Minnesota bringing more government organizations under its cyber umbrella | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


When it comes to cybersecurity, Minnesota has been ahead of the curve.

It used grant money from the Department of Homeland Security and other funding to create MNet – an enterprise telecommunications network that connects state and local government and education offices throughout the state.

Now, Minnesota is taking the “whole of state” cybersecurity effort even further.

John Israel, the state’s chief information security officer, said their updated approach is based across several pillars.

John Israel is the chief information security officer for the state of Minnesota.

“One was really creating a baseline of cybersecurity for local government and critical infrastructure, so getting resources to do assessments, understanding baseline controls, policies, standards, and ensuring that everybody has access to resources to build a security program,” Israel said on Ask the CIO. “Second tier was really bringing some advanced control security capabilities to these local governments, so looking at the buying power that the state has and the ability to really take enterprise class capabilities and bring them to even the smallest local government that may not even have an IT team, much less a cybersecurity team, and help them see the benefits of those capabilities within their program. The third part was bringing in cyber navigators. We brought in a team of cyber advisors that can really get to know and build the relationship with those local governments. It’s not a one and done and it’s not just that you’re getting outreach or you got the nebulous, ‘the state is doing something for you.’ You actually get to know a navigator that can help understand your unique needs.”

Israel said the state CISO’s office is offering resources, some at no cost and others at low cost, to help local and educational institutions improve their cyber defenses as the threats continue to evolve.

He said the DHS grant program has been especially helpful to deploy cyber capabilities statewide.

“That first plan was launched in 2023. We’ve been continuing to build and deploy off of that. We’ve got hundreds of entities that are on each of these programs throughout the state, and we’re seeing the value of that investment,” he said. “I wish I could say that we don’t have cyber attacks in Minnesota, or we don’t have successful ones, or we’re not seeing ransomware and other things that hit local governments. Unfortunately, we do. But the numbers are showing us that those who are being affected have not adopted these capabilities. And once again, I am not interested in telling folks you have to use the state services. I just want you to have some baseline control. That’s really the focus of that plan — not to buy our stuff or to adopt our tools as much as it is to make sure you have some tools or you have a program that meets these capabilities and is helping defend your networks and your data.”

A more common framework

The move toward a “whole of state” approach for cybersecurity is a growing trend.

A recent survey from the National Association of State Chief Information Officers and Deloitte found as cyber threats continue to advance and include the use of artificial intelligence, CISOs need more resources and funding that a whole of state approach provides.

NASCIO found 73% of the respondents say they favor a centralized model for managing cybersecurity over a federated one.

Israel said MNet started to prove out this concept by initially providing firewalls and intrusion detection systems that local governments didn’t have. Then over the last few years, Israel said his office found fewer and fewer local and education organizations were using these shared services.

“In 2023, we built a 15-member task force. It’s an advisory body that’s helped us really create the state’s whole state cybersecurity plan and focus on the creating and identifying the goal areas that we can really meet the needs of local governments,” he said. “That 15-member body is state, city, county folks. It’s tribal nations. It’s critical infrastructure. We’ve got water, wastewater and the energy sector. We’ve got the National Guard, and we’ve got some private sector folks that have seen how this really works to really help build that plan and help us make sure we’re meeting the needs of all of our communities.”

Minnesota, like all state, federal and private sector organizations, is facing a much more complex and aggressive cyber attacker, mainly because of AI tools.

Israel said while the state has used certain AI and automation tools for years, the newer capabilities have to help drive better and faster decisions. Minnesota recently completed an assessment of its security operations center as part of resetting its strategic direction and to help analysts improve the state’s overall cyber defenses.

Applying more AI tools

“We’ve seen the volume of logs, the volume of reports, the volume of telemetry that we need to mine to actually identify and defend state networks increase exponentially year after year. We’ve identified kind of gaps in the logging, things that we thought we had visibility to and didn’t,” he said. “Now I’m getting reports back now that project is fully implemented and throughout the phases of that, the amount of things that they’re being able to detect and respond to, and then those time frames for which we responded. It’s not necessarily the mean time to detect as much as it is the mean time to decision. How quickly can you get to the point where you can decide on to take action, pro or con?”

Israel said the SOC is using AI to identify patterns faster and automate their response.

Israel said analysts are searching logs using plain language, have access to cyber playbook much faster, and they’re able to mine through and hunt for new and novel threats in ways that they weren’t able to before.

“I think there’s still a lot more to come. We’re still at just the bleeding edge of what we’re going to be able to do in a security program, but we’re already seeing the value of being able to mine the data that we are collecting and monitoring it to get to faster decisions,” he said. “In the prior stages of AI, they were all operated independently. We had a security information and event management (SIEM) environment. We had a data lake that was recording archive logs. We had a security orchestration, automation, and response (SOAR) platform that was managed by engineers trying to build automation and rules based on patterns that they were detecting. But these were all operating separately and being managed separately. And now that we’re building that integration point as part of a consolidated platform offering, we’re seeing the value and the ability to look at this and as a coordinated effort and really build that maturity.”

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.