Texas Government Employees Must Undergo Mandatory Cybersecurity Training

The government of Texas is now mandating that all government employees receive cybersecurity training. Should your employees get trained too?

The government of Texas is now mandating that all government employees receive cybersecurity training. Should your employees get trained too? 

IT companies in Houston, San Antonio, Dallas, Austin and throughout Texas are speaking with clients and industry leaders on how government and private sectors on how to implement cybersecurity training for all employees and partners.

On June 14th, 2019, the House in Texas passed a bill that would require all government employees to undergo mandatory cybersecurity training every year. Nearly all employees who work for the Texas government are affected.

Is Cybersecurity Training for Government Employees a Good Idea?

Most IT specialists in Texas and elsewhere in the United States think so. Jason Simons, Vice President of the Houston Division of ICS, had this to say about the recent decision: “I think this is a great step. The government has the most comprehensive amount of information on the most amount of people of any entity. It should, therefore, be very well protected.”

“The state government of Texas isn’t fooling around with cybersecurity measures,” Simons concludes.

Why Are State and Local Governments Most at Risk?

Jason Simons’ assessment that governments should be especially well protected from cybercrime is an accurate one. 

To be sure, sensitive, personal information is the type of data that hackers and cybercriminals want, and as Simons’ appropriately points out, sensitive, personal data is exactly what the government has a lot of — social security numbers, tax information, home addresses and phone numbers, family information, health insurance and income data, and much more. 

Often, to get at this data, hackers and cybercriminals will use phishing scams, which target employees at businesses, organizations, and government entities. A phishing scam is one in which a fake email or phone call is directed at an unsuspecting victim at the target entity. The composer of the email or caller on the telephone will purport to be someone that the victim is familiar with — the victim’s doctor, friend, credit card company, or co-worker.

But within the email, for example, will be a link, download, or other such trap. Once the victim clicks on it, this will result in ransomware being installed on their computer. Phone call scams work in a similar way — by prompting the victim to take a certain action that will result in the download of ransomware or some other such trick.

In the case of ransomware (a form of malicious software), once downloaded, this will then shut off access to the system or data of the organization. An email or call is received shortly after from the originator of the ransomware. Unless the ransom is paid — often a sum in the thousands or hundreds of thousands (sometimes, in the millions when the target is the government) — all of the compromised data or system settings will be stolen, deleted, or otherwise compromised.

If this sounds pretty scary to you, you’re not alone. This very scenario has happened to numerous small governments in the United States. That’s why many IT specialists even suggested that the Texas government (and other state governments) mandate additional cybersecurity protections. Simons of ICS went on to say: 

“The human factor is only one aspect of this protection model. I do agree with cyber-security training, but I hope they also continue to expand the required technology to be deployed. Currently, the type of security that is deployed at different government offices varies drastically. They should all have to meet a stronger technology standard.”

Who Will Carry Out the Cybersecurity Training in Texas?

This has yet to be determined. 

For now, the Texas Department of Information Resources or DIR is currently accepting applications for IT cybersecurity awareness training programs in the state. DIR will certify those security training programs that meet the requirements determined by the state. According to the recently introduced legislation, there will be a minimum of five certification slots available for these training programs.

How Can a Security Training Program Meet the Certification Requirements?

The deadline for getting certification for security training programs was Friday, October 4th. In order to be considered, programs interested should have submitted their applications, which included details about their program, by this date.

According to DIR, consideration for certification will only go to those programs that are committed to helping employees of the Texas state government ensure complete protection of government department data and other information resources. The following procedures for ensuring the best cybersecurity practices must be included in acceptable training programs:

     - Data breach detection

     - Security assessment

     - Data breach reporting

     - Addressing of cybersecurity threats

After DIR determines acceptance and certification of the minimum of five programs, those program names will be listed on the Texas Department of Information Resources website so that government departments can begin training their employees.

Protect Your Business With Cybersecurity Training

What’s good enough for the government of Texas should be good enough for your business. Speak to a managed service provider in your area today to learn how you can get your employees trained in the appropriate cybersecurity protocols.

Disclaimer: This and other personal blog posts are not reviewed, monitored or endorsed by TalkMarkets. The content is solely the view of the author and TalkMarkets is not responsible for the content of this post in any way. Our curated content which is handpicked by our editorial team may be viewed here.

Comments