Former California CISO reflects on cyber’s importance in state government

ANDREY DENISYUK via Getty Images

Now a senior advisor at World Wide Technology, Vitaliy Panych said his aim was always to make everyone a “risk practitioner,” while managing an enormous state infrastructure.

After nearly 20 years working in California state agencies and having served as the state’s longest-tenured chief information security officer, Vitaliy Panych is starting a new chapter in his career.

Panych recently joined technology company World Wide Technology as senior cybersecurity and risk advisor, having led the development of Cal-Secure, the state's first multi-year cybersecurity roadmap, and provided information security oversight and services for more than 140 executive branch entities as well as cities, counties, special districts, schools and more.

It’s been quite a journey for Panych, who said he joined WWT after being impressed with the “culture” of the company and its “deep bench of expertise” on various technology issues, whether it be cybersecurity, artificial intelligence or modernization.

Panych recently sat down with Route Fifty to reflect on his career in state government and the challenges ahead.

This interview has been edited for brevity and clarity.

ROUTE FIFTY: How would you say that the government's relationship with technology has evolved?

VITALIY PANYCH: At a massive scale, needless to say, technology's being used to issue benefits, facilitate permitting, enable public safety. Technology is literally embedded into all of our daily lives, and embedded into every mission set and business operation within state government. That's a good thing. It certainly adds a considerable amount of efficiency in how government does business.

However, there's definitely risk that needs to be balanced, that needs to be managed. Suffice to say, my mission when I first started in government, my goal or agenda, was I wanted to make everybody a risk-managed security practitioner, or a risk practitioner.

What that means is knowing what the upsides are when you adopt an attack surface or a level of technology that obviously can and will be abused, and then what are the downsides, and being able to objectively quantify that. That's what I've been doing over the past year, and that's what my role was within state government as the California CISO. I played that CISO role to about 140 different agencies and helped them shape their security programs, helped them convey those security programs where it makes sense in how you measure risk, where is it reasonable to handle that risk, and then provide pathways and roadmaps to help mitigate that risk.

It's not only me by myself. I relied on really talented security practitioners within the state that would make any commercial, board-level member for the dollar spent be really impressed because, obviously, public servants are underpaid, always constrained, but they certainly do a lot to scale risk management and mitigation practices and translate them into operations.

When I first started being the CISO, we developed and released this Cal-Secure roadmap, which is a universal roadmap applicable within 140 of our state agencies, and then it also eventually prevailed over time into a lot of our partner public sector organizations. California is pretty big, too: 140 different executive branch agencies, 500 cities, 58 counties, about 1,000 school districts, 2,500 special districts. Those could be water utilities, those could be municipal or regional transit areas.

There's a big ecosystem where organizations work with each other, so it needs a common framework, a common taxonomy to bridge what we do and how we operate as a common operating model between the state and local services. I was really proud to get that released, and we also released last month a version two of that. Version two of that encompasses a lot of risk management tactics and mitigation strategies around AI, which is top of mind for everybody these days.

ROUTE FIFTY: I know it's not all on your shoulders when you're the CISO of California, but you've got all these cities and state agencies and special districts, and you've always got someone trying to get in: hackers and nation-states. What's that like on a day-to-day basis?

PANYCH: Back seven or so years ago, we realized there was even back then quite a significant intake and amount of suspected cyber incidents and breaches and events.

So, we built up what we call the California Cybersecurity Integration Center, which is really intended to be the backstop for those decentralized organizations that are not under our authority, and really provide them some services, such as coordination of incident response, escalation coordination within incident response [and] collaboration with threat intelligence sharing. We have a big net from our Security Operations Center. We receive quite a bit of volume and day-to-day telemetry around gaps, vulnerabilities, threats and indicators of compromise.

We get an opportunity to use that net of things that we capture and provide actionable operational telemetry that those downstream organizations can react to. But then, over time, we've evolved the CSIC and some of the California Department of Technology services to be more proactive, like conducting more proactive risk assessments, continuous control validation mechanisms. I always like to say it's one thing to put in a security defense mechanism and a control at a point in time, but that needs to be continuously validated and tested, because the threat actors, their cadence literally evolves day-to-day, minute-by-minute. It's not evolving on a particular set of a budget cycle. Continually testing those defense mechanisms is of the utmost imperative, and that was of the utmost imperative for California.

ROUTE FIFTY: The role of the CISO, have you found that it's still a very techy, hands-on-keyboards role? Or is it a lot more about managing relationships now? How has it changed?

PANYCH: It certainly has evolved, and the role of the CISO does need to be evolved, not just from a techy perspective. I like to think of it as akin to a medical director at a hospital. The medical director at a hospital was a surgeon, who did the technical work of conducting delivery of a medical exercise. You still need to be aware of the context of what's going on to make things work, but also, you're in a position of managing a program, managing risk, which is super pertinent to the business, or as we so like to say in state government, to the program areas.

You do have to be that influencer, if you will, to convince the board or the legislature, the governor's office, to think of risk as it matters in their terms. What does it matter? Why and how does it matter to the constituent, to a given program, whether it means facilitating quality of health to a public health organization, or receiving a benefit? You really do need to be that influencer, at the same time as knowing the context around the technicalities of cyber and how that all bridges together.

ROUTE FIFTY: How do you balance cybersecurity and risk management, with the push to modernize service delivery and be more reliant on technology? How do you navigate that tightrope?

PANYCH: Earlier on, establishing close relationships with the legislators, the stakeholders at the appointed level, at the department levels. Every organization has an appointed director. Establishing those relationships and figuring out what mission, what statutory obligation are they in the business of fulfilling, and then we walk back from there in how we align our operators on the ground to support that mission.

That mission could be purely from, for example, a resiliency availability perspective. If resiliency or availability suffers a gap in terms of a blip or a major outage, what exactly does that mean to the business? Or, for example, if an organization is running an old, legacy 20-year-old mainframe, what workforce risks are we inheriting, or are we looking at a year or two down the line? The operators that support critical mainframe applications or any other legacy applications, the workforce is retiring, moving on. Is that system application supportable with the given staff?

We're managing all facets of risk, not just technical debt, but also workforce risk, public perception, and what does the public think about usability of a given benefit-based system, so working with our user experience teams as well to make sure we inherit or provide security controls that are conducive to that without impacting the user experience of a given application.

It all flows together, all facets of risk, including legal liabilities. Legal liability is another facet of risk. Then we, from a statewide perspective, over the last eight years, we've evolved a set of security control services where we can provide security control services on demand, and not just technical services.

I established a virtual CISO service, so that's an advisory service to meet the gap of workforce shortages and gaps where we can assign or align a resource on demand for a short-term, medium-term risk mitigation, risk buy-down project. Our mantra has always been aligning our resources to meet the people where they are.

ROUTE FIFTY: From a cybersecurity perspective, how big a game changer could AI be, for better or for worse?

PANYCH: In my personal opinion, AI in the long term definitely is a force for good. There will be difficulties in the interim as it gets adopted, and a lot of industry standards are being evolved as we start to operationalize them.

For example, putting in a set of guardrails for a specific use case, what exactly does it mean to a chatbot? What does it mean to an attack surface that's being used to service your business? In the short term, we're already seeing increases in mass efficiencies. I ran the Security Operations Center, and using AI tactics and automation, we reduced our alert triage timeframes by 98%.

What that means is we're able to have a lens in triaging and seeing more threats and higher fidelity outcomes of threats and being able to bring them to remediation. We're ultimately doing more work for the investment that we have.

There are certainly a lot of opportunities and enhancements that are yet to be realized in securing source code, securing software. AI is being incredibly useful in finding bugs at a faster cadence than a human can, and providing actionable recommendations on the fly. It's certainly already in the operational space being used for far greater multipliers of efficiency than we can operate with with an existing bench. I'm definitely optimistic.

ROUTE FIFTY: When you reflect on your time in state government, what were some of the biggest lessons that you would want to impart?

PANYCH: My big recommendation is to figure out how to scale security. Build up a security service and be able to serve one-to-many, because we are, at the end of the day as security practitioners, constrained and understaffed. Using some of these automation mechanisms to be a force multiplier, and working with the vendor and partner community to help them realize how they could service the public sector a lot more efficiently.

ROUTE FIFTY: What are the biggest challenges ahead, particularly when you think about state and local governments? What are the big concerns on the horizon in the next 12 to 18 months?

PANYCH: With the AI-accelerated attacks that we're already experiencing and seeing, government organizations are well on their way in using AI for business transformation, but the threat actors living in the threat landscape are using AI to make their phishing lures a lot more realistic and more efficient.

That really puts it on a lot of these cyber-underserved organizations to perform — and perform at a lot faster pace and cadence — and do the basics that everybody should be doing, such as patch management, continuous threat exposure management, asset inventory. Not at a cadence of a regular monthly patch cycle or monthly change control cycle, but it's really becoming a matter of real-time, days and minutes, as we've seen certain attacks happen, and being able to triage and mitigate or close those gaps in more in a continuous real-time fashion.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.