Arkansas Moves Toward Statewide Cybersecurity Standards

Arkansas created a State Cybersecurity Office over a year ago, consolidating security for 15 agencies under CISO Gary Vance. A 2025 law and executive order centralized policy and risk oversight. Officials are now pursuing legislation to extend minimum cybersecurity standards to local governments, though independent local leaders may pose challenges.
Arkansas established its State Cybersecurity Office just over a year ago, uniting 15 agencies. The Arkansas Cybersecurity Act of 2025, effective April 8, gave CISO Gary Vance authority over executive-branch cybersecurity. An executive order further consolidated oversight, risk management, and incident response. The office operates within the Office of State Technology, itself part of the Department of Shared Administrative Services.
Officials are exploring minimum standards for local governments, a system with 75 counties and 75 elected judges. A 2022 vendor breach affected roughly 55 counties and kept services offline about three months. In the prior year, Arkansas saw 10 to 12 ransomware incidents across cities, counties, schools, and sheriff’s offices.
If Arkansas extends minimum cybersecurity requirements to local entities, residents could see more consistent protection for county, school, and sheriff systems, potentially reducing disruption from ransomware. Local governments may face new compliance costs and operational changes, while their independence could complicate adoption. State agencies might benefit from clearer coordination during vendor or network incidents. The ultimate effect may depend on funding, technical support, and how flexible the standards are for smaller jurisdictions.