Key Takeaways
- Lieutenant Governor Delbert Hosemann announced a new cybersecurity select committee to combat rising digital threats targeting Mississippi residents, businesses, hospitals, and educational institutions.
- Hosemann estimates over $100 million is stolen annually from Mississippians through cybercrime, encompassing ransomware, data breaches, and financial fraud affecting critical sectors like healthcare and education.
- The committee, including State Senators Scott DeLano and Jeremy England, focuses on improving prosecution capabilities, enhancing information sharing for victims, and strengthening preventive measures against cyber intrusions.
- Hosemann emphasized the need for clear guidance on where individuals and organizations should turn when victimized by cyberattacks, aiming to create a coordinated state response.
- The initiative reflects growing recognition of cybersecurity as a pressing economic and public safety issue requiring legislative action and interagency collaboration.
Mississippi Lieutenant Governor Delbert Hosemann has taken a significant step to address what he characterizes as a pervasive and costly cybercrime epidemic affecting the state. Announcing the formation of a cybersecurity select committee just weeks ago, Hosemann framed the initiative as a direct response to the substantial financial harm being inflicted on Mississippians through digital attacks. His statement that he believes "more than $100 million a year is being stolen from Mississippi residents and businesses" serves as the stark catalyst for this legislative effort, highlighting losses that extend beyond individual consumers to encompass vital community institutions specifically named, including hospitals, community colleges, and high schools. This figure, while presented as Hosemann’s belief rather than a formally verified state audit, aligns with national trends reported by agencies like the FBI’s Internet Crime Complaint Center (IC3), which consistently shows billions in losses nationwide, suggesting state-level impacts of this magnitude are plausible given Mississippi’s size and economic profile.
The core purpose of the newly established select committee, as articulated by Hosemann, is to develop a multifaceted state strategy to combat these threats. Speaking to WLOX, he outlined the committee’s three-pronged focus: establishing clearer pathways for prosecution of cybercriminals targeting Mississippi entities, ensuring that victims—whether individuals, businesses, or critical infrastructure operators—have access to reliable information and guidance on immediate steps to take when an incident occurs, and advancing preventive measures to reduce vulnerability before attacks succeed. Hosemann explicitly stated the committee’s aim is to create a system where there is "actually prosecution for these people," coupled with readily available resources for the public seeking help, moving beyond mere awareness to actionable support and deterrence. This reflects an understanding that effective cybersecurity requires not just technical defenses but also legal recourse, public education, and streamlined incident response mechanisms.
The committee’s membership includes State Senators Scott DeLano and Jeremy England, signaling bipartisan legislative engagement on this issue. Hosemann’s description of the committee’s work reveals a broad scope designed to tackle the complex nature of modern cyber threats. He mentioned individuals within the group would be actively working to identify threats penetrating "state assets or your home, for example," indicating concern over both governmental infrastructure breaches and personal cyber victimization. This holistic view acknowledges that cyber risks permeate all levels of society, from attempts to disrupt state government operations or steal sensitive citizen data held by agencies, to attacks on local hospitals that could endanger patient safety, to ransomware locking down school district networks and disrupting education, and to sophisticated scams draining individual bank accounts. The reference to a "whole mixed bag of things that include information, prosecution, and hopefully prevention" underscores the committee’s mandate to address the entire cybersecurity lifecycle: threat intelligence, legal accountability, victim support, and proactive defense.
The targeting of sectors explicitly named by Hosemann—hospitals, community colleges, and high schools—highlights particular vulnerabilities within Mississippi’s critical infrastructure and public services. Healthcare institutions are prime targets for ransomware due to the life-critical nature of their systems and the high value of patient health data on the dark web, often forcing difficult choices between paying ransoms or risking patient care. Educational institutions, from K-12 districts to community colleges, frequently operate with limited cybersecurity budgets and IT staff, making them susceptible to phishing attacks, data breaches involving student and employee records, and disruptive ransomware that can halt online learning or administrative functions. These sectors not only hold sensitive personal information but also provide essential community services; their compromise has ripple effects far beyond the immediate victim, impacting public health, safety, and access to education. The committee’s focus on providing clear information channels for victims is especially crucial here, as stressed administrators or IT personnel may not know the optimal steps to contain an incident or whom to contact for state or federal assistance.
While the committee represents a new state-level initiative, its goals align with broader national and regional cybersecurity strategies. Many states have established fusion centers, information-sharing and analysis centers (ISACs) specific to sectors like healthcare or education, or strengthened partnerships with federal agencies such as the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI. Hosemann’s mention of potentially looking at a structure akin to a "Department of Homeland Security" (though likely referring to enhanced state-level coordination capabilities rather than creating a literal DHS replica) suggests an exploration of models where threat intelligence flows bidirectionally between state, local, federal, and private entities. The emphasis on prosecution also points to a need for better coordination between state law enforcement, prosecutors’ offices, and federal cybercrime units, which often possess the specialized technical expertise and jurisdictional reach necessary for pursuing sophisticated, often international, cybercriminal networks. Success will depend on the committee’s ability to forge these connections and recommend concrete legislative or administrative changes.
The path forward for the select committee involves navigating several challenges inherent to cybersecurity policy. These include securing sustainable funding for recommended initiatives (such as threat-sharing platforms, incident response teams, or cyber hygiene training programs), addressing the persistent shortage of skilled cybersecurity professionals within state and local government, ensuring that recommended measures are practical and not overly burdensome for under-resourced entities like small towns or rural schools, and keeping pace with the rapidly evolving tactics of cyber adversaries. Furthermore, effectively communicating clear, actionable advice to the general public—such as recognizing phishing attempts, implementing multi-factor authentication, or knowing to report incidents to entities like the IC3 or state Attorney General’s office—remains a perpetual challenge. Hosemann’s focus on where people should go "when this happens to you" directly tackles this critical gap in public cyber resilience. The committee’s deliberations over the coming months will be closely watched by stakeholders across Mississippi as they seek to transform concern over the alleged $100 million annual loss into tangible improvements in the state’s cyber defense posture and victim support infrastructure. The initiative underscores a growing consensus that proactive, coordinated state action is essential to mitigate the escalating economic and societal toll of cybercrime in the digital age.

