Former California CISO reflects on cyber’s importance in state government

ANDREY DENISYUK via Getty Images
Now a senior advisor at World Wide Technology, Vitaliy Panych said his aim was always to make everyone a “risk practitioner,” while managing an enormous state infrastructure.
After nearly 20 years working in California state agencies and having served as the state’s longest-tenured chief information security officer, Vitaliy Panych is starting a new chapter in his career.
Panych recently joined technology company World Wide Technology as senior cybersecurity and risk advisor, having led the development of Cal-Secure, the state's first multi-year cybersecurity roadmap, and provided information security oversight and services for more than 140 executive branch entities as well as cities, counties, special districts, schools and more.
It’s been quite a journey for Panych, who said he joined WWT after being impressed with the “culture” of the company and its “deep bench of expertise” on various technology issues, whether it be cybersecurity, artificial intelligence or modernization.
Panych recently sat down with Route Fifty to reflect on his career in state government and the challenges ahead.
This interview has been edited for brevity and clarity.
ROUTE FIFTY: How would you say that the government's relationship with technology has evolved?
VITALIY PANYCH: At a massive scale, needless to say, technology's being used to issue benefits, facilitate permitting, enable public safety. Technology is literally embedded into all of our daily lives, and embedded into every mission set and business operation within state government. That's a good thing. It certainly adds a considerable amount of efficiency in how government does business.
However, there's definitely risk that needs to be balanced, that needs to be managed. Suffice to say, my mission when I first started in government, my goal or agenda, was I wanted to make everybody a risk-managed security practitioner, or a risk practitioner.
What that means is knowing what the upsides are when you adopt an attack surface or a level of technology that obviously can and will be abused, and then what are the downsides, and being able to objectively quantify that. That's what I've been doing over the past year, and that's what my role was within state government as the California CISO. I played that CISO role to about 140 different agencies and helped them shape their security programs, helped them convey those security programs where it makes sense in how you measure risk, where is it reasonable to handle that risk, and then provide pathways and roadmaps to help mitigate that risk.
It's not only me by myself. I relied on really talented security practitioners within the state that would make any commercial, board-level member for the dollar spent be really impressed because, obviously, public servants are underpaid, always constrained, but they certainly do a lot to scale risk management and mitigation practices and translate them into operations.
When I first started being the CISO, we developed and released this Cal-Secure roadmap, which is a universal roadmap applicable within 140 of our state agencies, and then it also eventually prevailed over time into a lot of our partner public sector organizations. California is pretty big, too: 140 different executive branch agencies, 500 cities, 58 counties, about 1,000 school districts, 2,500 special districts. Those could be water utilities, those could be municipal or regional transit areas.
There's a big ecosystem where organizations work with each other, so it needs a common framework, a common taxonomy to bridge what we do and how we operate as a common operating model between the state and local services. I was really proud to get that released, and we also released last month a version two of that. Version two of that encompasses a lot of risk management tactics and mitigation strategies around AI, which is top of mind for everybody these days.
ROUTE FIFTY: I know it's not all on your shoulders when you're the CISO of California, but you've got all these cities and state agencies and special districts, and you've always got someone trying to get in: hackers and nation-states. What's that like on a day-to-day basis?
PANYCH: Back seven or so years ago, we realized there was even back then quite a significant intake and amount of suspected cyber incidents and breaches and events.
So, we built up what we call the California Cybersecurity Integration Center, which is really intended to be the backstop for those decentralized organizations that are not under our authority, and really provide them some services, such as coordination of incident response, escalation coordination within incident response [and] collaboration with threat intelligence sharing. We have a big net from our Security Operations Center. We receive quite a bit of volume and day-to-day telemetry around gaps, vulnerabilities, threats and indicators of compromise.
We get an opportunity to use that net of things that we capture and provide actionable operational telemetry that those downstream organizations can react to. But then, over time, we've evolved the CSIC and some of the California Department of Technology services to be more proactive, like conducting more proactive risk assessments, continuous control validation mechanisms. I always like to say it's one thing to put in a security defense mechanism and a control at a point in time, but that needs to be continuously validated and tested, because the threat actors, their cadence literally evolves day-to-day, minute-by-minute. It's not evolving on a particular set of a budget cycle. Continually testing those defense mechanisms is of the utmost imperative, and that was of the utmost imperative for California.
ROUTE FIFTY: The role of the CISO, have you found that it's still a very techy, hands-on-keyboards role? Or is it a lot more about managing relationships now? How has it changed?
PANYCH: It certainly has evolved, and the role of the CISO does need to be evolved, not just from a techy perspective. I like to think of it as akin to a medical director at a hospital. The medical director at a hospital was a surgeon, who did the technical work of conducting delivery of a medical exercise. You still need to be aware of the context of what's going on to make things work, but also, you're in a position of managing a program, managing risk, which is super pertinent to the business, or as we so like to say in state government, to the program areas.
You do have to be that influencer, if you will, to convince the board or the legislature, the governor's office, to think of risk as it matters in their terms. What does it matter? Why and how does it matter to the constituent, to a given program, whether it means facilitating quality of health to a public health organization, or receiving a benefit? You really do need to be that influencer, at the same time as knowing the context around the technicalities of cyber and how that all bridges together.
ROUTE FIFTY: How do you balance cybersecurity and risk management, with the push to modernize service delivery and be more reliant on technology? How do you navigate that tightrope?
PANYCH: Earlier on, establishing close relationships with the legislators, the stakeholders at the appointed level, at the department levels. Every organization has an appointed director. Establishing those relationships and figuring out what mission, what statutory obligation are they in the business of fulfilling, and then we walk back from there in how we align our operators on the ground to support that mission.
That mission could be purely from, for example, a resiliency availability perspective. If resiliency or availability suffers a gap in terms of a blip or a major outage, what exactly does that mean to the business? Or, for example, if an organization is running an old, legacy 20-year-old mainframe, what workforce risks are we inheriting, or are we looking at a year or two down the line? The operators that support critical mainframe applications or any other legacy applications, the workforce is retiring, moving on. Is that system application supportable with the given staff?
We're managing all facets of risk, not just technical debt, but also workforce risk, public perception, and what does the public think about usability of a given benefit-based system, so working with our user experience teams as well to make sure we inherit or provide security controls that are conducive to that without impacting the user experience of a given application.
It all flows together, all facets of risk, including legal liabilities. Legal liability is another facet of risk. Then we, from a statewide perspective, over the last eight years, we've evolved a set of security control services where we can provide security control services on demand, and not just technical services.
I established a virtual CISO service, so that's an advisory service to meet the gap of workforce shortages and gaps where we can assign or align a resource on demand for a short-term, medium-term risk mitigation, risk buy-down project. Our mantra has always been aligning our resources to meet the people where they are.
ROUTE FIFTY: From a cybersecurity perspective, how big a game changer could AI be, for better or for worse?
PANYCH: In my personal opinion, AI in the long term definitely is a force for good. There will be difficulties in the interim as it gets adopted, and a lot of industry standards are being evolved as we start to operationalize them.
For example, putting in a set of guardrails for a specific use case, what exactly does it mean to a chatbot? What does it mean to an attack surface that's being used to service your business? In the short term, we're already seeing increases in mass efficiencies. I ran the Security Operations Center, and using AI tactics and automation, we reduced our alert triage timeframes by 98%.
What that means is we're able to have a lens in triaging and seeing more threats and higher fidelity outcomes of threats and being able to bring them to remediation. We're ultimately doing more work for the investment that we have.
There are certainly a lot of opportunities and enhancements that are yet to be realized in securing source code, securing software. AI is being incredibly useful in finding bugs at a faster cadence than a human can, and providing actionable recommendations on the fly. It's certainly already in the operational space being used for far greater multipliers of efficiency than we can operate with with an existing bench. I'm definitely optimistic.
ROUTE FIFTY: When you reflect on your time in state government, what were some of the biggest lessons that you would want to impart?
PANYCH: My big recommendation is to figure out how to scale security. Build up a security service and be able to serve one-to-many, because we are, at the end of the day as security practitioners, constrained and understaffed. Using some of these automation mechanisms to be a force multiplier, and working with the vendor and partner community to help them realize how they could service the public sector a lot more efficiently.
ROUTE FIFTY: What are the biggest challenges ahead, particularly when you think about state and local governments? What are the big concerns on the horizon in the next 12 to 18 months?
PANYCH: With the AI-accelerated attacks that we're already experiencing and seeing, government organizations are well on their way in using AI for business transformation, but the threat actors living in the threat landscape are using AI to make their phishing lures a lot more realistic and more efficient.
That really puts it on a lot of these cyber-underserved organizations to perform — and perform at a lot faster pace and cadence — and do the basics that everybody should be doing, such as patch management, continuous threat exposure management, asset inventory. Not at a cadence of a regular monthly patch cycle or monthly change control cycle, but it's really becoming a matter of real-time, days and minutes, as we've seen certain attacks happen, and being able to triage and mitigate or close those gaps in more in a continuous real-time fashion.




