New Law Expands West Virginia Cybersecurity Oversight

New Law Expands West Virginia Cybersecurity Oversight

New Law Expands West Virginia Cybersecurity Oversight

https://www.govtech.com/security/new-law-expands-west-virginia-cybersecurity-oversight

Publish Date: 2026-04-28 12:21:00

Source Domain: www.govtech.com

West Virginia has expanded the authority of its cybersecurity office with a new law that strengthens oversight and requires agencies to undergo annual security reviews.

House Bill 5638, recently signed by Gov. Patrick Morrisey, gives additional authority to the state’s chief information security officer. It also establishes more formal oversight of state agency cybersecurity practices, including required participation in annual reviews assessing readiness, data protection and risk management.

The state cybersecurity office, which is within the West Virginia Office of Technology (WVOT), is tasked with setting standards for cybersecurity and with managing the state cybersecurity framework. The legislation builds on a 2019 law that created the state’s cybersecurity office and established baseline requirements for risk assessments and reporting.


HB 5638 also formalizes coordination between the chief information security officer and the chief information officer, while shifting the state’s approach from compliance to enforcement. Agencies are required to undergo annual cybersecurity program reviews that assess readiness, data protection and modernization efforts. The state is empowered to recover costs from agencies that don’t participate.

The law takes effect in June with a Nov. 30 compliance deadline. WVOT is preparing agencies for the changes by implementing new reporting processes and expanding compliance outreach, an official confirmed via email. The office has initiated cybersecurity assessments under the existing framework, and it expects data from the assessments to collectively improve the state’s cyber defenses.

Nationwide, state cybersecurity officials have recently been looking at ways to unify cybersecurity efforts across agencies and even local government bodies. Ohio last year enacted requirements for cities and counties to adopt formal cybersecurity programs, with the state…

Source