IE11 Not Supported

For optimal browsing, we recommend Chrome, Firefox or Safari browsers.

Cyber Command Chief Outlines Progress, Plans for Legislature

A year after Texas Cyber Command was created through legislation, the agency has operationalized most of its core structure. Recently the agency's chief, TJ White, testified to the state Legislature about that progress and some of its plans — including possible procurements.

TJ White of Texas Cyber Command seated in a chair and speaking into a microphone.
Vice Admiral T.J. White, chief of Texas Cyber Command, testifying before the Texas House of Representatives Delivery of Government Efficiency Committee.
About a year after the governor signed House Bill 150 establishing Texas Cyber Command (TXCC), the new agency has set up most of its core organization and is looking forward to new activities.

Vice Admiral TJ White, chief of TXCC, laid out the agency’s progress and some of its plans for the Texas House of Representatives Committee on Delivery of Government Efficiency (DOGE) on Aug. 19.

“We are shifting the state’s cyber posture from primarily reactive incident response towards proactive prevention, enhanced readiness and increased resilience,” White said during his testimony.

HB 150 specified three main sub-organizations for TXCC to set up: The Cybersecurity Threat Intelligence Center (CTIC), the Information Sharing and Analysis Organization (TX-ISAO) and the Unified Cyber Task Force. TXCC has operationalized CTIC and TX-ISAO, White told the committee, but is still in progress on the Unified Cyber Task Force — particularly the task force’s Digital Forensics Laboratory. TXCC is working with the University of Texas at San Antonio on location, staffing, infrastructure and capability buildout for the laboratory, he said.

White discussed some other topics hinting at the new agency’s future needs and its hopes for vendor relations.

VENDOR RELATIONS


White said he hopes to see vendors interested in working with the state do more pre-procurement work to prove their companies, products and services have addressed cyber and business risk.

“They should come with ‘We went through the Claude code review, we went through the ChatGPT — pick your model — review, this is what was found and this is what we did to fix it. Similarly, this is the workforce we’re using and we certify to you that all the DevSecOps work is done either in-house or inside the U.S. Here’s our software bill of materials, and so now maybe a little bit of the cost goes up, but you can have confidence now as a result of that contract and that procurement,’” he said.

CONTINUOUS MONITORING


TXCC has conducted what White called a “light touch survey” of outbound state web traffic.

“We were not surprised to fundamentally confirm that some of that traffic is going to North Korea, some of that traffic is going to Iran, some of that traffic is going to Russia and some of that traffic is going to China,” he said.

TXCC is interested in repeating that activity and working toward making it continuous, expanding it across the state enterprise.

“Our ability to do that in real time with fidelity is one of the best things that we can do, and we’re partnering with [the Department of Information Resources] about how to actually procure and implement that kind of capability across the state,” he said.

LOCAL GOVERNMENT SUPPORT


The state doesn’t have a lot in place to support the cyber needs of local government, White said, but one of the things it does provide is Albert sensors from the Center for Internet Security.

However, he said the sensors might be outdated. Also, the state doesn’t have any ability to tap into the data those sensors produce at the local level, which he would like to see changed. White said the state is in conversation with partners about how to go about changing that, and said that project “looks a little bit like a capital expenditure.”

VOLUNTEER INCIDENT RESPONSE TEAM


The Texas Volunteer Incident Response Team (VIRT) currently consists of about 178 volunteers across the state who have signed up to help government agencies and higher education institutions that fall victim to cyber incidents. White thinks the program could become much bigger.

“Texas is, as I know all of you are all aware, a very volunteer-oriented state,” he said. “There’s no reason in my mind why we can’t 10x that, 100x that, and so on, and get them ‘deployed’ … in communities in advance of need.”

While some members of the committee expressed hesitation about the security risks of turning to volunteers for cybersecurity activities, White said the team is now requiring all volunteers to be American citizens and to go through background checks.
Ben Miller is the associate editor of data and business for Government Technology. His reporting experience includes breaking news, business, community features and technical subjects. He holds a bachelor’s degree in journalism from the University of Nevada, Reno, and lives in Sacramento, Calif.