Nevada’s Governor’s Technology Office introduced a statewide data classification policy intended to standardize how state agencies label and protect information following a major cyberattack that disrupted government systems for weeks. The framework establishes four sensitivity tiers—public, sensitive, confidential, and restricted—and directs agencies to choose the more restrictive category when classification is unclear, aiming to prevent inconsistent handling of private versus public data and to create a common baseline for interagency data sharing.
State officials and lawmakers described the policy as a foundational step for broader cybersecurity improvements in the wake of the incident, alongside initiatives such as expanding multifactor authentication, standing up a new Security Operations Center (SOC), and forming a legislative working group to guide future security measures. The policy is positioned as a standardization and resilience measure and does not change Nevada’s public records law, under which records are presumed public unless specific confidentiality provisions apply.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Nevada’s Governor’s Technology Office introduced a statewide data classification policy to standardize how agencies categorize and protect information, described as the first such statewide policy in the U.S. The policy establishes four categories—public, restricted, sensitive, and confidential—and directs agencies to default to the more restrictive category when uncertain.
Following the cyberattack, Nevada lawmakers elevated cybersecurity as a priority by approving a new Security Operations Center and creating a legislative working group to guide future measures. These steps were described as part of the state's broader response to the incident.
Nevada experienced a major cyberattack that reportedly crippled or disrupted certain state government systems for weeks. The incident became a catalyst for broader state cybersecurity and data-governance reforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.