Key Takeaways
- West Virginia enacted House Bill 5638, expanding the authority of the state chief information security officer (CISO) and mandating annual cybersecurity reviews for most state agencies.
- The law clarifies that agency participation in the reviews is compulsory and allows the state to recover costs when an agency fails to engage, including expenses for outside consultants.
- Higher‑education institutions, state police, certain constitutional officers, the Legislature, and the Judiciary are exempt from the new requirements.
- The CISO must submit an annual report to the governor and legislators detailing the program’s progress and findings.
- Beyond state agencies, West Virginia is leveraging federal State and Local Cybersecurity Grant Program funds to assist local governments with cybersecurity assessments, vendor connections, and sustainable technology planning.
- Officials recognize that emerging AI‑driven threats increase the difficulty of distinguishing legitimate communications from attacks, underscoring the need for continuous vigilance and education.
- Parallel modernization efforts include a central licensing portal powered by AI and a multi‑year migration of legacy mainframe systems to cloud or hosted environments.
Legislative Changes to West Virginia’s Cybersecurity Framework
In mid‑March, West Virginia lawmakers passed House Bill 5638, which amends the state’s cybersecurity program to give the chief information security officer (CISO) expanded oversight of policies, risk management, and related responsibilities across most state agencies. The bill took effect on June 12, prompting agencies to adjust their practices to align with the new statutory language. Rather than creating an entirely new program, the legislation focuses on ensuring existing cybersecurity measures are consistently implemented and monitored.
Mandatory Annual Security Reviews
A core provision of the bill requires every covered agency to conduct a yearly cybersecurity review in collaboration with the Office of Technology. Previously, the language allowed agencies to treat participation as optional, weakening the effectiveness of the process. The revised statute now states that agencies “shall” perform the review, removing ambiguity and placing a clear obligation on each entity to engage with the Office of Technology to complete the assessment.
Accountability and Cost Recovery Mechanisms
To reinforce compliance, the law introduces a financial consequence for non‑participation. If an agency—designated as an information custodian—declines to take part in the required review and the Office of Technology must hire external experts for diagnostics or evaluation, the state can recover those expenses from the agency, up to the actual cost incurred. CIO Heather Abbott summarized the intent: “if we have to hire somebody to come in and help us with this review, they have to pay for it.” This mechanism aims to deter neglect and ensure that the state does not bear unnecessary costs for others’ lapses.
Reporting and Transparency Requirements
The CISO is now obligated to submit an annual report to the governor and legislators detailing the status of the cybersecurity program, including findings from the agency reviews, progress on remediation efforts, and any emerging risks. While the law protects sensitive cybersecurity information from public disclosure, the reporting requirement provides elected officials with a clear view of the state’s security posture and helps guide future policy and funding decisions.
Scope of the Law and Exemptions
The revised cybersecurity requirements apply to most state entities but explicitly exclude higher‑education institutions, the state police, certain constitutional officers, the Legislature, and the Judiciary. Abbott noted that these exclusions stem from existing governance structures or separate statutory mandates that already impose cybersecurity obligations on those bodies. Consequently, the Office of Technology’s oversight focuses on the executive branch agencies that fall under the CISO’s direct authority.
Shift from Optional to Required Participation
Abbott emphasized that the substantive change lies in the language surrounding the annual reviews. Previously, the wording allowed agencies to view the reviews as a voluntary exercise, leading to inconsistent participation. By mandating that agencies “shall” work with the Office of Technology, the state ensures that even those lacking internal cybersecurity expertise receive the necessary support to complete a meaningful assessment. This collaborative approach helps bridge capability gaps across agencies of varying size and resources.
Support for Local Governments Through Grant Programs
Recognizing that many local governments lack the budget to employ full‑time cybersecurity professionals, West Virginia is actively helping them access federal State and Local Cybersecurity Grant Program funding. The Office of Technology holds informational sessions to walk municipalities through the application process, identify eligible projects, and connect them with vetted vendors. Abbott stressed that the goal is not merely to spend grant money on new tools but to ensure communities can sustain those technologies after the grant period ends.
Informal Cybersecurity Assistance for Communities
Beyond formal grant support, local officials frequently approach the Office of Technology for informal cybersecurity assessments. Although the state does not directly manage local‑government systems, its staff can guide officials on what to look for, which standards to consider, and how to prioritize remediation efforts. Abbott described this outreach as a tangible benefit of a whole‑of‑state strategy, providing a “lifeline” for smaller jurisdictions that would otherwise struggle to obtain expert advice.
Emerging Threats from AI‑Driven Attacks
Abbott warned that artificial intelligence is reshaping the threat landscape, enabling attackers to discover vulnerabilities more rapidly and craft convincing phishing emails and websites. The primary challenge, she said, lies in distinguishing legitimate communications from malicious ones—a task that grows harder as attackers automate and scale their efforts. “Every time we find one that they block, they create 10 more,” Abbott noted, highlighting the relentless pace of modern cyber threats.
Broader Modernization Initiatives
While cybersecurity remains a priority, West Virginia is pursuing additional modernization projects. A central online portal is under development to help businesses determine required licenses and permits, employing AI behind the scenes to match users with the appropriate state systems. Simultaneously, officials are migrating legacy mainframe applications to cloud or hosted environments, aiming to complete the transition within two years. Abbott anticipates that this shift will reduce the state’s mainframe footprint, lower operating costs, and improve agility in adopting new technologies.
Strategic Vision for Adaptability in the AI Era
The overarching objective of West Virginia’s cybersecurity and IT modernization efforts is not simply to keep pace with technological change but to ensure the state can manage the risks and opportunities that accompany it. Abbott expressed confidence that the state’s ability to adapt—especially in the face of AI‑enabled threats—and to assist local governments in doing the same will be central to its long‑term strategy. By strengthening accountability, fostering collaboration, and investing in sustainable solutions, West Virginia aims to build a resilient security posture that protects both state assets and the communities it serves.

