Original Coverage & Source Attribution: www.govtech.com
A little more than a year after standing up its State Cybersecurity Office (SCSO), bringing 15 state agencies into a unified group, Arkansas is moving toward whole-of-state cybersecurity.
The Arkansas Cybersecurity Act of 2025, which became law April 8, 2025, gave state CISO Gary Vance responsibility for cybersecurity across the executive branch and governorās office. A few agency CISOs have since joined the SCSO and report to Vance, and more are expected to follow.
āOver the past year, we have been working feverishly to get our state cybersecurity policy in place,ā Vance said Thursday during a panel conversation* at the Cyber Civil Defense Summit Central, hosted in Baton Rouge, La., by the University of California, Berkeleyās Center for Long-Term Cybersecurity.
āImagine trying to have 15 individual cybersecurity policies,ā he said. āWe now have one. All the departments roll up under that primary cyber policy.ā
The state cybersecurity act, combined with an executive order, streamlined cybersecurity oversight, improved risk management and enhanced response across state agencies. SCSO sits within the Office of State Technology, and both are part of the larger Department of Shared Administrative Services.
But the state is also pushing to have local governments observe a minimum level of cybersecurity standards. There is legislative work underway to bring whole-of-state cybersecurity to public-sector entities which, Vance said, have fiercely independent leaders. The local government landscape includes 75 counties with 75 elected judges.
There will be challenges, not all of them pleasant, Vance said after the summit. He has been through similar growing pains as a private-sector executive and, having worked at a global-level enterprise, said he āunderstands how to take on large-scale cybersecurity.ā
In Arkansas last year, there were 10 to 12 ransomware events across cities, counties, schools and sheriffās offices, he said. But a November 2022 attack on a third-party vendor downed many counties and overwhelmed locals.
Apprentice Information Systems (AIS) ā based in Arkansas ā suffered a cybersecurity incident that affected about 55 counties according to news reports. Vance recalled that services in affected counties were offline for about three months while the state office worked on recovery.
And, because the networks were connected to the state network, the CISO said that it was too risky to reconnect until resolution was complete.
āIt was a hard pill for them to swallow.ā
With ransomware, business email compromise and identity threats continuing, it is inevitable, he said, that the state will mandate minimum cybersecurity standards.
āWhole-of-state will happen like it has in other states,ā he said, pointing to North Carolina, Texas, Louisiana and Oklahoma. āOne way to do that is through legislation, and it will be legislated ⦠. Honestly, that will be another yearās worth of work.ā
*Government Technology Staff Writer Rae D. DeShong moderated the panel discussion.
Rae D. DeShong is a Texas-based staff writer for Government Technology and a former staff writer for Industry Insider ā Texas. She has worked at The Dallas Morning News and as a community college administrator.
window.fbAsyncInit = function() {
FB.init({
appId : ‘314190606794339’,
xfbml : true,
version : ‘v2.9’
});
};
(function(d, s, id){
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) {return;}
js = d.createElement(s); js.id = id;
js.src = “https://connect.facebook.net/en_US/sdk.js”;
fjs.parentNode.insertBefore(js, fjs);
}(document, ‘script’, ‘facebook-jssdk’));




