AGP Picks
View all

200+ Cyber Vulnerabilities Found & Fixed Thanks to State of Maryland Partnerships with Security Researchers

Page Content

Crownsville, MD: Today, the Maryland Department of Information Technology (DoIT) is announcing that more than 200 unique cybersecurity vulnerabilities have been identified and fixed on web-facing State of Maryland IT assets through partnerships with the security research community. Maryland's partnership with the security researcher community is part of an "all of the above" cybersecurity strategy DoIT is using to remediate vulnerabilities and harden its defenses.

"Cyber threats are growing stronger, and the State of Maryland is ready to meet the moment," said DoIT Secretary Katie Savage. "We are moving with urgency, creating some of the most advanced state-level cybersecurity initiatives in the country. Thanks to the dedication, expertise, and ingenuity of security researcher partners who participated in 'Hack the State' and our fellow Marylanders participating in our Vulnerability Disclosure Program, we are finding unique vulnerabilities before they can be exploited by threat actors."

DoIT recently facilitated an event called "Hack the State 2." The event brought together 12 world-class security researchers vetted by BugCrowd. Security researchers use legal pathways to find and report cybersecurity vulnerabilities; Bug bounty programs pay researchers money for vulnerabilities they discover. The Maryland bug bounty program is modeled after a similar program conducted by the Department of Defense to identify vulnerabilities in federal defense systems. DoIT Secretary Katie Savage previously led the Defense Digital Service, where she and her team ran "Hack the Pentagon" and multiple other bug bounty programs.

Hack the State 2, combined with the existing Vulnerability Disclosure Program (VDP) launched last October, positions Maryland as a leader among states in this area. Few, if any, other states have programs of this size and scope. This program is one of several cybersecurity advances the State has made in the last year. In February, the State released the Cybersecurity and Privacy Policy Suite, a comprehensive governance framework that is hardening state systems by mandating advanced "zero-trust" cybersecurity practices. It has also expanded its cybersecurity information-sharing umbrella to ensure that local partners and critical infrastructure providers have access to up-to-date threat intelligence.

"We are working with urgency to pursue an "all of the above' cyber strategy that will keep the State's systems and services secure," says State Chief Information Security Officer James Saunders. "Thanks to our latest Hack the State event, we are not only finding vulnerabilities today but also building long-term partnerships with world-class security researchers that will safeguard our state in the future."

Governor Moore officially confirmed James Saunders as the State of Maryland's State Chief Information Security Officer on May 11, 2026.


Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Military Industry Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.