Thanks To Hack the State 2, Cyber Flaws Are Getting Bugged Before The Bad Actors Can Bug Us.
The Maryland Department of Information Technology (DoIT) announced that partnerships with the security research community have helped identify and fix more than 200 unique cybersecurity vulnerabilities on public-facing State of Maryland IT assets. The effort is part of DoIT’s broader cybersecurity strategy to remediate vulnerabilities and strengthen state defenses.
DoIT recently hosted Hack the State 2 with 12 security researchers vetted by BugCrowd. Through legal reporting channels and bug bounty incentives, researchers identify qualifying vulnerabilities. Hack the State 2, combined with the existing Vulnerability Disclosure Program (VDP) launched last October, positions Maryland as a leader among states in this area. Few, if any, other states have programs of this size and scope. This program is one of several cybersecurity advances the State has made in the last year. In February, the State released the Cybersecurity and Privacy Policy Suite, a comprehensive governance framework that is hardening state systems by mandating advanced “zero-trust” cybersecurity practices. It has also expanded its cybersecurity information-sharing umbrella to ensure that local partners and critical infrastructure providers have access to up-to-date threat intelligence.


