BlackLeafwatch the watchmen
West Virginia state government cybersecurity

West Virginia's $1.3M cybersecurity mandate, never built

Summary

West Virginia's Office of Technology spent $1,344,098 building a statewide cybersecurity framework the legislature ordered in 2019 -- then never rolled it out past a two-agency pilot. It paid $260,000 to renew the software meant to run the program for two more years with no evidence anyone opened it, cancelled the contract, and told the state's own legislative auditor it "always operated an effective statewide cybersecurity program." The auditor's response: untrue. No agency has filed the risk assessment state law has required since 2020, and by the auditor's own account, the state's overall cybersecurity status is unknown.

By Locusta · July 17, 2026

In 2019, West Virginia's Legislature ordered its executive-branch agencies to get a cybersecurity checkup. It created the West Virginia Cybersecurity Office -- a unit inside the Office of Technology (OT) tasked with building a statewide framework of standards, risk assessments, and reporting so the state would actually know how exposed its computer systems were. OT paid two contractors $1,344,098 to build it. The contractors finished on schedule and handed the completed program over in January 2022. It has never been used on more than two agencies. West Virginia's own Office of the Legislative Auditor -- the Legislature's independent watchdog, whose performance reviews go straight to the Joint Committee on Government and Finance -- found the state's overall cybersecurity status is now, in its own words, unknown.

A law with a deadline nobody enforced

House Bill 2452, effective June 2019, put a Chief Information Security Officer (CISO) in charge of a cybersecurity framework covering executive-branch departments, agencies, and boards -- higher-education institutions, the State Police, and the Legislature and Judiciary are carved out by statute, though they can opt in voluntarily. Covered agencies would have to undergo a risk assessment, adopt the resulting standards, and report back annually on their readiness. The law set a hard first deadline -- each covered agency's initial self-assessment was due to the CISO by December 31, 2020. That deadline is why the requirement matters: without it, there is no baseline anyone can check a state agency's cyber defenses against, and no way to tell if they get better or worse over time.

OT hired the work out rather than build it in-house. Security Risk Solutions, Inc. was paid $895,098 over a two-year contract to design the framework, write the policies, and produce a rollout plan. Relational Security Corp. was paid $449,000 for the software agencies would actually use to run their risk assessments -- a Governance, Risk, and Compliance (GRC) tool, the kind of program that turns a checklist of security questions into a tracked, auditable record. Together: $1,344,098, all of it before a single agency outside the pilot ever touched the finished product.

$1.3 million, two contractors, zero statewide rollout
West Virginia Office of Technology cybersecurity contract spend, by contractor, FY2019-2023
Security Risk Solutions, Inc.
895,098
Relational Security Corp.
449,000
Source: WV Office of the Legislative Auditor, PERD, Report PE 25-04-688 (January 2026)
View data as table
West Virginia Office of Technology cybersecurity contract spend by contractor, FY2019-2023 ($1,344,098 total)
Security Risk Solutions, Inc.895,098Built the framework, policies, and rollout plan
Relational Security Corp.449,000GRC risk-assessment software, purchase + 2-yr renewal

Delivered, shelved, renewed anyway, cancelled

The contractor's closeout report landed January 5, 2022; OT approved the final payment two weeks later. At that point the state had a finished cybersecurity framework, tested on two pilot agencies -- the Tax Division and the Board of Risk and Insurance Management -- and a rollout plan telling OT exactly how to take it statewide. It never happened. The auditor put it plainly: OT has had possession of the completed program since January 2022, and it is unclear why the agency never rolled it out.

What happened to the software is the harder part to explain. The GRC tool's original contract expired at the end of 2021 -- and instead of walking away, OT renewed it for two more years, through December 2023, for $260,000, with no evidence it was used a single time during that renewal period. OT let it run unused, then cancelled it on January 1, 2024, telling auditors the contract was dropped because the agency wasn't using it -- the same software it had just finished paying $260,000 to keep.

Renewed the software for two years, with no evidence it was ever opened
GRC risk-assessment software cost, Relational Security Corp.
Initial purchase (2021)
189,000
2-year renewal (2022-2023)
260,000
Source: WV Office of the Legislative Auditor, PERD, Report PE 25-04-688 (January 2026)
View data as table
GRC risk-assessment software cost paid to Relational Security Corp.: $189,000 initial purchase plus a $260,000 two-year renewal never shown to have been used
Initial purchase (2021)189,000Tested on 2 pilot agencies, then shelved
2-year renewal (2022-2023)260,000No evidence of use; cancelled Jan. 1, 2024

The people who built it left; the people who replaced them didn't know it existed

Turnover compounded the drift. OT's Chief Information Officer at the time the program was built resigned in July 2023; the Chief Information Security Officer who oversaw its development, Cox, resigned in June 2024 -- five months after the GRC contract was already cancelled. When PERD's auditors sat down with the agency's current leadership, the new CIO and CISO said they were unaware the cybersecurity program requirements existed in state law at all, and had no knowledge that a completed Cyber Risk Program was sitting in the agency's own files. A statewide security mandate had become, inside its own agency, tribal knowledge that nobody still there remembered.

OT's defense: it was never broken

Given the chance to respond before publication -- the standard practice for every state performance review -- OT largely did not concede the point. Its written reply stated the agency "always operated an effective statewide cybersecurity program that included risk assessments and reporting," and asked PERD to soften the report's language to match -- while separately acknowledging the implementation "did not precisely match the documented approach laid-out in statute." It pointed to substitute tools already in place -- vulnerability scanners, a federal cyber-hygiene report, a free federal assessment tool called CSET -- as proof the framework existed in spirit, and told PERD that reacquiring the GRC software would be "an unnecessary expense", since those substitutes cover the same ground.

PERD's answer, printed alongside OT's in the same report, does not hedge: the agency's claim that it "always operated an effective statewide cybersecurity program" is "untrue, regardless of how many tools are being used." The auditors declined to soften the report's findings. Their standard for "effective" is the one the Legislature wrote into W. Va. Code section 5A-6B -- statewide risk assessments collected, standards adopted, annual reports filed -- not a substitute set of tools OT selected on its own and never mapped back to the statute the office is bound by.

Paid to two contractors to build a statewide cybersecurity framework never rolled out
$1,344,098
$895,098 to Security Risk Solutions for the framework itself; $449,000 to Relational Security Corp for risk-assessment software
Paid to renew the risk-assessment software with no evidence it was ever used
$260,000
renewed for two more years after the pilot ended, then cancelled Jan. 1, 2024, because it wasn't being used
State agencies the completed cybersecurity program was ever tested on
2
the WV Tax Division and the Board of Risk and Insurance Management -- the only two, out of every agency covered by the 2019 mandate

The takeaway

  • The state can't say how secure its own systems are. Because OT never collected the required risk assessments or filed the mandated reports, PERD's report states plainly that West Virginia's overall cybersecurity status is unknown -- six years after the Legislature ordered a program built specifically to answer that question.
  • Money kept moving after the program stopped. OT paid $260,000 to renew software for two years with no evidence it opened once, then cancelled it -- a fifth of the entire $1.3 million program's cost spent on a tool nobody used during the exact window it was paid for.
  • Nobody currently at the agency is accountable for the gap. The and CISO who built the program are both gone; their replacements told auditors they didn't know the legal requirement existed or that a finished program was sitting in the agency's files -- and even as the agency's official response insisted its program was 'always...effective,' it separately acknowledged the implementation 'did not precisely match' what the statute requires.

All findings are from the West Virginia Office of the Legislative Auditor's Performance Evaluation and Research Division, "Performance Review: The West Virginia Office of Technology," Report PE 25-04-688 (January 2026) -- read directly in full, including the agency's complete written response and PERD's point-by-point rebuttal, both reproduced in the report itself. Dollar figures are the report's own, drawn from the state's WVOASIS financial system and independently re-summed against the report's stated totals; percentages in the analysis were independently recomputed and check out exactly against the report's underlying figures.

Sources(1) ▾
  • West Virginia Office of the Legislative Auditor, Performance Evaluation and Research Division (PERD), Performance Review: The West Virginia Office of Technology -- The West Virginia Cybersecurity Office Has Not Fulfilled the Legislative Mandate of Developing a Statewide Cybersecurity Program (2026-01-12)The West Virginia Legislature's own performance-audit arm reviewing the state Office of Technology's cybersecurity program pursuant to the West Virginia Performance Review Act (W. Va. Code section 4-10-7) -- the sole evidentiary basis for this piece's figures. Source for the creation of the Cybersecurity Office under House Bill 2452 and its statutory duties (pp. 13-14, Table 1), the two contracts totaling $1,344,098 and their milestone invoices (p. 17, Table 2), the GRC software purchase, renewal, and cancellation timeline (pp. 18, 21-22, Figure 1), the /CISO turnover and their stated unawareness of the program (p. 20), the audit's objective/scope/methodology (Appendix B, pp. 29-30), the agency's full written response and PERD's point-by-point rebuttal (Executive Summary pp. 9-11, Appendix C pp. 31-34), and the five recommendations (p. 12). wvlegislature.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account