A Law That Closes the Loophole
For years, West Virginia's cybersecurity program told agencies they should complete an annual review with the Office of Technology. The word "should" did a lot of work in that sentence. Some agencies participated. Others didn't, and nothing happened.
House Bill 5638, which took effect June 12, 2026, changes the verb. Agencies now shall complete the review. State CIO Heather Abbott put it plainly in a recent interview: the old language "didn't put any onus on the agencies to do it." The new law does. It gives the state chief information security officer broader authority over risk management across most agencies, requires an annual report to the governor and legislature, and shields sensitive security findings from public disclosure so agencies can be candid about their gaps.
The law applies to nearly every state entity except higher education, state police, some constitutional officers, the legislature, and the judiciary. That's a wide net, and it's a model other states are likely to study.
The Part Vendors Should Actually Read
The headline change is the "shall." The part with teeth is the cost-recovery clause. If an agency skips its review and the Office of Technology has to bring in outside help to do the diagnostic work anyway, the state can now bill that agency for the actual cost incurred.
Abbott's framing was blunt: "If we have to hire somebody to come in and help us with this review, they have to pay for it." That's a meaningful shift in incentive. An agency weighing whether to prioritize a review against a dozen other budget pressures now has a dollar figure attached to inaction, not just a compliance checkbox.
It says that, you know, the agency shall do this. And it really didn't put any onus on the agencies to do it.
Why This Isn't Just a West Virginia Story
Watch what happens in South Dakota right now and the pattern gets clearer. Local governments there are absorbing cyberattacks after a federal grant that would have funded local cybersecurity support got rejected, according to reporting from South Dakota Searchlight. Counties are paying for incident response out of general funds because nobody built a structural mechanism to catch the gap before an attacker did.
West Virginia's law is a structural mechanism. It doesn't wait for a breach to force accountability. It builds the accountability into the calendar, with a review that has to happen every year and a cost if it doesn't. That's the direction state cybersecurity policy is heading generally: less trust-based, more audit-based, with real budget consequences attached to the parts that used to be optional.
For agencies without dedicated security staff, Abbott's team is also trying to close a resourcing gap that shows up in nearly every state. As she noted, a lot of local governments "can't afford to pay, you know, a $200,000 salary for a CISO." The Office of Technology is positioning itself as a resource of last resort for exactly those agencies, helping them apply for federal cybersecurity grant funding and walking smaller entities through informal assessments.
What This Means for the Systems Agencies Already Run
Here's the practical question for any agency facing an annual review: can you actually produce what the reviewer asks for? A cybersecurity review isn't just a network scan. It's a look at how data moves, who touched it, and whether that trail is documented well enough to survive scrutiny.
Agencies running document and data workflows through ad hoc scripts, shared drives, or point-to-point integrations often can't answer those questions cleanly. There's no consistent audit trail because there was never a governed pipeline to generate one. That's a different problem than a firewall misconfiguration, and it's usually a bigger one to fix under deadline pressure.
This is where governed integration platforms earn their keep. AIRLIFT Connect tracks every document and data movement through a full lifecycle - queued, downloading, transforming, delivering, completed - with a timeline that holds up when someone outside the agency asks to see it. When a cybersecurity review shows up on the calendar every year instead of occasionally, having that evidence already generated, rather than reconstructed under pressure, changes how the review goes.
Mandatory reviews with financial teeth are a preview of where more states are headed, not an isolated West Virginia policy quirk. Agencies that build auditability into their document and data pipelines now won't be scrambling to produce it later. cloudPWR builds AIRLIFT Connect for exactly that reason: governed pipelines that keep the audit trail ready before anyone asks for it.
