Advanced Communications and Information Technology - Joint
Video
Transcript
5 documents
Machine transcript
May contain errors. Verify important quotations against the official video.
About transcript accuracy
- Source
- SliQ live captions
- Model
- SliQ live ASR
- Processing date
- October 2, 2026
Unknown speaker
5:02
We're gonna go ahead and get started buying the whole gavel there I appreciate everyone being here for the first technology committee meeting was held in a while first thing we need to do first order of business is to approve the minutes from the November seventeenth. meeting on a motion. Second. Okay all in favor. The opposed all right so those are adopted
The purpose of the meeting this morning is we're gonna take a look at cybersecurity and our broadband and get an update from the I. us as we haven't held a meeting in quite awhile so first up I've asked some folks from A next step innovation they are leaders in the cybersecurity area and I've asked them to come and just talk to us about so what they're saying the cybersecurity around best practices and things that we can
learn as a state so at this time I'm gonna ask you Mr Townsend and Mr o'quinn would come forward to the. Yes care. And then now when you gentleman get to. The seated after just turn on your microphones there and introduce yourself to the committee and then will be. Open to hearing representation. Okay good morning first of all
let me thank you for the invitation opportunity to speak with you a hundred thousand one of the founders of next of innovation by way of a little bit of experience working cyber security for twenty years before I worked for a company I was over everything everything cybersecurity related for one of the Department fences research supercomputing centers in Vicksburg Mississippi. Once again thank you very much for a of Alanis opportunity to
talk with you my name is David of land I am the director cybersecurity for next up innovation prior to being next up I was a a professor of computer science building and university and prior to that I was working as a a researcher in cybersecurity at MIT Lincoln laboratory in New England and I've been working in the field of cybersecurity for some time mostly from a research perspective but of late very much in the applied round and we look forward to talking with you
about some of the things that we've seen and how Arkansas can help better secure it's schools and state organizations. Our thank you John for being here you definitely sound like you're very knowledgeable in this field and we appreciate you sharing your expertise with us this morning so with that we'll go ahead and let you. Thank you very much have the floor. and certainly we we welcome any any questions Miller the to stop whenever you're ready Sir a brief intro about our company
we've been in business for over fifteen years probably eleven or twelve has been have we have a pretty very strong cybersecurity practice in fact is one of our core pillars of our company Our company is probably forty fifty people we've been doing this obscurity side for state agencies and local government things like that Mississippi for over ten years of some of our other customers department offense actively right now on contracts SEC universities the U. of a system which are doing a little
work with some of their entities there is a kind of an essence voluntarily starting to undergo some these processes one of the things that that we thought was particularly that will relevant to this is city Mississippi the way that they do things we've been on the contract again for two contracts for over ten years went right now we're currently on the only firm on the contract to do penetration testing and cyber security audits for state agencies things like that they require all other state agencies to have an order
performed every three years to put some teeth into that the way that they enforce that is for certain or purchasing request they have to go before the board of the information technology services department Mississippi they're not allowed to appear before the board if they have not had an audit within the last three years so sometimes we get it we request Hey we have to have an audit is going to be done in two weeks because we've got a request is gonna get approved so that's how they're actually enforcing that we have
over the last ten years we've probably done. I'm gonna say I don't know the numbers exactly hundred fifty two hundred dollars for different state agencies that's not require currently for the school districts and for higher ed they are starting to they can use it and they're starting to but it's it's that's definitely a slow take their but speaking of school districts we actually did do security assessment and penetration tests for the school district North Little Rock that was performed
earlier this year we actually a follow up meeting with with doctor Gregory police chief last week he said they're still going to the river the report and looking at that Doctor we can give more details of that but one of the things that he said was he was a very cybersecurity focused and and his his response back to us was that everyone is do this and that they should be encouraged not required to do it so if every shot every school should NO R. in LR as these definitely trying to set an
example but also they're trying to do their due diligence Yes some of the things that that we see or we recommend in addition to the pen testing and security audits number one thing we recommend mainly because you don't know what you don't know no that's not a one and done and we move on with life situation but it's definitely a step one for sure beyond that some of the things that we would recommend being investigator required or encouraged is monitoring or the B. S. security operations center
or local staff what's what you find out what's wrong you fix it if you then have no insight into what happens after that then you're gonna find yourself back in the same situation you're never gonna be perfect there's way too many things that can go wrong but it's a definitely a step wise constant fight to stay not the last man in line. you know the users though these days are the main problem and whether it be an intentional or malicious users or were you guys need to focus your second efforts that in terms of
training turned look emails and phishing attacks that is the number one way that state agency is giving state actors China Russia Ukraine whatever that's how they're getting in and traditionally almost to a fault once you get into an environment the controls around protecting your assets are greatly reduced you have the front door locked but what you get in the inside interior doors are wide open so efficient campaigns help train the users training training in general but that active testing them getting the
try to click on something and and then training them after the fact what they should do to help raise their awareness make them think twice Speaking of that internal lack of control one of the things that is the best you may have heard is kind of a buzz word last couple of years really since covid is a zero trust so starting to do and it's it's a it's a higher technological lift but if I'm honest I'm already in the house I still have to go and unlock the door every time I go in a different room so nothing that
we we trust nothing I don't trust him sitting right beside me until he proves to me who he is buy something some factor that I can understand and and and therefore issue trust so those are some of the things we recommend number one for sure would be contesting audits of the new then what they need to address with the need to fix number two would probably be monitoring so they can continue to have the insight that can be thank you bye now suffer we can be internal with them doing their own a set of basic remain everything's
and then again Leslie MFA multi factor I did mention that right so making sure that everyone realizes something more than just a password and then perhaps the phishing campaigns as what I would recommend. So before I start talking I want to go ahead make sure you all know that you can ask questions at any given point in time as a when I was a professor I I prefer to start question the classes with questions because that way I can know what you do know and what you're interested in so if you just want me to shut up and ask me questions
please just do that now I'll try to make sure that I have and listen actually looks like we might have a question all right here off the back of representative Brown. And this really no question it to request what's your jargon we are not professionals in this field and it's just because I've met with your company previously that I know pen testing is penetration testing that's great okay so if you could help us all thank you my apologies okay I understand so so let me go and explain what
what that actually is very briefly just so that you can understand so we all know what it's we all know how bad it is for a bad guy to get into your network we know that it's a bad thing but why is it a bad thing well as Trent was saying is that once you get into that front door. They can have their role they can roam around the house and they can look at whether they want to and take whatever they want to that's how it works and sort of the real world and it's also how it works and that works unfortunately that's the way that networks are constructed
they have a very hardened outer shell with very soft interior. And so when an attacker can get inside and very often they get inside not through the front door but through the window through a user once they're there then they have full reign inside of that internal network that that soft internal network and so what a penetration test does is that we essentially start from that perspective we put a computer inside of your network and say okay I have not working activity what damage can I do.
And then once we've done that once we figure that out and we've looked at what what we can see and what we what doors we can knock on which ones are unlocked which ones we can break down after we've done all that we try to get as far as we can and then at the very end we write a report and the primary thing that we're trying to provide in the penetration test report our what are your top threats now we've all heard it I hope of vulnerabilities vulnerability is something that's wrong with your system
that can be exploited well I threat is a vulnerability on your device that can be exploited and do damage. Right so the identification of threats as the primary purpose of the penetration test is to say listen if a bad guy got on your network what damage can you do right and so that's that's what a penetration test is hopefully that makes sense mmhm all right so so in the interest of that one of the things I want to talk about it's a little bit of a
a thing that I think about very often personally and that is the concept of education and the furthering of the human capital side of this not necessarily just from the user perspective that's extremely important because users make up a. They are they are the people that get things done but they're also the people that frankly don't have time to deal with cyber issues right because I got work to do right we understand that I'm we're talking about on the IT side we have information technology professionals that
are very talented and do their job very well and what we're interested in is a company and we are making inroads into this actually in Arkansas we talk with regularly a regular at the department of education and training there information technology professionals on the process of what we call purple teaming and red teaming and so the idea of red teaming is thinking about security from an attacker's perspective right we all know about how defending a network from the inside is we call that
the blue team the blue team are the people that protect the network and they fight attackers but sometimes the best way to fight an attacker is to learn how to think like one if you can think like the attacker you can predict where they're going to go and so one of the things that we are in the early phases of doing is working with regard to and his cyber threat response team for the K. twelve systems to train them on the process of what we do every with every organization we go to we want to
train these IT professionals not only to do the blue team work but also think like a red timber and go through exercises where they had it we can help them learn how to do a reading right to redeem the team explained okay red team blue team okay I'm doing it again I'm doing it again thank you So the red team's of the blue team is the defense their defenders the red team or the attackers both of which are interested in furthering the security of our all of an organization right they're both
working for the good guys but they're doing it from two different mental perspectives one is thinking about how do I get in and everyone is thinking about how to like keep you out and the purple team is when they collaborate and they talk and the best possible exercise is when you have a red team person and this is something that I did when I was at MIT we were doing it with the warfighters in what we call cyber ranges which is essentially just a place to practice cyber techniques and and
cyber procedures and so the war fighters would have a red team okay they would have a certain set of military personnel and possibly contractors that were actually working to get into a cyber rain get into a system and then you would have the actual war fighters wearing their their uniforms fighting them off keeping them out and then after they would do a particular set of techniques they would stop they would go outside and then they would talk about it never say okay this is what we tried what did you see what we saw
this okay well we also we're doing this over here and that sort of collaboration I think is one of the things that will help all the way down to K. twelve I think every government organization could benefit from some of that perspective so that's one of the things that we are really interested in and like I said we're we're making inroads into to working with the Arkansas department of education to help train their specifically their coops some of the coops
that are maintaining the the or the the school districts that are out there Arkansas so we're working with them and it's working out we're looking forward to doing more with that so so do you does anyone have any questions so far. Comments do you talked about the the audits I think you did a good job on the penetration test so when you go into a straight audit of an organization can you tell us about how how that's done and and what is involved in
an audit absolutely so our audience to be separated into two phases the first phase is the penetration test right so we walk in you tell us what networks what portions of your organization you want us to to work with and then we just go in and we see what we can see and we spend about half of our time doing that the other half of the time we are taking a look at the the configuration of your critical infrastructure meaning that you've got wireless access points around here you know
you've got wires going into a devices you got switches you got all these different things all of those have configurations associated with them that say this is okay this is not and so what we do is we look at those configurations we manually review them sometimes we use tools to do that to give us a sense of okay this device how close is it to best practice and where does it diverge where is it different from best practice and then we provide your up you provide your report letting you know that in some cases we're doing some
analysis of how your organization has its permissions your constructed meaning that we want to look and see okay this person can do this and this person can do that well is that a problem and if it is we want to make a make sure that we let you know. Jeff Williams. So that's the second portion of it is the we we call that our configuration review portion and then after all of that we take all that information and put it into a report this is what most organizations like ours do it this way and then there's an
executive summary and the executive summary. Provide you with thirty thousand foot view of what we saw in your environment and then a set of top findings the top findings are going to be a distillation all the hundreds of different vulnerabilities into a set of things that if you do these things your security goes from here to here we call it a qualitative increase in your security posture right it's supposed to be a big win and is essentially what do you what how do you get the best bang for
your Buck right so does that answer your question yes and then as a follow up to that how good have organizations bit about implementing those I I would. So I can I can address that because I've been doing these longer than he has for the state police for the state or the company it certainly does very what we find is that the organizations that have. As this is a the trick to trick but have the budget to have someone to have time to do that then yes they go look at them we
find some places I see the we we've we have gotten into an environment about integration testing the exact same way we got it last time and it was in the report last and they did nothing they probably put it on the desk and look at a game which is honestly at this point I was a track travesty. But the ones that are proactive the ones that do have on cities and budget with a decent staff they will usually at least address this top findings the state of Mississippi actually requires that they do when they were to submit the report they have to submit what's called a plan of actions and milestones
right so dates and things that they are going to do to fix it and when it's done so that the state knows aren't you that address these top things these top findings there are probably twenty other reports that have hundreds of recommendations of things that they do otherwise a large chunk of those probably go unheeded but truthfully speaking there many cases such a low priority when you have to balance the risk versus the cost of doing so but usually the top
findings are addressed against the state requires a day submit something right okay. The that sounds encouraging because I know I'm a former I. T. professional and I know how that the report goes on the desk and yeah Senator English thank you so let me get this clear your are you working with the department of education right now and all school districts to. To do this are you looking at
doing that we are in the sort of the initial phases we've we've gone and talk with them one on one and they've expressed an interest in providing this as an Avenue for training for them we have not we have not put a rubber on the road yet but it is something that we're looking for to having further discussion about but it is it is definitely something that we're interested in participating in and it is something that we think is going to be valuable not only for Arkansas we think it's valuable for Mississippi as well and anyone who will listen
to us so but yes does that answer questions so this is our our sales page of will. It is of the concept the concept I am I am trying to sort of me personally I'm trying to sell the concept of purple teaming in in general and I think that that having a certain. Training human capital whether it's us or someone else into thinking like an attacker. He is the that is the future of of cyber security that is where we're going to get the furthest amount of bang for our Buck if you ask me.
Thank you thank you. What are the the main threat you're saying I know malware and and ransomware were two big ones of those still the main one you see or is it that we have other things that were saying authorized I think that there's there is a fair amount of the same stuff because the same things work and they're going to keep using the same things that they keep working right and so a lot of that in terms of our
terms of clicking on the wrong thing right we're all familiar with that that that because it still works there still going to use it organizations are becoming more savvy as to how to mitigate that and the technologies are getting better at being able to spot it there we're moving towards a so called next generation artificial intelligence approaches to this and there's something to be said for that but ultimately I think a lot of it boils down to the threats that we're seeing today the the sort of the bleeding edge of threats that we're seeing today are combination of
multiple techniques at the same time right. Drainages that if if I might However it's not all leading edge and that's what the one of the biggest problems is ours now being sold as a service yes right so I can go and rent a a a missed a network of machines and go and attack you don't have to know the expertise or anything about the odds of a little bit of money and can push a few buttons so the the the the amount that you have to to with stand is not just well these are sophisticated taxing in China
and Russian those it's not just that it's and and and the ease they made an analogy earlier that you have a house built in our front door is the door to prison and they're that close right and so you're constantly fighting off the worst people in the world all they wanted to take advantage of you so malware and and excuse me ransomware that's the easiest low hanging fruit and also yields the most amount of money right your school district our senior school districts may not be
always the target of a nation state your your state agencies very well may be but nevertheless they're both the same the the the consequence may be a little bit different and the impact but they're also they're also honestly they're just as easy to get so does have to be some sophisticated genius it could be a kid down the street with a little bit of money and some YouTube videos right. So I think the the only the the the the only other thing to say is that we we may have the especially when it when it comes
to running something like to K. twelve networks and like that or even a smaller state agency we may have the of opinion or anything about it will they never gonna come after us because we're not valuable the problem is is that there's something called a supply chain. Right that every state agency as part of it just like it is where if you can get inside of a network from the hardened exterior then you have an easier time the same thing is true is if you can compromise one part of the state organization or or compromise one state organization then you very often
will have free reign throughout the other state organizations we call that a supply chain attack and that's true all the way down to K. twelve which is one of the reasons why at a national level or federal level their organizations such as he's that are they are focused on trying to help all the way down the K. twelve local governments K. twelve school districts trying to help them to increase their overall security posture because they they understand that even
the smaller school districts are part of the supply chain all the way up to the federal government so. That's the one thing I would add about the and then then the last question I have is and I don't know how much detail you can get in on this what if scenario but when they are successful the breaches happened data has been compromised. Is there a a best practices to how do you handle that because unfortunately with a lot of the
stuff that it's not and if it's it's a win and and how do we handle the when. Sure So the first thing unfortunately anything else as we definitely recommend no matter how superior your talent is in their house superior your network defenses are we definitely recommend having some form of cyber insurance because as you mentioned it so it's a win on any of the second thing to consider is going to be what type of data was taken right if it's
inconsequential data then obviously the the wrist and impacts to the revision is much less what we are seeing now though is it used to be if let's say that someone cryptid all machines in my network and they would say you need to pay me fifty thousand dollars to get a decryption key okay great well if I have a back of all my data I don't care I don't neither Christian key then I would just ignore you move on in life what they're doing now is up for instance I'm sure that you have a quite a bit somewhere in your a network of departments quite a
bit of personally identifiable information. What they're doing now is basically an essence blackmailing to say in on the second level if you don't pay us so we're going to post this all over you creation that you were hacked in that we stole all of the state at and so that's the leverage they have on you so so if you have a good disaster recovery or business continuity plan that's great but that's not always going to cover everything so well we definitely recommend if that happens is immediately if you have insurance Miller
call your insurance immediately notify authorities such as the FBI because there are cases where you paying those it can actually be a federal crime depending on that the perpetrators but always involve the authorities immediately do not try to try to manage it by yourself. Our colleagues any other questions. Taxing that gentlemen thank you for for being here for your information I think it was a
very valuable and and very insightful to us thank you very much we appreciate your time thank you. All right and now following we have Mr Askins who's the director of the I. S. is going to come give us an update on Where they're at I think is most members know he's been with the department just a little over a year now and look forward to hearing an update on the part of. An update on some of the projects we've been working on
area and what you can introduce yourself then you're recognized. The area I'm Jonathan Askins I'm the Director DIS I guess I should thank next level for setting up some nice softball questions for me to answer of because many of the things that they were recommended that we implement we started about two years ago so we're we're moving in I think in the
right direction I was just confirmation from a from that standpoint so. And I apologize there seems to be a focus on cyber security so I will move through my presentation of a bill really just an overall presentation but I move through my presentation fairly quickly so. Like this doesn't seem to be. The third is. Senator okay thank you.
So from a data center modernization standpoint what we. I started undertaking just over a year ago is we have worked with many would consider to be a decentralized or federated I T. infrastructure and the governor said that there is no way to really quantify the risk of what's you know in the various departments out there so he
charged us with centralize this and so we can begin to get a set of standards in place and so that's what we have we have done will I'll kinda gloss through those fairly quickly but there is a time line where we have started we're roughly forty percent complete of the benefits for this is. One we do set a set of standards we have a set of standards now for some of the things that you just heard disaster recovery
patch management backup we have of the same set of standards now for endpoint protection across our network and across the end points I'm glad they brought up zero trust because we are implementing zero trust architecture we have that in place in our new DCM we're pushing that out to the various agencies right now so I'm glad to know that we're moving in the right direction from a security standpoint I think it just went through the benefits that we're getting from a security
standpoint from a user experience and standpoint are very a CIO's cannot log into dashboards they can see exactly what's happening with their systems they can understand the CPU usage they can understand ram usage all these types of things were setting up a server of series of dashboards with them and then there's just the benefit of better technology newer technology that that will ultimately affect the citizens of Arkansas because they will see goods and services and products and services delivered
to them more efficiently and more quickly and then it's more resilient from that standpoint so for the first time now we have the same disaster recovery program I'll close across of the executive branch so we're we're working we have the same patch management so we've set a set of standards and settle requirements we now have two active data centers active active so we can fail over at any point so if something does happen within a matter of minutes we can fail over and and
and pull those systems back up and I guess from a standpoint of what are the efficiencies we have found so far roughly forty percent through the program we have found so far about fifty one thousand dollars a month in savings from a. Standpoint of just the the I. T. budgets that the various agencies may have we're looking at about fifty one thousand a month we're also
retiring systems and we're retiring floor space they no longer need the the floor space so that's a little harder to quantify but we we know that we're retiring systems and we know we're we're we are retiring floor space so we're getting more more efficient and we're beginning to save dollars of for the for the agency's. So I can. So that we don't like all right
so I'll kinda quickly moved through here's our time line from this perspective we really wanted to get started in the fourth quarter of last year but supply chain issues didn't allow us to really get started until the first quarter of this year I I when I say calendar year so we really didn't get started until January because the equipment didn't arrive until late December so we were able to move fairly quickly and like I say we're about forty percent
complete we expect to be at the end of this year we expect to be in the sixty to sixty five percent range and then as we move through calendar year twenty three will begin to finish up there's a pretty heavy load in the first two quarters of calendar year twenty three and that's the agencies that essentially have their own I. T. server rooms if you will we're moving those inside to the
new modernized datacenter so we think we should be done around the end of the fiscal year and in terms of June or July twenty three. So again I'll I'll move fairly quickly through this and I'll get straight to what I think folks want to talk about and that is cybersecurity so I will say in the outset cybersecurity I will talk in very general terms today I don't like to get into some of the specifics or
the strategies that we have I'll be happy to do that all one on one more than happy to do that hello what I want but I don't typically talk in terms of our strategy or specifics around our cyber security so. About a year and a half ago I hired our new chief security officer Gary Vance he had about twenty five years worth of experience in the private sector and in the
military and I ask Gary to come in and look at cyber war and the holistic approach instead of a very op what I would consider to be opportunistic approach from a standpoint of handling event after event after that with no real overarching strategy so we've created an overarching strategy I'm asking you to to do that so essentially the goals are to
create a a more aware workforce the gentleman from next level talked about creating that workforce we are starting to create phishing campaigns now from a standpoint of training folks we have a new security training module that we are rolling out this month and so and we're we're doing tabletop exercises with our very a CIO's and we're also working with the thinking institutional if you're familiar
with the fortune institute we're working with fortune from a standpoint of reaching out for training and and creating some additional training opportunities we will optimize security so a sensually being able to get everything under a single roof for a single command if you will is very important for us that's something that we've been doing in our new data center course approved performance we want to provide IT security
to the to to actually the entire Arkansas secretary I realized that my and I believe legislation says you will provide it for pretty much the executive branch in the K. twelve in the Arkansas network but at the same. Time I I understand and recognize there are local municipalities there are counties there are folks that don't have the the the level of sophistication budget that we perhaps have we can get grants
through homeland security and through the I I I I J. the infrastructure act those are primarily designed to go to the municipalities and counties. What we've asked system for permission for and we've asked the administration for permission for a talking about administration we've asked them for permission for is the ability to look at this more as an enterprise level so many times you you may receive a million dollars in grants but if
that's broken up into a hundred and seventy five different pieces you have fragmented that grants so much that it's not really effective and so what what we've asked for and received permission for is to do it more than enterprise level to where we look at things in administer and still make sure that ninety percent of the dollars get to the county send them and the municipals but at the same time we're looking at for more of an enterprise level
standpoint and we found largely when we visit with the municipals that. It is more than awareness standpoint helping us make sure that our employees or where so the things that you know from from a phishing campaign just creating that kind of awareness creating that security trial training a lot of those things will go a very very long way there are a lot of what I would consider to be guard rails that are our smaller
communities could put up that are absolutely free that would protect them a long way what we've discovered is that sometimes they may be purchased from a vendor a twenty thousand dollar piece of software and they think they're protected and they're really not so what we're trying to do is reach out to them and help them understand the levels of protection some of the ways that they can do it for for for absolutely free and and be more protected from
from than just buying a. Piece of software. Okay. So we set up our core framework our core framework is essentially to identify protect detect respond and recover. I'll focus a lot for all identify from the standpoint of yes we are doing penned a pen testing as you'll see in the in the next slide we started creating retainers so we can have our folks begin to do pen testing we're trying to do
assessments across our entire infrastructure right now and that would include K. twelve so we're starting to look at it identify where your vulnerabilities are identify your threat landscape is the buzz word that everyone uses so what we're doing right now is we're trying to identify what that threat landscape is it changes daily but we start to look at that add an identification standpoint then
we we we put in place what we consider to be the stop gaps for those vulnerabilities we understand where we're vulnerable we understand or threat landscape and we put in place to the to the extent that we have the budget to do so but we put in place stop gaps. All along the way from that standpoint course we're we're constantly detecting we did set up twenty four by seven monitoring service over the last eighteen months uh we have two different systems are two different services that are
giving us twenty four by seven monitoring at this point we have what is called a sim which is an internet event manager essentially where it takes all the Loggins it takes all of the activity and it's just constantly charming that activity looking for suspicious type of activity and immediately our folks are alerted we take a look if there's something that we need to do we we going to response mode so then we respond.
If it is a situation which. I don't know if this is would or not but not COVID we hope that we're in a situation where we don't have to recover but we are prepared to recover if we need to do that. So these are the the areas that we have put in place over the last eighteen months for security you can see there we we we have programs that are
largely involved around San management we we we. Put an emphasis on MFA making sure that most of our our agencies and departments and divisions and schools have MFA in place that is a tremendous deterrent but if we have the MFA in place you can see pen testing but these are a number of the programs that we put in place over the last eighteen months really creating what I would consider to be
our threat environment or are. framework if you will from that standpoint pretty I'm I'm very pleased. As how we have made progressions in security I feel like we have moved from a reactive security force to more of a proactive security force I feel like we still have a long way to go and I continue to challenge our folks to move to being more proactive but I feel like we've
made that shift from a reactive to a proactive force so. I'm going to pause at cybersecurity because I know there may be some questions and I'll be happy to answer those. I don't see any but I'll she wanted okay that what what what percentage of of state agencies are currently within the data center right now and is the the effort to try to get everybody in or just certain ones are kinda like its I can speak for
the executive branch at this point so from the executive branch standpoint we're we're about halfway through and then that time line that that I share with you to to finish would be the executive branch so obviously I would love to have discussions with others but right now my focus is was on the executive branch so right now we're trying to get all the executive branch all the different various committees within the executive branch or
agencies within the data center yes Sir right. Thank you Mr chairman my question kind of relies on maybe scale one to ten we deal in so many citizens data. The cross various platforms whether it's R. naught state police taxes etcetera where are we on a zero to ten in protecting and I know it can't ever be at ten but where are we are maybe where were we when you started you said we've gone from reactive to proactive where are
we with cyber security with regard to personal data of our citizens while. That's a good question because that's really all the matters doesn't it it's I would say we are trending Gosh. Somebody would probably argue with a number but I would say that we are upwards of seven trending toward toward a ten at this point obviously we're not going to reach a ten in full awareness of
that but I would say that we have put a number of security things in place and it's again I don't want to bore you just by reading your present by reading the presentation but it's it's then the presentation we have created a number of different. Programs we have bought products we have bought Services we bought monitoring so I would say. Seven trending toward a ten.
I appreciate that I know Senator English and I were at a meeting how long how long ago was and they were telling us we were on a zero to ten in the two to three range so that's a dramatic improvement and I appreciate all the work that's going on. Representative love your next. Thank you to Robert there Mr.
Thank you Mr so as well as we talk about training toward seven as a as a committee what can we do to to assist your efforts. Well first of all I've I probably need to be more aggressive in making sure that update you I should probably read be reaching out my office and my missus so we should probably be doing more of a an aggressive start on on our port in terms of
reaching out to you there will always be I will always try to come to you and and not trying to scare you I don't I could do that if I wanted to but I don't want to do that what I want to do is lay out information and a plan to get there. That is very budget conscious so if we do have a situation where I feel like we need an an additional appropriation or we
need additional dollars I would visit with you about that okay but I'm a cost recovery agency so essentially I push out my cost in my expenses to the agencies so it could be that I'm simply informing you of these are the additional things that we're putting in place you'll see this when the agencies come forward with their budget from a cyber security standpoint I would ask you to remember that
is all. From that standpoint when they when they come to you with their budget request I understand that there that I may be coming to them saying we're going to have some additional cyber cost and and just make sure that your cognizant I'll try to make sure your contents of that video and and then also on on the on the side of the executive is as far as you say you know you're at fifty percent In your you're trying to close intent on the one hundred there's not and there's no additional legislation or
anything like that necessary to make sure that that happens no not at this point no Sir no Sir read some states have mandates to get this done nothing I think Louisiana has a mandate to do this and I think Oklahoma has a mandate and people have asked me what would you like to mandate the mandate would be great but at the same time we have discovered some real business issues we have surfaced some real business issues when we sit down and talk
about the complexity of bringing an agency like public safety into our data center well there's a lot of complex issues that you've got to work through and a mandate may not surface those issues if you have a situation where you've got two sides they need to come to an agreement on moving in there's a lot of business issues that get surfaced that can be fixed so. A committee that would be great but at the same time I feel like the process that we're going through now is really going to
be more beneficial just means that I have to put a sale sat on but at the same time I feel like it's more beneficial for us in the long run to go through these business issues and wrestle with them now okay in Mr chairman last question is this is is it was something that was brought to my attention From another state. As You DHS and in other entities worked with cities and counties.
In their systems can can possibly be linked to ours is there anything that you have that would. Provide the protection to I don't know if if we want to say we want to try to expand in the cities and counties but. What is it that we can do. To the system as well as this body I would need to think on that we need to think through that but I would be happy to visit with you if you reach out or or I can
reach out be happy to visit with you we do have things in place that okay that handle some of what you're talking about at least I think where your question is heading we do have those kinds of things in place I'll be happy to visit with you and share that with you okay and as well as DHS has their own security officers well we can sit down and talk about that make sure that it it it's what you're what you're thinking okay. Thank you Mr thank you and kind of along the lines senator English and I have been working
with the and having some meetings about how to address that issue is that right after Mr Aston's came on board I was started talking to him about how do we make this a statewide their scope is primarily just the state agencies but obviously cybersecurity is a runner we want a holistic approach and so we've actually been kind of working on something and we we probably need to you would definitely need to get you all involved and and what we're working on on this well to have
something driver ready for ready for the session okay that are at. Senator hammer or you're actually thank you Mr you've mentioned K. twelve on several occasions are you talking about the agency when you refer to K. twelve in the comments you made referred to the network the K. twelve network yes Sir okay and do you lend any support and I know there's some career technical schools that offer in cyber security courses think maybe one of the issues is
finding a qualified help have you had any discussions about how we could network what you do maybe with you know the of high school or center in the career tech centers going into this path of career path and and what could be done to kind of bring them into the fold for your site purpose. Yes Sir I've had some very initial discussions regarding that but I I firmly believe where where you're I think where you're headed is from a standpoint of many times our community in our career colleges
are the ones that are going to be actually looking at. Cyber security sometimes we think a computer sciences degree is going to equate to a cyber that's really not what we're looking for it actually we're looking for a gamer that spends twenty four by seven in front of the computer and so if we can reach out to that very narrow sliver of of folks and and really entice them that this is
a and a great career then we're we're trying to do that we're hiring apprentices right now through the ACT S. program so what we're trying to bring on is apprentices that have the what I guess what I would say use of have the capacity to be an I. T. professional or cyber security professional they may not have the certifications but I'm not worried about that I'll train them in those areas I just
want the aptitude and the desire so we're bringing them on as apprentices and trying to move them forward I I I think we're getting ready to hire some of our first apprentices this month we're in interviews right now okay thank you yes Sir. Senator English so just how to carry on with what you're you're talking about the cyber security thing into a big issue but I know that UALR has their program that. We're really trying to spread
the resources out to the local communities community colleges and in many cases some these are adults who have not really ever thought about being in cyber security but a member for a community that bill or for a bank that may work for a hospital and they need to have that security I mean that cybersecurity certification to bring them up to speed which gives them an opportunity for more money but it also gives an opportunity for people who've
never thought about it before so I'm really excited about what they're doing because they're spreading the resources out to local communities that and we don't always get to have those kinds of of efforts because they don't have the resources but I think it's exciting so that are you gonna move to then to this whole data thing to the A. R. data I knew you would like that I love it if you know what that it's just my passion is been my passion for a long time we've got a transparency we've got a
longitudinal study we've got all kinds of stuff I'm excited Mr chairman you okay with me moved please continue thank you Sir. So we will talk about a our data from the and and the things that we're doing there and I'll just straight go straight to this one essentially what we're doing with our aid A. R. data program is we're working to try to create data driven outcomes and so what we do at
DIS is we take data from the very agencies and maybe DHS may deter be DWS it may be the department of corrections we're taking that data and and our sole focus is on making sure that that nation datas rationalized that we link it that is correct that is complete that it's a that it's a pristine dataset if you will that can then have additional data put on top so you can model so you can run a I so you can run varying
types of services all that and really create some. new products if you will from a from a standpoint so so our focus is been on the. Creating a pristine set so we can combine new data sources to create new data products of a true data driven outcomes so if you. Take a look at our products I'll just bring a couple to bear
so the economic security report in the past the economic security report was basically a static report that came out once a year and we have created a situation now to where you can log into a tableau portal you can take a look at all of the the changes that have happened I wouldn't say near real time but I would say weekly aye aye so
school counselors people who are making guidance types of decisions to our students are able to look at economic gaps across our state in almost I mean it in in weekly types of information see here of the gaps and if you're thinking about a career in staying in the State of Arkansas this would be a great area for you to start putting your skills and putting your studies together and and that's the whole purpose of the S. R. is to be able to do that across the state so we're doing that at the at the high school level from the S. R. we're working with higher education and Dr Markham and and making
sure that we're helping to train our folks and we're using data the data that we already have we're just combining different data sets and creating some new and enhanced data products we're pretty excited about it I think Senator English is more excited about it than I am but but I will say that the economic stability report not only are we doing it and creating what I what I would consider to be a much better product but we're doing it at a much more costly way
yes are used across the state three hundred and fifty thousand dollars and it was a single static report it it it didn't cost the state any thing this year because we essentially had grant money to pay for that so and I will say that the entire A. R. data team is. Only sustained and funded right now through grant funding one hundred percent grant funding so we're creating a lot of new products and new services of with grant with total grant
funding and I will. Finish with an example of another state far west maybe as far west as you can possibly get they spend fifteen million the they spent fifteen million dollars standing up the program they spend twenty million dollars a year putting a program together their next data driven product will be their first one so we're quite proud of what we've been doing in Arkansas
with grant funding and and Senator Pitsch I think at one point in time you and I talked several months back and I mentioned to you the Arkansas is leading the way in this and we continue to get confirmation on this every time we go to conferences people talk about look at the stuff that we we get lumped with Arkansas Arkansas Alabama get lumped together quite frequently but look at the things that Arkansas student look at the things that Alabama is doing its we're doing some incredible
things around the transparency in bringing data together so. I'll again pods for any questions. Okay I think I'm almost as excited as Senator English here because I'm the one who passed the legislation to create the open data and transparency in and seeing it come to fruition like this is this is what you are doing is great representative brown. Thank you Mr chair I have one welcome to questions
is this of the project that will enable our Kansans to logging into their account and renew their fishing license and their driver's license all in one spot it would really be nice to do that and yes ma'am this would create the infrastructure to be able to do that yes ma'am and my other question is will this be the infrastructure that will allow I think DHS is one who would do this to find dead beat.
Errands maybe by tracking down their address after they buy a fishing license something there there is always a fraudulent element from a standpoint of bringing together different data sets how how we choose to look at that I I think is yet to be determined but anytime you bring together datasets. You can use that for detecting fraud of not only detecting fault the fraud but preventing
fraud right now the program is focused on efficiencies around delivering services however anytime you bring those data sets together there there can be some fraud detected and and in the future it may very well be used for that well. I don't know whether this is exactly fraud but I mean when somebody is in the system at one address and you're unable to reach them to have them.
Cough up the money to help support their children and then you find that they've bought a fishing license and they're at a different address that gives you the opportunity to go check at that address it could now that is that's fraud county is but you know maybe it's unintentional but yes ma'am. But that I think that's important I mean there's a lot of kids go without financial support yes ma'am I would agree thank you.
Senator says Megan this topic allowed. But one of the things that in in re regard we are having some conversations the I. S. is with a number of other state and some of our group meetings to talk about how do we gather all that data input it now it may be down the road years but the opportunities are there to be able to gather some of the data in your right we work very closely with Alabama in a lot of other states because we all have an interest in having in in in
operable interoperable whatever that word is system so we're we're not Siloti in this state and it's just our information is how do we make it so that we can share all these things with without in other states so we're talking about whether or not people are working in Missouri or whatever we've never been able to do that before but but now hopefully this is a law a lot of really good you have some excellent staff over there that have been at least we do and I I'm I couldn't be more couldn't be happier thank you for that
I'm thrilled with everything that's going on. Thank you. Okay so for future initiatives some of the things that we're looking at from a future standpoint is one we're always working from an innovation standpoint around cybersecurity of so we're always trying to sandbox things make sure that from a server standpoint that we are on the cutting edge the second area that we're focused on right now is
looking at efficiencies I mean every phone in our excuse me every desk has a phone we might not need to have every desk having a phone we all have a computer and we have a hard phone do we need all of that equipment maybe not so we're looking at things right now from a standpoint of how can we be more efficient from a communication standpoint getting our job done and we're going to try to create some pilot programs along the
way where we look at would soft phones in the computer save us some money so those are all just future initiatives and I talk about but it's we are largely driven around two things protecting the state and and squeezing every dollar every bit out of the dollars that we get squeezing those and being more efficient so those are those are really our our initiatives.
Well I have force this morning that's it you know that are out there that that that was great we appreciate the update the work you're doing and I'm very excited about what you're doing for the citizens of the state in Virginia. Keep up the good work thank you. next we have Mr Norman Mr calls from a legislative audit Mace similar weird at first that we have the auditors here but they're the one. Organization that touches every
school every municipality every county in the state and last session with passing legislation that requires cyber incidents to be reported to them and then We're looking at how they can be a role and helping us in the cybersecurity fields I've asked them to come give us an update on the reports were received about what incidents have occurred and that gentleman if you would introduce yourself to the committee you are recognized to proceed.
Commission chairman my name's Roger Norman I'm the legislative auditor for the state. Thank you Mr chairman my name is David Coles legislative audit. Thank you Mr chairman Amos Kevin White currently staff auditor insisted legal counsel but I was named this past Friday is the successor to Mr Roger Norman to be legislative auditor. All right and you're recognized thank you I'm a first off I'd like to thank the General Assembly for for passing this legislation I know.
A representative makes we work closely with you on this and it was it's very important and our risk assessments of the oddities that we have so it's it's been a very valuable piece of information we're not experts were not cyber security experts I'm giving this to you from a layman's perspective we're auditors for CPA's recesses and When when the act one act two sixty was first passed
what when it was passed we stood up a server within information systems reporting mechanism. To collect this information we try to make this as simple as possible but No we found that it wouldn't is is easy as we thought it would be because we're relying on the information that's being reported to us as far as you know the types of incidences that are occurring. So on on the form when you see this and you see something that
you you don't understand I I'll try to explain them here in a minute The. This is the worst security incident was chosen over cybersecurity incident because it's a broader term and we wanted to capture all manner of incidences that were happening because we simply didn't know before Act two sixty there was really no other. Broad reporting. The requirement for the state of Arkansas other than what is
reported to the Attorney General. We've learned a lot of things over the past year one of them being that. A lot entities are really uncomfortable talking about cyber security and I think this has a lot to do with the of the lack of a what cyber security awareness. In an audit terms you know we see a lot of federal requirements like through the Gramm leach Bliley act which basically affects higher
education more than anybody. But there is a strong requirements for cyber security protection one of those being cyber security education for all employees it's not. It's mandatory it's not voluntary it has to be done. And through that. Process we see a little better with higher education a little better understanding little more openness to to discuss this with
us. Because we are an audit agency we we don't really want when something happens and we get a report in a look at the report and I see if there's anything I can do that to help them you know we don't have a lot of resources as far as how we can respond to but you know many times I would referring to Mr Vance for Mr asking from the I. S. and they may or may not reach out you know it some of them
dead and just talking with Mr Vance you know he would reach out to or they'd reach out to him and they they basically tell on that you know we've got everything under control we're we're okay so go away don't bother us any if you have to remember that when these events happen it's a shock to the system and you know we're not talking about state agencies or higher education we're talking about some small cities water departments simply aren't
capable or have the capacity or the expertise to deal with something of this some of and of this manner. It It. For lack of a better word it was it was just the shock in it some of them just like froze you know when I would talk to and they would not know what I would want to do what they wanted to tell me or you know they had maybe reported to the local law enforcement and local law enforcement didn't know what to tell on.
And I had a standard response you know we ask him to you know what if if depending on the type of event with asking reported to the FBI of course local law enforcement was first and foremost. And. You know Sturch. Remediation responsible mediation efforts immediately. you know there's the law requires them to report this within five days of the actual detection of the events that in always happen.
I think some of it was that some individuals were unclear as to what exactly had happened. you know we we gave them a little bit of a break this year but you know we're we're gonna probably you know be a little sterner going forward because you know we realize that the sooner it can be remediated the better off they are. We we track the incidences is best that we could.
Anything that that we saw as a trend for instance one of the ones that you see on the list was fraudulent transactions which constitutes twenty three events which was the most that we've seen. That that was everything from a fraudulent check either a check that was intercepted in the mail somehow obtained washed the pay E. changed sometimes the amounts were changed.
when we start seeing there's and there's definitely an uptick on it now we notified the Municipal League the association of counties they alert their users to be on the look out for this you know to regularly monitor your bank account to reconcile And to make sure that these these that word gets out there because. In the event of these fraudulent transactions especially with the checks most individual cities
and counties that were affected by it wouldn't just cities and counties it was K. through twelve some state agencies community colleges If you don't recognize that pretty quick and alert the bank you can be out some money we had we had several cities and counties that that felt that that didn't get to a quick enough and they were financially penalized for that because the bank if you catch a quick enough the bank will make you all.
But how how what's happening why it's happening. You know there's it leads to federal agencies investigating it and there's really no good explanation for why it's happening we know what's happening all over the country about two years ago it was two is rampant in the state if if any of you were in the local committee meetings you probably remember seeing a lot of these findings comes or.
Are there if there's any questions related specifically to these reported events I'll be glad to answer those otherwise I wanted to move to the next you kind of mentioned this so will these incidents show up on findings on those an individual entities. And other arts brought to the. Audit committees as of now we have a plan on putting in in the
report it It simply because we want to encourage. Eight individuals or a governments to report this to us you know we're we're basically on the honor system and I know that there was a lot of trepidation from some of these reporting entities like you know what's going to happen or we're going to get a finding we don't want to deter any of that you know with audit obviously they're always afraid of getting a finding for something like that unless there's something in gregis.
You know we won't write it up and if we do write it up depending on the nature of it it'll be communicated them to them in a management letter because that's not something we would want to broadcast in a report you know we try to protect the identification of these entity so there doesn't make him a bigger target and and and to make sure that they understand they need to report it and that we're trying to use his information to better. Thanks Brian for.
Senator English. So I remember that when you do auditing of of communities and schools at all that there's a little place in there for backup plans for their computers thank. Could this cyber security kind of fall into that same sort of category without maybe. Put the hammer autumn but that issue say but but probably and so at some point the that needs
to be included certainly and and that's what we do we do look at that in that respect we have what we call our review of computers where we do look at security logical security of access security we will get back up plans is a disaster recovery plans remote access policies wireless policies when we see a failure in those endeavors or in that area we will write him up the
main issue with especially the cyber security events is that unless they resolve all they can in law enforcement take time for it can take years for it to be resolved I mean we've we've talked to the secret service the US postal inspectors the F. B. I.. Some places is just not a problem you know and local law enforcement albeit some or do have capabilities to investigate this. Most of them don't don't and you
know we were at audit we're retraining some of our information systems auditors towards cyber security. So we'll have a better understanding and grasp of it and be able to actually get into some of these these areas and and restarted and look and see if we can fifteen years ago this was not a not an issue no ma'am but it's been the last few years it really is issued it just seems like it's and something that just kinda needs to go along with.
How is your computer system and because if you think about it we're talking about kids records and family records said all all kinds of things so that need to be protected thank you Senator English we're we're looking at in minutes we don't have the the staff to do it on all the audit so we do but we do look as David said on the computer systems we look controls and everything one of the things we don't do right now is my understanding is the penetration testing and by that I mean that's something that we
could do but it's not of our practice right now to do that that's kind of like in a school district the or even you look a little rock all the high schools sell the elementary schools all that'll that's a big job because it it it goes cross not just that quarters but across the board. Yes ma'am I I think that any of the cyber security events it's going to take a lot of coordination between the various entities but I think that we do have the the communication and
have those relationships particularly with the the local entities that we could be of the law are of great benefit to them okay. Thank you Mr chair I have a question and it's kind of general but help me understand school districts municipalities do they all just sort of have standalone computer systems or
when they come on and log into their system each day is it part of an integrated network that is monitored by you all are somebody so. With K. through twelve a lot of the school districts around most the vast majority of our own apps can which is the state applique of financial applications and student tracking There are there on the K. twelve network but individually within
the school district they they have their own local network. Apart from that municipalities and counties they're all different they're all stand alone. You have different levels of what I call sophistication I I never want to demean any county or city or even Kate K. through twelve I. T. person because there's some really good ones out there but it boils down to resources as far as what they
use you know like in counties there are some specific vendors that set then that works out for the county's they use the same accounting software cities are the same but there is a multitude of vendors that maintain their networks. Well. Now you may scoff at my attempts to be secure at my own home but I use Norton. are are they using something to
help protect their networks so with our reviews when we go in and we perform audits RSC hours we look at the the basic elements of security in one of the things that we do insurers that they use some type of virus protection and that virus protection is established and set to automatically update. You know and I'm I thank you for to mention a couple times before but. You know users for the we're just a week is lame because
whether we download something through an email or you know enter something in the U. S. B. drive there's always risk based Lycoris zero day virus or malware or something so there's always going to be risk but we we do our best. To make sure that basic security standards are out there we even issue what we call best practices to all the cities and counties all the agency agencies we audit
that I guess you would call it minimum protections yeah a lot of these cities and counties don't either have the financial resources or simply don't have the personnel that can achieve these levels of security so we we do our best to help them but you know being non audit group there's a line we simply can't cross so they rely on vendors and we communicate with vendors and we do our.
We do a pretty good job I think working with the vendors just one last simple question I mean a. I mean are they told you know you don't use these computers for personal email or your personal banking or your personal business or to check Facebook and all that sort of stuff they told that is absolutely forbidden and if we catch you doing it you're going to. We're going to. Scold you are some fire you are something we do you know in those cases where we find.
And in those situations we will write a finding depending on how they're using that computer I will say that a lot of cities and counties have really over the last twenty years I've really done better as far as knowing what the dangers are out there and minimizing their use their personal use expressly with Facebook because there were times when. A federal elected officials you know with they were running for reelection they would have their
Facebook page up and we would walk right in and go. You know I I tell this story alive but when I first started doing this over twenty years ago I would walk into an office and say well where do you keep your password and a lot of them we just picked their keyboard and just look at so or if if it was on a post it note. Taped to their computer screen or whatever so it's come a long way there's still a long way to go. And I think we can continue to
educate. These these people and I'm I thank we'll get there some day. Will get better thank you yes. I don't have anything else forces one. Just a quick note on you know we talked about the collaboration. Endeavor that we hope for a while but what we're trying to do is we seen. Other states create
collaborative efforts with state government at all levels of state government City County K. through twelve state agency president south Carolina created a collaboration without one single piece of legislation I thought that was remarkable I've seen a few presentations on that I don't know how. Detailed we can get into it but we are starting. We were meeting with the different associations I've I've talked to Mr Askins a couple
different times he's definitely on board with what we're we're trying to do and we hope that we can put something together that sustainable meaningful and helps not just local government but all citizens for the state of Arkansas. The. Any other questions. John thank you and thank you for your oh eight Senator Senator English jump in here last. So over the last couple years
I've been looking at the whole cyber security thing and there are states that have like Georgia and South Carolina and all that that really have a total entities so we're not out by a little piece of software over here and we don't have a little group set up over here and but we have some kind of a governance thing where we're looking at the big picture for all of it rather than just an individual state agency or K. through twelve or higher ed or whatever the case may or community whatever the case may
be so looking at it in totality and much better able to use our resources and gathers resources together and collective minds so I'm I'm all for which try what we're trying to do thank you thank you John thank you. All right and last but not least Our. Merry go. I have a I've asked our our new
of broadband manager to common just spend a few minutes to introduce himself to the committee and sorry we're down to the bare bones here but The yes the important people are here definitely but once you get settled if you would just introduce yourself a little bit about your background and your your vision for the office. Thank you for having me so first you know was a thank you to governor and secretary I pressed. Four forty to me this this very
profound responsibility and opportunity that I have here instead of Arkansas also think chief of staff Hudson under court and honestly the current mission. So we should Curtis who is my favorite persons was to say that as they have been instrumental in guiding me on in this last month representative Meeks thank you in the Committee for have me today to introduce myself and give some brief comments because I will not keep you from watching very much longer. Audley I also think members of the assembly and your staffs
because without would you do we would not be able to be successful as a state. Again my name is going how we I am the director of the Arkansas state broadband offices working day thirty for me so I'm glad to be here on this first anniversary with you and will be back on myself I come to this office in the state from the Louisiana office of broadband development connectivity you know there was little of a different situation there we first started a year ago we got in with one piece of legislation that have the very sort of basic
foundations of a grant program and we have the bill that office from scratch so was very interesting I really we sort of became noted for it for two things one selling up and moving very quickly and secondly I have a very innovative and thought leaders in the province Business we're going to do here in Arkansas so I quickly vision for the Office moving forward and I said this to everyone that I've come into contact with including some members here today right we want to be a leader in the south and a top ten state in the country and everything that we do in all things related to broadband Arkansas has a great
story to tell would have to tell it is the twenty twenty you'll notice it is given out nearly forty million dollars three or ninety two million to be exact in broadband infrastructure grants and that number I would least lead most states around the country into something we should be proud of and they want to build upon the success I'm moving forward you know moving beyond just the grants I wish reporting and foundational you know broadband in my opinion truly is an all state issue that requires all state effort to provide all state solutions and in order for we're gonna focus
not only on the infrastructure slash access fees we have to focus on affordability and we're also going to focus on the digital literacy an opportunity that can come from that I've used this before as well but I'll say it again right we can make Arkansas the most wires in the country with broadband running to every single home and business in the state but if some are Kansas can't afford it then it's a problem it's a wasted investment likewise we can be the most whites in the country we can make it free but of our residents understand the value that it can impact transform their lives of them have the literacy skills
necessary or they don't have the devices this. As Jerry to take advantage of it that's also a problem and also it was that investments are really moving forward the future is very bright Arkansas has a great story to tell we're gonna tell it we're gonna be innovators and thought leaders in the broadband space and I can't wait to keep going so thank you. Thank you Sir Mr wish more folks have been here to to to be part of the adoption but I have no doubt you'll you'll definitely be visiting with us more in the future we look forward to worker going to do and
My committee analyst says reminded me that it has on or before you kind of the. Not under the bus here but responsibility the new broadband manager has to issue a biennal back annual report to this committee about the state of broadband within the state it's within the Arkansas Code we get that code section but didn't. As the new broadband manager want to make sure that you were aware that that was one of one of the new responsibilities we
we have for you and we will be looking for to those reports and progress updates as we go in the future by any other committee members have any questions for our. Senator English we can't just not that you have any questions. So we are very thrilled to have you here we're excited about the connectivity the affordability in that digital literacy so critically important their workforce issues here in the state and but we're excited in
either I know you can be out and meeting lots of people the state and I appreciate that very much because this is a community thing it's not it's not State Capitol thanks it's important to all the communities I have so it's very important to get out and and we the people you know where they are listen to them it's extremely important to hear them I think and I committed to this last Thursday and committed against a second last Thursday of the county judges association meeting and again Saturday evening at the Arkansas like mayors association I get the other that is my intention to is
it also in five counties by Christmas and so when we do that of course the senators and state representatives will be invited to those events and have town halls and speak of our all their cans and so and I look forward to seeing you on the road and of course I'm sure many discussions that will have to follow well we're looking forward to working with you we appreciate you thanks very much thank you. Bills. Okay saying not thank you Sir welcome to Arkansas we'll look forward to seeing what you're gonna be able to accomplish for our citizens thank you.
All right I guess that is the end of our agenda for the day so saying no further business we are turned.
Agenda
A. Call to Order
B. Consideration to Approve the November 17, 2021, Meeting Minutes [EXHIBIT B]
C. Presentation of Cybersecurity Practices at Next Step Innovation [EXHIBIT C]
D. Presentation of the Department of Information Systems (DIS) Activities [EXHIBIT D] - Jonathan Askins, Director, DIS, Transportation and Shared Services
E. Presentation on Security Incidences
F. Introduction of the New State Broadband Manager - Glen Howie, State Broadband Manager, Department of Commerce
G. Other Business
H. Adjournment
Documents
| Title | Type | Pages | Source |
|---|---|---|---|
| Agenda — ADVANCED COMMUNICATIONS AND INFORMATION TECHNOLOGY - JOINT, Sep 12, 2022 | Agenda | 1 | Official source ↗ |
| EXHIBIT B - 11-17-2021 Minutes | Exhibit | 1 | Official source ↗ |
| EXHIBIT C-NSI Handout for Cybersecurity | Exhibit | 7 | Official source ↗ |
| EXHIBIT D-IT Communications 9.12.2022 | Exhibit | 17 | Official source ↗ |
| Handout Cybersecurity Incident Report | Exhibit | 2 | Official source ↗ |