What's Happening?
A new report from the National Association of State Chief Information Officers (NASCIO) and General Dynamics Information Technology (GDIT) reveals that U.S. state governments are increasingly taking on the role of protecting critical infrastructure from cyberattacks.
This shift comes as local governments and special districts struggle with limited cybersecurity staffing, aging technology, and rising cyber-physical threats. The report, released on Wednesday, indicates that nearly 90% of state CIOs surveyed consider cyberattacks against critical infrastructure, including water systems, hospitals, transportation, energy, and communication networks, a high concern. While 73% of state CIOs have critical infrastructure cyber protection as part of their whole-of-state cybersecurity plans, resources are not equally distributed. Only 65% of state CIO budgets include critical infrastructure cybersecurity funding for executive branch agencies, compared to just 31% for local governments and special districts. A significant 22% of CIO budgets lack any dedicated critical infrastructure cybersecurity funding. Dr. Mischa Beckett, senior director of cyber threat intelligence at GDIT, highlighted that many operational technology (OT) systems, some decades old, are now internet-connected, creating new vulnerabilities that predate modern cyber threat landscapes, including AI and nation-state actors.
Why It's Important?
The findings underscore a critical vulnerability in the nation's infrastructure, as essential services like water, healthcare, and transportation are increasingly exposed to sophisticated cyber threats. The disparity in cybersecurity funding and resources between state-level agencies and local entities creates a fragmented defense, leaving smaller, often less-equipped jurisdictions highly susceptible to attacks. This is particularly concerning given that many critical systems are operated by state, local, and private-sector entities. Successful cyberattacks on these infrastructures can lead to severe disruptions, economic losses, and even endanger public safety. The report highlights that while public awareness of cyber threats has grown, the allocation of resources has not kept pace, creating a dangerous gap. The reliance on outdated OT systems, now connected to the internet for convenience, introduces significant risks that were not anticipated when these systems were initially designed. This situation demands a more unified and adequately funded 'whole-of-state' approach to cybersecurity to safeguard vital services and protect citizens from the escalating threat landscape.
What's Next?
The report recommends several immediate and long-term actions for states to address these growing cyber gaps. States are urged to inventory high-risk infrastructure, formalize whole-of-state governance, and expand shared cybersecurity services. Implementing basic protections such as multifactor authentication and regular backups is also emphasized. Furthermore, the report calls for the development of sustainable funding mechanisms, as federal cybersecurity support, including programs from the Cybersecurity and Infrastructure Security Agency (CISA) and the State and Local Cybersecurity Grant Program, remains uncertain. Dr. Beckett pointed to initiatives like Texas' Project Watershed 250 pilot, which leverages volunteer expertise and technology from cyber and AI companies to protect the water sector, as a potential model. The Multi-State Information Sharing and Analysis Center (MS-ISAC) has also advocated for a 'whole-of-state' approach. The ongoing challenge will be to integrate cybersecurity into broader operational risk discussions, ensuring that it is not treated as a siloed concern but rather a fundamental aspect of infrastructure management and resilience.
Beyond the Headlines
The growing cybersecurity gaps in critical infrastructure reveal a deeper systemic challenge related to governance, funding, and technological evolution. The 'set-it-and-forget-it' mindset regarding legacy systems, as noted by CISA's Billy Bob Brown, Jr., in a related context, highlights a cultural inertia that adversaries exploit. The report implicitly calls for a paradigm shift where cybersecurity is embedded into the operational DNA of all critical infrastructure entities, regardless of their size or budget. The increasing interconnectedness of operational technology (OT) systems, originally designed without internet exposure in mind, with modern IT networks blurs the lines between physical and cyber threats, creating a 'cyber-physical nexus.' This necessitates a holistic security strategy that considers both digital and physical vulnerabilities. The long-term implications include potential erosion of public trust in essential services, increased national security risks from nation-state actors, and a widening digital divide in security capabilities between well-resourced state agencies and struggling local districts. Addressing this will require not only technological upgrades but also significant investment in human capital, training, and a sustained commitment to adaptive security practices.













