West Virginia's $1.3M cybersecurity mandate, never built
Summary
West Virginia's Office of Technology spent $1,344,098 building a statewide cybersecurity framework the legislature ordered in 2019 -- then never rolled it out past a two-agency pilot. It paid $260,000 to renew the software meant to run the program for two more years with no evidence anyone opened it, cancelled the contract, and told the state's own legislative auditor it "always operated an effective statewide cybersecurity program." The auditor's response: untrue. No agency has filed the risk assessment state law has required since 2020, and by the auditor's own account, the state's overall cybersecurity status is unknown.
A law with a deadline nobody enforced
House Bill 2452⧉, effective June 2019, put a Chief Information Security Officer (CISO) in charge of a cybersecurity framework covering executive-branch departments, agencies, and boards -- higher-education institutions, the State Police, and the Legislature and Judiciary are carved out by statute, though they can opt in voluntarily. Covered agencies would have to undergo a risk assessment, adopt the resulting standards, and report back annually on their readiness. The law set a hard first deadline -- each covered agency's initial self-assessment was due to the CISO by December 31, 2020⧉. That deadline is why the requirement matters: without it, there is no baseline anyone can check a state agency's cyber defenses against, and no way to tell if they get better or worse over time.
OT hired the work out rather than build it in-house. Security Risk Solutions, Inc. was paid $895,098⧉ over a two-year contract to design the framework, write the policies, and produce a rollout plan. Relational Security Corp. was paid $449,000⧉ for the software agencies would actually use to run their risk assessments -- a Governance, Risk, and Compliance (GRC) tool, the kind of program that turns a checklist of security questions into a tracked, auditable record. Together: $1,344,098, all of it before a single agency outside the pilot ever touched the finished product.
View data as table
| Security Risk Solutions, Inc. | 895,098 | Built the framework, policies, and rollout plan |
|---|---|---|
| Relational Security Corp. | 449,000 | GRC risk-assessment software, purchase + 2-yr renewal |
Delivered, shelved, renewed anyway, cancelled
The contractor's closeout report landed January 5, 2022⧉; OT approved the final payment two weeks later. At that point the state had a finished cybersecurity framework, tested on two pilot agencies -- the Tax Division and the Board of Risk and Insurance Management⧉ -- and a rollout plan telling OT exactly how to take it statewide. It never happened. The auditor put it plainly: OT has had possession of the completed program since January 2022, and it is unclear why the agency never rolled it out.
What happened to the software is the harder part to explain. The GRC tool's original contract expired at the end of 2021 -- and instead of walking away, OT renewed it for two more years, through December 2023, for $260,000⧉, with no evidence it was used a single time during that renewal period. OT let it run unused, then cancelled it on January 1, 2024, telling auditors the contract was dropped because the agency wasn't using it -- the same software it had just finished paying $260,000 to keep.
View data as table
| Initial purchase (2021) | 189,000 | Tested on 2 pilot agencies, then shelved |
|---|---|---|
| 2-year renewal (2022-2023) | 260,000 | No evidence of use; cancelled Jan. 1, 2024 |
The people who built it left; the people who replaced them didn't know it existed
Turnover compounded the drift. OT's Chief Information Officer at the time the program was built resigned in July 2023; the Chief Information Security Officer who oversaw its development, Cox, resigned in June 2024 -- five months after the GRC contract was already cancelled. When PERD's auditors sat down with the agency's current leadership, the new CIO and CISO said they were unaware the cybersecurity program requirements existed in state law at all, and had no knowledge that a completed Cyber Risk Program was sitting in the agency's own files⧉. A statewide security mandate had become, inside its own agency, tribal knowledge that nobody still there remembered.
OT's defense: it was never broken
Given the chance to respond before publication -- the standard practice for every state performance review -- OT largely did not concede the point. Its written reply stated the agency "always operated an effective statewide cybersecurity program that included risk assessments and reporting,"⧉ and asked PERD to soften the report's language to match -- while separately acknowledging the implementation "did not precisely match the documented approach laid-out in statute."⧉ It pointed to substitute tools already in place -- vulnerability scanners, a federal cyber-hygiene report, a free federal assessment tool called CSET -- as proof the framework existed in spirit, and told PERD that reacquiring the GRC software would be "an unnecessary expense"⧉, since those substitutes cover the same ground.
PERD's answer, printed alongside OT's in the same report, does not hedge: the agency's claim that it "always operated an effective statewide cybersecurity program" is "untrue, regardless of how many tools are being used."⧉ The auditors declined to soften the report's findings. Their standard for "effective" is the one the Legislature wrote into W. Va. Code section 5A-6B -- statewide risk assessments collected, standards adopted, annual reports filed -- not a substitute set of tools OT selected on its own and never mapped back to the statute the office is bound by.
The takeaway
- The state can't say how secure its own systems are. Because OT never collected the required risk assessments or filed the mandated reports, PERD's report states plainly that West Virginia's overall cybersecurity status is unknown -- six years after the Legislature ordered a program built specifically to answer that question.
- Money kept moving after the program stopped. OT paid $260,000 to renew software for two years with no evidence it opened once, then cancelled it -- a fifth of the entire $1.3 million program's cost spent on a tool nobody used during the exact window it was paid for.
- Nobody currently at the agency is accountable for the gap. The and CISO who built the program are both gone; their replacements told auditors they didn't know the legal requirement existed or that a finished program was sitting in the agency's files -- and even as the agency's official response insisted its program was 'always...effective,' it separately acknowledged the implementation 'did not precisely match' what the statute requires.
All findings are from the West Virginia Office of the Legislative Auditor's Performance Evaluation and Research Division, "Performance Review: The West Virginia Office of Technology," Report PE 25-04-688 (January 2026)⧉ -- read directly in full, including the agency's complete written response and PERD's point-by-point rebuttal, both reproduced in the report itself. Dollar figures are the report's own, drawn from the state's WVOASIS financial system and independently re-summed against the report's stated totals; percentages in the analysis were independently recomputed and check out exactly against the report's underlying figures.
Sources(1) ▾
- West Virginia Office of the Legislative Auditor, Performance Evaluation and Research Division (PERD), Performance Review: The West Virginia Office of Technology -- The West Virginia Cybersecurity Office Has Not Fulfilled the Legislative Mandate of Developing a Statewide Cybersecurity Program (2026-01-12) — The West Virginia Legislature's own performance-audit arm reviewing the state Office of Technology's cybersecurity program pursuant to the West Virginia Performance Review Act (W. Va. Code section 4-10-7) -- the sole evidentiary basis for this piece's figures. Source for the creation of the Cybersecurity Office under House Bill 2452 and its statutory duties (pp. 13-14, Table 1), the two contracts totaling $1,344,098 and their milestone invoices (p. 17, Table 2), the GRC software purchase, renewal, and cancellation timeline (pp. 18, 21-22, Figure 1), the /CISO turnover and their stated unawareness of the program (p. 20), the audit's objective/scope/methodology (Appendix B, pp. 29-30), the agency's full written response and PERD's point-by-point rebuttal (Executive Summary pp. 9-11, Appendix C pp. 31-34), and the five recommendations (p. 12). wvlegislature.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
In 2019, West Virginia's Legislature ordered its executive-branch agencies to get a cybersecurity checkup. It created the West Virginia Cybersecurity Office⧉ -- a unit inside the Office of Technology (OT) tasked with building a statewide framework of standards, risk assessments, and reporting so the state would actually know how exposed its computer systems were. OT paid two contractors $1,344,098 to build it⧉. The contractors finished on schedule and handed the completed program over in January 2022. It has never been used on more than two agencies. West Virginia's own Office of the Legislative Auditor⧉ -- the Legislature's independent watchdog, whose performance reviews go straight to the Joint Committee on Government and Finance -- found the state's overall cybersecurity status is now, in its own words, unknown.