As cited
Copy frozen at (site build).
ot ics
NASCIO reports state CIOs confront expanding critical infrastructure cyber risks amid local capability, governance gaps
State chief information officers identify cyberattacks on critical infrastructure as a high or moderate concern, with 90% viewing them as high priority, yet face persistent obstacles including fragmented authority, capability gaps, unstable funding, and vulnerable operational technology systems. A joint NASCIO and General Dynamics Information Technology research brief found that 73% of states have incorporated critical infrastructure protection into comprehensive plans, though the maturity and centralization of these whole-of-state approaches vary widely. Local governments and special districts remain particularly vulnerable due to limited staffing, aging equipment, and complex operational technology systems with minimal security controls, while states are expanding support through assessments, incident response, and training programs.
Why it matters: State and local government leaders, utility operators, and healthcare facility administrators need to assess whether their critical infrastructure has access to state-level cybersecurity services and whole-of-state governance frameworks, as fragmented authority and capability gaps create immediate risk to water, wastewater, energy, and transportation systems. Federal funding uncertainty for programs like the Cybersecurity and Infrastructure Security Agency and State and Local Cybersecurity Grant Program threatens sustained progress, requiring practitioners to advocate for stable appropriations and formalize governance structures now.
- Source published
- First seen by Cybersecurity Tracker