Award

Kansas Information Security Office

Executive Summary

Kansas transformed cybersecurity from periodic, agency-by-agency reporting into a continuous statewide defense model that identifies risk, enforces baselines, remediates vulnerabilities, validates compliance, and reports progress in near real time. Led by the Kansas Information Security Office (KISO), the KISO Continuous Defense Model established a common operating discipline across more than 70 agencies and 22,700 endpoints, replacing fragmented visibility and manual remediation with measurable, governed, repeatable cybersecurity execution.

The results were immediate and measurable. In the first 60 days, Kansas reduced active endpoint vulnerability findings from 7.1 million to 3.9 million. By April 2026, active findings had fallen to 1.8 million, a 75% reduction from baseline. Patch compliance exceeded 90% within hours for targeted patch events, mean time to patch improved by 60%, and automated Windows 11 modernization, remediation, and validation produced more than $915,000 in documented cost avoidance.

This initiative was not simply a technology deployment. It changed how Kansas manages cyber risk. The state now has an operating model that allows leadership and participating agencies to see exposure, prioritize action, validate remediation, and demonstrate progress across the enterprise. Most importantly, it reduces risk to the systems Kansans rely on every day for benefits, licensing, public safety, tax administration, health services, and the continuity of government operations.

Award Category

State/Territory

Year

Entry Status

Related Awards