CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

NASCIO reports state CIOs confront expanding critical infrastructure cyber risks amid local capability, governance gaps

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7464

As cited

Copy frozen at (site build).

ot ics

NASCIO reports state CIOs confront expanding critical infrastructure cyber risks amid local capability, governance gaps

State chief information officers identify cyberattacks on critical infrastructure as a high or moderate concern, with 90% viewing them as high priority, yet face persistent obstacles including fragmented authority, capability gaps, unstable funding, and vulnerable operational technology systems. A joint NASCIO and General Dynamics Information Technology research brief found that 73% of states have incorporated critical infrastructure protection into comprehensive plans, though the maturity and centralization of these whole-of-state approaches vary widely. Local governments and special districts remain particularly vulnerable due to limited staffing, aging equipment, and complex operational technology systems with minimal security controls, while states are expanding support through assessments, incident response, and training programs.

Why it matters: State and local government leaders, utility operators, and healthcare facility administrators need to assess whether their critical infrastructure has access to state-level cybersecurity services and whole-of-state governance frameworks, as fragmented authority and capability gaps create immediate risk to water, wastewater, energy, and transportation systems. Federal funding uncertainty for programs like the Cybersecurity and Infrastructure Security Agency and State and Local Cybersecurity Grant Program threatens sustained progress, requiring practitioners to advocate for stable appropriations and formalize governance structures now.

Actorsplay
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary