Award

South Carolina: Checking our Cyber Vital Signs

Executive Summary

South Carolina’s integrated, statewide cyber risk management program (SC Cyber Health) drives continuous, measurable improvement to cyber health across state government.

Until recently, South Carolina monitored cyber risk through a combination of robust security and privacy standards, agency security support services and real-time monitoring of agency assets through the state Security Operations Center (SOC). Those capabilities were strong, but largely agency centric. While agencies could monitor their own activity, review reports and access security support services, they lacked a standardized way to benchmark their total exposure, remediation progress or agency cyber program maturity compared to the rest of the state. A program enhancement was desired to bring enterprise visibility, lignment and maturity to statewide cyber health.

To enable this statewide view, the South Carolina Department of Administration’s (Admin) Division of information Security (DIS) has spent the last two years building a new enterprise cyber risk management program that provides a real-time view of cyber risk across more than 80 state agencies and continually updates how the state calculates and visualizes cyber risk as the threat landscape continually evolves.

To build this multipart program, DIS established or revitalized critical components, including governance standards, risk data sources, risk management processes, reporting tools and a dedicated agency-engagement team. It then integrated them into a unified statewide program with common goals and measures.

Key accomplishments during the two-year buildout of SC Cyber Health include revising the state’s security control framework, completing the first statewide cybersecurity audit, centralizing findings and remediation workflows in a single system of record, providing agency personnel with access and training on how to
use the system, developing common statewide metrics and reporting on agency adoption of statewide security tools and creating a real-time cyber risk dashboard based on standardized cyber vital signs and risk scores with both agency-level and statewide views.

With this program, state and agency leaders have achieved a new level of coordination in managing cyber risk, extending established oversight and support activities into a sharedresponsibility operating model in which agencies manage remediation and the state provides governance, visibility and support.

The impact is measurable: achieved 100% participation across state agencies and a 25% reduction in identified cyber risk findings statewide. Active risk management through structured remediation surged over 10x, driving a sustained downward trend in agency cyber risk scores.

Related Awards