
Loading

Loading
We use strictly necessary cookies to run this site, and — only with your consent — analytics cookies to understand how it's used. See our Privacy Policy for details.
State governments should formalize authorities to take on a greater role in providing services to critical infrastructure providers, according to a recent research briefing from the National Association of State Chief Information Officers.
Summary
"States must continue to strengthen and formalize their whole-of-state governance structures for critical infrastructure, clarifying roles and defining incident prevention and response capabilities and responsibilities," the Sept.
9 research briefing says. The briefing comes from NASCIO and General Dynamics Information Technology. It was written by Meredith Ward, NASCIO deputy executive director, and Joshua Verville, business development director of state, local government and education at GDIT.
Ward and Verville draw on findings from a NASCIO-Deloitte biannual cybersecurity study, and NASCIO’s 2026 State CIO Survey set to be published in late September. The findings are also based on interviews with state chief information security officers. President Trump signed a March 2025 executive order shifting more cybersecurity responsibilities to state governments.
The NASCIO study identified a trend of state governments increasingly taking on a "whole-of-government" approach to cybersecurity through providing cybersecurity services to external entities including local governments, critical infrastructure and private entities that are critical to public health and safety.” Ward and Verville write, “Our interviews solidify this data point as states consistently described movement toward ‘whole‐of‐state’ cybersecurity coordination. However, the level of centralization, authority and maturity varies widely.” "With limited statutory authority, states rely heavily on relationship-building, trust and collaborative service models to coordinate incident response, encourage adoption of best practices and maintain visibility into statewide threats," the briefing says. “[S]everal states indicated that centralized visibility, shared services and coordinated incident response significantly strengthened protection for high‐risk sectors like water, wastewater, healthcare, transportation and energy,” according to NASCIO.
According to the brief, 73 percent of state governments reported that securing critical infrastructure is a part of their whole-of-state comprehensive cybersecurity plan. Thirty-two percent of state CISOs reported providing cybersecurity services to public electric, water and wastewater utilities, while 24 percent provide services to public hospitals and healthcare facilities, according to the brief. The brief says state CISOs reported providing services ranging from "training, multifactor authentication, endpoint protection, vulnerability management, incident response, cybersecurity assessments and security operations center services,” to critical infrastructure providers.
The briefing found that state CISOs "are not confident" in the ability of local governments to manage cybersecurity best practices. "At the same time," Ward and Verville write, "there are questions about what the right approach is to assist local governments and special districts in securing critical infrastructure." "Concerns range from how to appropriately manage and build those relationships, address technological gaps and standards and how to fund the necessary assistance. Recent global events have heightened these questions, as nation-states often play a big role in cyber attacks on critical infrastructure," the brief says.
The brief describes local governments and special districts as having the potential to "represent the greatest cyber vulnerability" to a state, due to a lack of staffing with cybersecurity expertise, infrastructure relying on legacy technologies and management over operational technology systems with "limited security controls." "These smaller communities have hundreds of entities with limited cybersecurity support which offers an expanded entry point for malicious actors," the briefing says.
"CISOs across the states noted rising cyber activity against water districts and hospitals with the increasing potential for convergence of cybersecurity and real-life physical threats." The briefing also found 63 percent of state CIO budgets include critical infrastructure cyber protection funding from the federal government, emphasizing that “almost every” state CISO expressed concern “regarding the uncertainty of future federal funding, particularly Cybersecurity and Infrastructure Security Agency programs." The brief highlights the looming lapse of the authorization for a popular state and local cybersecurity grant program run by the Federal Emergency Management Agency and funded by CISA as another area of concern for state CISOs.
Authorities for the program are set to lapse Sept. 30. House appropriators have proposed $50 million to fund the grant program in the fiscal 2027 House spending bill for the Department of Homeland Security.
“There is growing apprehension that the progress made through whole‐of‐state programs may stall or collapse without sustained federal investment, pushing states to explore legislative appropriations and sector-specific grants to maintain essential services,” the briefing says. Ward and Verville write, "Overall, the findings show a nation in transition: states are stepping into broader cybersecurity leadership for critical infrastructure because the risks demand it.
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment — not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.