Subscribe to Our Weekly Newsletter
Interim Hearings

Cyber Command Chief Tells Texas Lawmakers Rural Help Is ‘Pretty Close to Zero’

Cyber Command Chief Tells Texas Lawmakers Rural Help Is ‘Pretty Close to Zero’

Texas stood up a cybersecurity agency last year and gave it responsibility for the whole state. Its chief told the House committee that created it on Aug. 19 that for most of the state’s small and rural governments, he has almost nothing to send.

Asked by Vice Chair Salman Bhojani, D–Euless, what a rural county with no IT budget can get from the state, Timothy “T.J.” White, chief of the Texas Cyber Command, did not soften it. “For large swaths of Texas and particularly in rural areas. It’s pretty close to zero,” he said. “Our goal is really to perhaps educate, inform and advise.”

The block on House Bill 150, the 2025 law that created the command and moved cybersecurity functions out of the Department of Information Resources, ran roughly 68 minutes of the House Committee on Delivery of Government Efficiency‘s eight-hour sitting — the second-largest charge of the day, and the agency’s first extended report to its authors.

Newsletter

Latest News, Direct To Your Inbox

Get the most important Texas news and conversations delivered to your inbox.

White said the state funds Albert sensors through the Center for Internet Security and the MS-ISAC, sensors “deployed for the better part of a decade across the country, a program that was supported through DHS.” Then: “Federal funding for that program has been canceled.”

The gap landed on the committee personally. Rep. Pat Curry, R–Waco, disclosed mid-questioning that he is himself in the middle of a breach. “My identity was stolen about two weeks ago,” Curry said. “Several credit cards have been issued. There was actually somebody tried to file an income tax return on me, with federal government. There’s credit cards in Germany. My information is all over the dark web.” He said it appeared to him that “the breach came from the Parks and Wildlife Department,” and that he had asked the command to investigate.

Curry wanted the data taken down. White told him the state has no such power. “The unfortunate reality is that once the data is on the dark web, it’s likely to remain on the dark web,” he said. “We don’t have any authority to go in and remove it.”

Curry turned it into a demand about other agencies and “the lack of expertise in those agencies in this particular case of protecting our data.” His suspicion: “the IT department just wasn’t ready. They hadn’t done what they were supposed to.” White’s reply was one line: “I understand your task and we will move out.”

Capriglione followed with the framing that carried into the afternoon’s privacy charge. “The internet is forever,” he said. “So sometimes when information shows up, especially on a distributed system like the dark web, it becomes almost impossible to actually eradicate.” The fix, he argued, is upstream: proper security, “but also that people don’t collect personal information when it’s not needed or necessary.”

Capriglione had opened the questioning on measurement, pressing White on whether the state even knows what it is defending. “We will not succeed in cybersecurity if we cannot assess the state of what we have,” White answered. “So the ability to build that map of our technology and how it connects, it’s fundamental to everything that we do.” He signaled that the current compliance regime is not enough: “Self-attestation is a necessary beginning, but it cannot end there.”

Rep. Daniel Alders, R–Tyler, drew the hearing’s most-quoted line by asking a straightforward question about early results. White answered that his own time is going somewhere else. “You’re right, I’m spending a lot of my time figuring out the LBB and the LAR process,” he said. “And once I get that figured out, maybe I can get after cyber security more confidently.”

Alders then produced a policy change. He told White that the Government Code does not appear to require members of the state’s Volunteer Incident Response Team — private-sector security professionals who surge to help entities under attack — to be U.S. citizens, and said “you can draw the conclusions there about a potential security risk.” White confirmed the command had already acted. “In order to be eligible to be a member of the … VIRT, you have to be a US citizen. So that is the standard going forward,” he said, dating the change to “the 1st of March.” He added: “I think that’s a good lesson learned.”

Rep. Ana-María Rodríguez Ramos, D–Richardson, asked what stops a state cyber agency from becoming a surveillance one. “We are not a monitoring agency. We are not a collection agency. We don’t have any law enforcement or investigative powers of citizens per se,” White said. “We do what you, the legislature authorized us to do and we’re complying with the law.” Pressed on how the volunteer force is recruited, he conceded he is still learning it: “I inherited the vert. I think it’s a phenomenal idea.”

Bhojani’s first question was about handoff risk. Standing up an agency “in mid biennium and taking over live operation functions” from DIR, he said, means “by definition, there are probably temporary blind spots.” White said the two agencies have worked as “superb mission partners.”

White had opened his testimony citing a live case: over the preceding weekend, the command coordinated an incident response at UT San Antonio “with a number of other federal, state and private sector partners.” He described the build-out as advancing on sites in Austin and San Antonio, a statewide information sharing and analysis organization, and a digital forensics laboratory planned with UTSA. Asked by Curry whether the command is responsible for university cybersecurity generally, White said standards-setting for higher education “is in our charter.”

John Dixon, testifying for the Texas Business Leadership Council, followed as a practitioner rather than an advocate, citing an Air Force signals intelligence background and a stint as temporary security chief at a large municipally owned utility in February 2022, ahead of Russia’s invasion of Ukraine.

No vote was taken; this was an interim hearing. Members’ questions on rural capacity, agency-level IT competence and the volunteer force point to the shape of cyber legislation in the 90th Legislature, which convenes in January 2027.


Also heard

The committee worked nine posted topics in a single eight-hour sitting. The panel opened with about 19 minutes on the State Auditor’s cybersecurity findings at the Texas School for the Deaf, then ran roughly two hours of agency oversight covering the Department of Information Resources, the Sunset Advisory Commission and the Texas Space Commission. It spent about 18 minutes on House Bill 3963, the early childhood integrated data system, and roughly 40 minutes on Senate Bill 14, the 2025 rulemaking and agency-deference overhaul. A 70-minute charge on using artificial intelligence to detect fraud, waste and abuse drew witnesses from the attorney general’s office and the Health and Human Services inspector general.


Fact box

Issue
Interim charge monitoring implementation of House Bill 150 (89R), which created the Texas Cyber Command

What happened
The command’s chief made his first extended report to the committee that wrote the law, telling members state resources for rural and small local governments are “pretty close to zero” and that federal funding for the Albert sensor program has been canceled; he confirmed a new U.S.-citizenship requirement for the Volunteer Incident Response Team; a committee member disclosed his own identity theft and demanded the command investigate; no vote (interim hearing)

When
Wednesday, Aug. 19, 2026, 9:00 AM CT · run time 8:00:47 · this charge ran roughly 11:22 a.m. to 12:30 p.m.

Where
Room E2.012, Capitol Extension, Austin

Chair
Rep. Giovanni Capriglione, R–Southlake (HD-98)

Archived video
house.texas.gov, video 22736


Newsletter

Latest News, Direct To Your Inbox

Get the most important Texas news and conversations delivered to your inbox.