Key Takeaways
- California Governor Gavin Newsom appointed Mike Marshall as the state’s new Chief Information Security Officer (CISO), effective immediately.
- Marshall brings 18 years of public‑sector cybersecurity experience, most recently serving as acting information officer at the California Environmental Protection Agency (CalEPA).
- He assumes leadership of the California Department of Technology’s (CDT) cybersecurity office and will oversee implementation of Cal‑Secure 2.0, the state’s updated cybersecurity roadmap.
- Cal‑Secure 2.0 rests on three pillars: workforce development, inter‑agency coordination, and technology modernization, while allowing agencies to tailor efforts to their specific risk profiles.
- Marshall’s prior work—including participation in CDT’s Information Security Leadership Academy and collaboration on the original Cal‑Secure initiative—directly aligns with two of the roadmap’s core priorities.
- He succeeds Vitaliy Panych, who helped shape Cal‑Secure 2.0 during his seven‑year tenure as state CISO.
Mike Marshall’s Professional Background
Mike Marshall’s career in public‑sector cybersecurity began in 2008 when he joined the California Public Employees’ Retirement System (CalPERS) as an information security architect. Over the ensuing decade and a half, he accumulated a breadth of experience spanning risk assessment, security architecture, incident response, and policy development. His LinkedIn profile highlights progressive responsibilities, including leadership roles that required coordinating multidisciplinary teams and aligning security initiatives with organizational missions. This extensive trajectory positioned Marshall as a seasoned practitioner capable of navigating the complex interplay between technology, governance, and public accountability that characterizes state‑level cybersecurity.
Transition to the California Environmental Protection Agency
In 2017, Marshall moved to the California Environmental Protection Agency (CalEPA), where he initially served as the agency’s Information Security Officer. During his five‑year tenure, he built and matured CalEPA’s security program, instituted baseline controls, and fostered a culture of continuous improvement. His performance earned him a promotion to acting information officer in 2022, a role he held until his appointment as state CISO. While at CalEPA, Marshall also collaborated closely with the California Department of Technology on several joint initiatives, most notably the original Cal‑Secure framework launched in 2021. This partnership gave him firsthand insight into the state’s strategic cybersecurity objectives and the operational challenges faced by diverse agencies.
Leadership in the Information Security Leadership Academy
Beyond his day‑to‑day security duties, Marshall participated in the California Department of Technology’s Information Security Leadership Academy, an intensive 11‑week program designed to groom public‑sector technologists for senior security leadership roles. The academy’s curriculum blends state‑specific security and compliance requirements with hands‑on technical training, incident‑response simulations, and management skill‑building exercises. Marshall’s completion of this program underscores his commitment to professional development and equips him with a holistic view of both the technical and managerial facets of cybersecurity—an asset that will be valuable as he steers statewide strategy.
Appointment as California’s Chief Information Security Officer
On Friday, Governor Gavin Newsom announced Marshall’s appointment as the state’s Chief Information Security Officer, a position housed within the California Department of Technology. The CISO role entails overseeing the security posture of all state entities, advising the governor and agency heads on cyber risk, and ensuring alignment with federal standards such as NIST and the Federal Information Security Management Act (FISMA). Marshall’s extensive public‑sector background, combined with his recent experience at CalEPA and the Leadership Academy, made him a natural candidate to fill the vacancy left by Vitaliy Panych, who stepped down in late July after seven years of service.
Cal‑Secure 2.0: California’s Updated Cybersecurity Roadmap
Marshall steps into his new role as California begins implementing Cal‑Secure 2.0, the successor to the original Cal‑Secure strategy released in 2021. Unveiled on July 31, the roadmap reflects lessons learned from the inaugural version and incorporates evolving threat landscapes, including ransomware, supply‑chain vulnerabilities, and the growing sophistication of nation‑state actors. Cal‑Secure 2.0 is structured around three interrelated pillars: (1) developing and retaining a skilled cybersecurity workforce; (2) enhancing coordination and information sharing across state agencies; and (3) modernizing security technology to keep pace with emerging threats. Importantly, the framework preserves flexibility, allowing each agency to prioritize the risks most pertinent to its mission while operating under a common statewide baseline.
Pillar One: Workforce Development and Retention
The first pillar of Cal‑Secure 2.0 addresses the chronic shortage of cybersecurity talent that plagues both public and private sectors. Initiatives under this pillar include expanded scholarship programs, partnerships with community colleges and universities, and the creation of clear career ladders within state service. Marshall’s prior involvement with the Information Security Leadership Academy directly supports this goal, as the academy serves as a pipeline for cultivating future leaders. By investing in continuous education, certification incentives, and competitive compensation packages, California aims to build a resilient workforce capable of defending critical infrastructure and protecting citizens’ data.
Pillar Two: Coordination and Information Sharing
Effective cybersecurity demands seamless communication among the myriad departments, boards, and commissions that constitute California’s government. The second pillar of Cal‑Secure 2.0 establishes standardized reporting mechanisms, joint threat‑intelligence platforms, and regular cross‑agency tabletop exercises. Marshall’s experience working with CDT on Cal‑Secure projects positions him to champion these collaborative efforts, ensuring that lessons learned in one agency—such as CalEPA’s handling of environmental data breaches—are rapidly disseminated statewide. Enhanced coordination not only improves situational awareness but also reduces duplicated effort and accelerates incident response times.
Pillar Three: Technology Modernization
The third pillar focuses on updating legacy systems, adopting zero‑trust architectures, and leveraging advanced tools such as endpoint detection and response (EDR), security information and event management (SIEM), and automated patch management. Marshall’s background as an information security architect equips him to evaluate existing technology stacks, identify gaps, and prioritize investments that yield the highest risk reduction per dollar spent. By aligning technology upgrades with national standards like NIST CSF and encouraging the adoption of cloud‑secure configurations, California seeks to shrink its attack surface while maintaining service continuity for essential public functions.
Strategic Flexibility for Agency‑Specific Risks
While Cal‑Secure 2.0 provides a unified framework, it deliberately preserves agency‑level flexibility. Each department can conduct its own risk assessments to determine which threats—whether they involve protecting health‑care data, safeguarding water‑resource management systems, or securing election infrastructure—warrant the greatest attention. This risk‑based approach enables agencies to allocate resources where they will have the most impact, avoiding a one‑size‑fits‑all mandate that could either overburden low‑risk units or leave high‑risk entities underprotected. Marshall’s track record of tailoring security programs to CalEPA’s unique environmental‑data challenges demonstrates his aptitude for guiding agencies through this nuanced decision‑making process.
Succession from Vitaliy Panych and Continuity of Vision
Marshall succeeds Vitaliy Panych, who served as California’s CISO for seven years and played an instrumental role in drafting both the original Cal‑Secure and its 2.0 update. Panych’s departure in late July marked the end of a period of strategic stability, but his contributions have left a solid foundation upon which Marshall can build. The seamless transition reflects the state’s commitment to continuity in cybersecurity leadership, ensuring that ongoing initiatives—such as workforce expansion programs and technology modernization contracts—remain on track without disruption.
Implications for California’s Cybersecurity Posture
Mike Marshall’s appointment arrives at a pivotal moment when state governments are increasingly targeted by sophisticated cyber adversaries seeking to exploit valuable data and critical services. His deep public‑sector expertise, proven ability to bridge technical and managerial domains, and direct involvement in shaping Cal‑Secure 2.0 position him well to elevate California’s defensive capabilities. By emphasizing workforce growth, inter‑agency collaboration, and tech modernization—while preserving the flexibility for agencies to address their unique risk landscapes—Marshall is poised to help California not only react to threats but also anticipate and mitigate them proactively. As the state rolls out Cal‑Secure 2.0 over the coming months, stakeholders will be watching closely to see how his leadership translates into measurable improvements in resilience, incident response times, and overall confidence in the security of California’s digital government.

