IndustrialCyber

NASCIO reports state CIOs confront expanding critical infrastructure cyber risks amid local capability, governance gaps


State chief information officers are increasingly taking responsibility for protecting critical infrastructure from cyber threats, with 90% identifying cyberattacks as a high concern and 73% incorporating protections into comprehensive state plans. However, fragmented authority, capability gaps, unstable funding, and vulnerable OT (operational technology) remain persistent obstacles. Drawing on the 2026 NASCIO State CIO Survey, the 2026 NASCIO-Deloitte Cybersecurity Study, and interviews with state CISOs, the National Association of State Chief Information Officers (NASCIO) and General Dynamics Information Technology (GDIT) research brief revealed that CIOs are not confident in the cyber practices of local governments. At the same time, there are questions about what the right approach is to assist local governments and special districts in securing critical infrastructure. 

At the same time, state CIOs and CISOs are grappling with AI (artificial intelligence) advancing speed and sophistication of attacks, shortfall of qualified cybersecurity professionals, and expanding role of states in strengthening critical infrastructure from cyber threats. 

“In the 2026 NASCIO State CIO Survey, CIOs overwhelmingly indicated that protecting critical infrastructure is a top-tier concern,” the joint report detailed. “Nearly 90 percent of respondents identified cyber attacks targeting critical systems, such as communications networks, electric grids, water/wastewater systems, data centers, hospitals, oil pipelines and others, as a high concern. The remaining CIOs identified cyber attacks targeting critical infrastructure as concerning at a moderate level, indicating a near-unanimous recognition of the cyber risks facing critical infrastructure and states.”

This comes as smaller local governments and special districts are particularly vulnerable due to limited staffing and aging infrastructure, though states are expanding support through assessments, incident response, and training—about 32% of state CIOs provide services to utilities and 24% to healthcare facilities. 

The NASCIO-GDIT report found that sustained federal funding and stronger state-level governance are needed to maintain progress. Challenges include managing state-local relationships, closing technological gaps, and securing funding, covering concerns intensified by nation-state involvement in critical infrastructure attacks.

“Rising operational technology (OT), Supervisory Control and Data Acquisition (SCADA) systems and cyber‑physical risks further intensify pressure on states,” the report identified. “Our interviews found that the highest CICP risks often are in water and wastewater systems, dams and hydro-water systems, hospitals and transportation systems. These systems rely on operational technology to control and manage the physical equipment and processes. However, many states cited increased risk due to aging systems, broad remote-access exposure and emerging threats such as automated reconnaissance.”  

States noted additional concerns about aging OT, proprietary systems and infrastructure that relies on outdated platforms that lack upgrade paths. Perhaps an even greater barrier is that, in some cases, there remains uncertainty about who is responsible when there is a critical infrastructure cyberattack, especially if legal authority, governance structures or partnerships are not in place. 

One state’s approach requires all utilities to perform annual cybersecurity assessments, report SCADA incidents and engage in regular state‑led coordination. This structure enables proactive critical infrastructure visibility and oversight. Another state launched a grant program led by its environmental protection state agency with federal funding to harden water providers’ OT/SCADA systems. These risks will require a coordinated approach to assess, modernize and drive cross-sector and state-level support structures to meet escalating risks. 

Advances in technology allow for more interconnected industrial environments, remote monitoring and enhanced process optimization. But modernizations can also blur boundaries and create broader attack surfaces with cascading risks and real-world consequences.

Data indicate that whole‑of‑state cybersecurity models are emerging as the primary framework for improving statewide cyber resilience in critical infrastructure. The 2026 State CIO Survey asked if critical infrastructure cyber protection is part of state whole-of-state comprehensive plans and majority of states (73%) said yes.  

“Our interviews solidify this data point as states consistently described movement toward ‘whole‑of‑state’ cybersecurity coordination,” it added. “However, the level of centralization, authority and maturity varies widely. During our interviews, several states indicated that centralized visibility, shared services and coordinated incident response significantly strengthened protection for high‑risk sectors like water, wastewater, healthcare, transportation and energy.”

The report detailed how New Jersey’s integrated approach treats cybersecurity as a whole-of-state responsibility requiring strong governance and demonstrated value to local partners, as CISO Michael Geraghty explained, “You can’t simply tell local governments that you’re from the state and you’re here to help; you have to demonstrate it through meaningful action. When you consistently deliver on your commitments and provide real value, the communities you’ve helped become your strongest advocates, and their trust encourages others to seek your assistance. Conversely, failing to follow through on your promises can quickly become your greatest liability, undermining confidence in your organization.” 

Utah’s shared services model, funded primarily through federal grants, provides endpoint protection, patching, training, and incident response to roughly 80% of its local government entities, and recently secured $1.5 million in additional funding for water-sector cybersecurity.

The report also detailed how local governments and special districts can represent cyber vulnerability. Many small communities lack staffing with cyber expertise, have highly variable infrastructure relying on aging equipment and manage complex OT systems with limited security controls. These smaller communities have hundreds of entities with limited cybersecurity support, which offers an expanded entry point for malicious actors. CISOs across the states noted rising cyber activity against water districts and hospitals, with the increasing potential for convergence of cybersecurity and real-life physical threats. 

In the 2026 NASCIO State CIO Survey, CIOs reported offering a range of cybersecurity services, from training, assessments and recovery services beyond the executive branch. About a third (32%) offer services to public electric, water and wastewater utilities and about a quarter (24%) offer services to public hospitals and healthcare facilities. 

State cybersecurity services are extended beyond the executive branch in several areas. Fifty-seven percent of respondents said their states provide cybersecurity services to other branches of government, while 55% provide services to local governments, public libraries and special districts. Fifty-three percent said they extend services to K-12 school districts.

Thirty-five percent of respondents said their states provide cybersecurity services to higher education, followed by tribal governments at 28%. Public hospitals and health care facilities accounted for 24%, while the same 24% said their states do not provide services beyond the executive branch. Twenty-two percent said their states provide cybersecurity services to public electric, water and wastewater utilities.

The 2026 NASCIO-Deloitte Cybersecurity Study indicated that cyber budgets are failing to keep pace with rising demands in technology, talent and costs. Further complicating this challenge are concerns almost every state CISO expressed regarding the uncertainty of future federal funding, particularly Cybersecurity and Infrastructure Security Agency (CISA) programs, the Multi-State Information Sharing and Analysis Center (MS‑ISAC) and the State and Local Cybersecurity Grant Program.  

“There is growing apprehension that the progress made through whole‑of‑state programs may stall or collapse without sustained federal investment, pushing states to explore legislative appropriations and sector‑specific grants to maintain essential services,” according to the report. “States have limited resources and funding mechanisms to offer CICP outside of executive branch agencies and federal support is crucial to assisting vulnerable localities and other critical infrastructure sectors.”  

Clearly, states are expanding cybersecurity leadership for critical infrastructure in response to growing threats. “Yet without clearer governance authority, stronger local capacity and stable federal support, national resilience will remain uneven. State CIOs and CISOs play an increasingly important role in facilitating collaborative partnerships across sectors. Growing whole‑of‑state models, deeper regional/cross-sector collaboration and sustained investment offer the most viable paths toward securing essential services and mitigating the increasingly cyber‑physical risks facing communities nationwide. The cyber threats to critical infrastructure are only growing and states must act now.”

The NASCIO-GDIT report recognized that there is no ‘silver bullet’ to solve these challenges, but there are steps that can be taken now to address critical infrastructure cyber protection. States must identify, inventory and assess high-risk critical infrastructure systems that pose the greatest risk to public health and safety and prioritize the cyber posture of those systems. States must prepare for increased AI-enabled attacks on critical infrastructure. Even without funding or authority, states must continue to lean into their whole-of-state models and collaboration with local government entities.

Additionally, states must also continue to build trust and coalitions with all branches of state government, the private sector, K-12, higher education and other relevant entities to collectively strengthen critical infrastructure cyber protection capabilities. States must continue to strengthen and formalize their whole-of-state governance structures for critical infrastructure, clarifying roles and defining incident prevention and response capabilities and responsibilities. States should strongly encourage, or require when possible, critical infrastructure entities to employ basic cyber hygiene such as multifactor authentication, daily backups and cyber awareness training.

Furthermore, state legislators and/or regulators should consider mandatory reporting of cyber incidents from local governments, utilities and special districts. There are at least 10 states that mandate this reporting for CICP. States should maintain or expand critical infrastructure cyber protection services, including access to state contracts, to local governments and special districts, even when the adoption of those services is not mandatory.

As a critical part of the nation’s homeland security, the federal government must fund federal grants and other programs that have been crucial to the strides made in critical infrastructure cyber protection. States must also develop sustainable funding streams beyond federal assistance to ensure long-term resilience.



Source link