Expanding Responsibilities Bring Fresh Challenges for State CISOs, Survey Reveals

0
6

Key Takeaways

  • State CISOs are handling expanding duties—policy involvement, AI governance, and cross‑agency coordination—but their confidence in overall cyber defenses has fallen sharply.
  • Legacy systems and outdated solutions are major impediments to defending against increasingly sophisticated, AI‑enabled threats.
  • Budget growth has stalled or reversed; only 22 % of CISOs report budget increases of 6 % or more, while 16 % saw cuts since 2024.
  • Demonstrating the value of cyber investments through effectiveness metrics (e.g., incident response time, phishing click rates) has become a top priority for half of respondents.
  • A “whole‑of‑state” approach—centralized funding, legislation, and coordinated governance—is gaining traction in states such as Texas, Utah, and Massachusetts, though it adds pressure on CISO budgets.
  • Effective communication that frames cyber risk in enterprise‑risk and mission‑continuity terms improves stakeholder receptivity to funding requests.
  • The expiration of federal State and Local Cyber Grant funds and the winding down of COVID‑era assistance are key drivers behind budget uncertainty.
  • Protecting critical infrastructure (pipelines, hospitals, utilities) is increasingly viewed as a life‑or‑death cybersecurity imperative.

Overview of State CISO Responsibilities and Survey Findings
State chief information security officers now shoulder a broader portfolio than ever before, ranging from traditional network defense to shaping policy on the safe use of artificial intelligence and coordinating with local governments and higher‑education institutions. A joint survey by the National Association of State Chief Information Officers (NASCIO) and Deloitte captured these expanding responsibilities while highlighting a stark mismatch between growing demands and available resources. Respondents reported that their workloads have intensified even as budgets tighten, creating a precarious balance that threatens the effectiveness of state cybersecurity programs.

Declining Confidence in Cyber Defenses
Confidence among state CISOs in their ability to ward off external threats has plummeted. Only 22 % of respondents described themselves as “extremely or very confident” in their state’s external‑threat protection, down from 48 % in 2022. Faith in the cyber capabilities of local governments and public higher‑education institutions also hit a low, with just 63 % expressing confidence compared to 35 % two years earlier. This erosion of trust reflects a growing sense of exhaustion and the realization that no single control can guarantee safety in a threat landscape that evolves daily.

Challenges Posed by Legacy Infrastructure
A persistent barrier to modernizing defenses is the reliance on legacy infrastructure. Many state systems run on outdated hardware and software that are difficult to patch, monitor, or replace without significant investment. The survey found that confronting ever more sophisticated threats—especially those amplified by AI—is made harder when CISOs must work within these constraints. Without the ability to upgrade to current‑generation tools, agencies remain vulnerable to exploits that target known weaknesses in aging platforms.

Budget Pressures and Funding Trends
Financial constraints are exacerbating the technical challenges. Only 22 % of CISOs reported budget increases of 6 % or more since the previous survey, a sharp decline from the 40 % who saw such growth in 2024. Meanwhile, 16 % noted budget reductions since 2024. Because cybersecurity spending is often buried within broader IT or agency budgets, precise tracking is difficult, yet the trend clearly signals that financial support is not keeping pace with rising responsibilities. The combination of flat or slightly increased budgets and escalating costs for talent and technology makes many CISOs feel as though they are operating under effective budget cuts.

The Role of Effectiveness Metrics
To counter the perception of ineffective spending, half of the survey participants identified implementing effectiveness metrics as a primary focus area. Metrics such as mean time to detect and respond to incidents, phishing click‑through rates, and compliance with patch‑management schedules allow CISOs to quantify the return on cyber investments. By translating technical outputs into business‑relevant data, these indicators help justify funding requests and demonstrate progress to legislators and agency leaders who may otherwise view cybersecurity as a cost center rather than a risk‑mitigation function.

Whole‑of‑State Cybersecurity Strategies
Several states are adopting a “whole‑of‑state” model that centralizes cybersecurity governance, funding, and incident response across all government entities. Examples cited include Texas’s investment in the Texas Cyber Command, Utah’s dedicated cybersecurity appropriations, and Massachusetts’s funding for training initiatives. This approach aims to eliminate fragmented defenses and create a unified security posture. While beneficial, the model also places additional fiscal and administrative pressure on CISOs, who must often coordinate without direct authority over local jurisdictions.

Communicating Risk to Stakeholders
Success in securing resources increasingly hinges on how CISOs frame their requests. Those who translate technical risks into enterprise‑risk language—emphasizing impacts on mission continuity, public safety, and service delivery—receive better receptivity from legislators and governors. By avoiding overly technical jargon and linking cyber investments to tangible outcomes (e.g., keeping hospitals online or preventing utility outages), CISOs can align cybersecurity with the strategic priorities of state leadership, making funding approvals more likely.

Impact of Federal and COVID‑Era Funding Expiration
Two major external factors are driving the current budget squeeze. First, the State and Local Cyber Grant program administered by the Department of Homeland Security is set to expire, removing a significant source of supplemental funding that has historically flowed to local governments (about 80 % of the grant dollars). Second, the special COVID‑era assistance that helped states bolster remote‑work defenses and expand cybersecurity staff is winding down. The loss of these streams creates uncertainty and forces CISOs to compete for a shrinking pool of state‑only dollars.

Critical Infrastructure Concerns
Protecting critical infrastructure has emerged as a top‑of‑mind issue for many CISOs. Recent attacks on pipelines, hospitals, and energy grids underscore that cyber threats can have immediate, life‑or‑death consequences. State and local cyber grants have previously enabled local governments to harden these vital systems, and officials hope that continued or replaced funding will allow similar efforts to persist. As adversaries increasingly target essential services, the need for resilient, well‑funded cybersecurity programs becomes not just a matter of data protection but of public safety.

Conclusion and Outlook
The survey paints a picture of state CISOs operating at an inflection point: responsibilities are expanding, threats are growing more sophisticated—particularly with AI‑enabled tactics—and traditional sources of support are receding. Confidence in defensive capabilities has declined, yet there are clear pathways forward. By adopting effectiveness metrics, embracing whole‑of‑state coordination, communicating risk in business terms, and advocating for sustained funding—whether through state legislation or new federal mechanisms—CISOs can hope to stabilize and eventually strengthen their states’ cyber posture. The coming years will test whether these strategies can translate into tangible resilience against an ever‑evolving threat landscape.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here