Skip to content
CISO Spotlights

Career profile

John Toney

Chief Information Security Officer, State of Vermont

Status
Current role, per sources checked 9 October 2026
Appointed
8 April 2024
Published

Compiled 9 October 2026 from public records. Each statement below is drawn from the sources listed at the end.

John Toney is the Chief Information Security Officer for the State of Vermont, a role he was appointed to on April 8, 2024. The appointment was announced by Denise Reilly-Hughes, Vermont's Chief Information Officer and Secretary of the Agency of Digital Services.

Career path

Before joining Vermont, Toney was global chief information security officer at Dallas-based City Electric Supply, part of a portfolio of companies specializing in the design and manufacturing of electrical components. In that role he was the first CISO of an enterprise spanning eight countries and built global security teams across five continents, with work experience in thirty-four countries overall. Earlier in his career, he served as Global Director for incident response, threat intelligence, and forensic investigations at Procter & Gamble in Cincinnati, Ohio.

Toney spent a decade as a Special Agent with the U.S. Secret Service, specializing in network intrusion crimes and critical systems protection, as part of nineteen years of government service overall. He was trained as a hacker through the Secret Service's Network Intrusion Response program and served on protection details at The White House, the U.S. Naval Observatory, and Department of Homeland Security Headquarters. He also received specialized training in protecting information and operations technology environments at the Idaho National Laboratory through DHS. Toney holds a bachelor's degree from Michigan State University and an executive CISO certification from Carnegie Mellon University's Heinz College of Information Systems and Public Policy.

Remit and interagency work

Toney has focused on securing critical infrastructure, including water utilities, telling an interviewer he takes a proactive approach to finding vulnerabilities across the state's critical infrastructure sectors. His team has used internet-scanning tools to identify exposed water-system equipment and has flagged security gaps directly to municipal officials. He has described compliance with standards set by the Cybersecurity and Infrastructure Security Agency as a first priority, alongside consolidating the number of cybersecurity vendors the state uses. Vermont's security office under Toney has worked with the Vermont Intelligence Center and the Secretary of State's office on a unified threat intelligence platform, assisted the Attorney General's Office in vetting and contracting, and collaborated on securing the 2024 general election.

Public remarks

In a 2024 interview, Toney described his daily routine, saying, "My morning cup of coffee comes in the form of cyber threat intelligence," and explained that it shapes his approach throughout the day. He presented on Vermont's cybersecurity posture to the Vermont Legislature's House Energy and Digital workgroup on May 7, 2025.

Sources

  1. 1.
    vermont.govvermont.gov · undated page · checked 9 October 2026 · tier A
  2. 2.
    vermontbiz.comvermontbiz.com · undated page · checked 9 October 2026 · tier A
  3. 3.
    legislature.vermont.govlegislature.vermont.gov · undated page · checked 9 October 2026 · tier A
  4. 4.
    National Security Institutenationalsecurity.gmu.edu · undated page · checked 9 October 2026 · tier A
  5. 5.
    StateScoopstatescoop.com · published 7 May 2024 · checked 9 October 2026 · tier B

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.