summarized recent project startups and closeouts, including the Victim Notification System, Medicaid data exchange, Highway Patrol’s motor carrier permit system, and several completed HHS and RIMS projects. Members asked for follow-up on ADA compliance work, the public-facing RIO website, and the state’s mainframe retirement timeline, and staff agreed to provide updates later.
Craig Falkley reported on coordination of services with political subdivisions and higher education, including StageNet, cybersecurity, radio/911 services, and PeopleSoft coordination. He also explained distributed ledger technology as a tool for transparency and fraud prevention, but said it is not widely used in state government and suggested the report be modernized to focus more broadly on emerging technologies such as AI and cybersecurity. The committee generally agreed that the topic should be updated.
Chris Gurgan presented the mandatory cybersecurity incident reporting program created by HB 1314, explaining how agencies and political subdivisions report incidents through NDIT’s website or service desk. He said 77 incidents had been reported since 2021, 47 met the statutory definition, and most were phishing-related; most reported incidents were resolved, with one recent ransomware matter still open. He also reviewed notable incidents since the last report, including the PowerSchool compromise, a SimpleHelp intrusion at a school district, a court intrusion, a WSUS vulnerability, a business email compromise, and a recent ransomware incident involving a non-state critical infrastructure entity. Members asked about recovery of stolen funds, early warning signs, smishing, training, MFA, conditional access, and cybersecurity maturity assessments; Gurgan said the state uses MFA and conditional access, provides awareness training to state employees, and would return with more information on maturity assessments.
Tony Ambrose then updated the committee on the K-12 student information system bridge project. He said district implementation of Infinite Campus had begun statewide, but the data migration vendor originally selected was terminated for poor performance and replaced by Aurora Educational Technology, which had experience with similar statewide migrations. He also said DPI is migrating special education data from Tynet into Infinite Campus, and that some SLDS-based tools such as e-transcripts and Choice Ready may not function exactly as they do now at July 1, requiring interim or alternative solutions. Members raised concerns about summer school disruptions, the timing of the cutover, and whether the new system would support existing reporting and transcript functions; DPI said it was working on identity, authentication, data-sharing agreements, and post-go-live integrations, and would continue to refine the plan beyond June 30.
FL
Florida 2025 Regular Session
January 14, 2025 - 09:00 AM
Transcript Highlights:
- Several metrics on the ransomware side, we look at meantime to detect, respond. to the 24-7 question.
- Several metrics on the ransomware side, we look at meantime to detect, respond. Metrics.
- On the ransomware side, we look at mean time to detect, respond, and recover.
- In addition to the mean time to detect, respond, and recover, which we're tracking at the ransomware
Summary:
The subcommittee held its first meeting to examine Florida’s information technology governance, budgeting, cybersecurity, data management, and telecommunications operations. Chair Schneider and other members framed the panel as a new joint policy-and-budget forum focused on reducing jargon, improving accountability, and asking whether technology investments are feasible, aligned with state goals, cost-controlled, and secure. State Affairs Chairman Will Robinson and members emphasized that the committee should avoid buying “shiny new objects” without clear business cases and should focus on long-term value, cybersecurity, and operational efficiency.
Florida Digital Service and Department of Management Services leaders provided an overview of the state IT enterprise. Secretary Pedro Allende described DMS as the state’s business, workforce, and technology service provider, while State CIO Warren Spanholz outlined Florida Digital Service’s four core areas: cybersecurity, project success, data interoperability, and enterprise architecture. Chief Data Officer Ed Ryan said the state data catalog is about 400,000 elements and roughly half of agencies are participating, and he described efforts to identify authoritative data sources and improve interoperability. Chief Information Security Officer Jeremy Rogers discussed the state cybersecurity operations center, enterprise risk management, incident response exercises, and a recurring $35 million cybersecurity resiliency budget. Chief Technology Officer Leo Schoonover described oversight of major IT projects over $10 million, updated project management standards, and a shift toward smaller phased implementations and more flexible methodologies to reduce delays and overruns.
Other presenters covered telecommunications, data center operations, and cybersecurity workforce development. Director Denise Atkins said the Division of Telecommunications manages Suncom and MyFloridaNet, with nearly $336.9 million appropriated for fiscal year 2024-25, and is procuring the next network contract while emphasizing security controls and vendor flexibility. Tim Brown said the Northwest Regional Data Center operates on a chargeback basis, serves state and local customers, and returned surpluses to customers in recent years. Cyber Florida Director Ernie Ferraroso described training, workforce pipelines, K-12 outreach, a cyber range, and research programs aimed at building Florida’s cyber workforce and improving public-sector readiness.
Members asked about budget setting, project delays, change orders, cybersecurity reporting, data catalog participation, interoperability, and expanding cybersecurity operations centers. Officials said chargeback rates are based on actual direct and indirect costs, project delays often stem from unclear scope and insufficient upfront planning, and cybersecurity success is measured by mean time to detect, respond, and recover. They also said the state is moving toward more modular project delivery, broader agency participation in shared cybersecurity services, and expanded CSOC locations within existing staff and budget where feasible.