Lawmakers enacted House Bill 5638 in mid-March, altering West Virginia’s cybersecurity program to give the state chief information security officer (CISO) greater authority over cyber policies, risk management, and other security responsibilities across most state agencies. As agencies respond to the changes, which took effect June 12, state CIO Heather Abbott is focused on what they will mean for departments — and for the state’s broader cybersecurity strategy. The law requires agencies to do yearly cybersecurity reviews. It protects sensitive cybersecurity information from public disclosure and requires the CISO to report annually to the governor and legislators on the program’s progress. It applies to all state entities except higher education institutions, state police, some constitutional officers, the Legislature and the Judiciary. The modifications, Abbott said, are less about creating a new security program than making sure agencies actually follow through on the one that already exists. What shifted, she said, was the language around the annual reviews, which had left too much room for agencies to treat participation as optional. “It says that, you know, the agency shall do this,” Abbott said. “And it really didn’t put any onus on the agencies to do it.” The annual reviews were originally intended to give the state a regular look at each agency’s cybersecurity readiness and broader security environment — and under the previous language, agencies were supposed to participate in at least one review with the Office of Technology each year. The new requirements, Abbott said, are designed to strengthen that process by putting more responsibility on agencies to participate and address the findings that emerge. The distinction matters because the reviews are not simply a paperwork exercise. Some agencies do not have the expertise to handle the work on their own which is why the updated law makes their participation