Key Takeaways
- Indiana has established a dedicated Office of Cybersecurity within the Department of Homeland Security via Executive Order 26‑19, signed by Gov. Mike Braun in July.
- The office will develop and implement a statewide cybersecurity strategy, coordinate preparedness and incident response, and strengthen overall resilience.
- It serves as the primary coordinator for cyber policy across state government and collaborates with state agencies, local governments, critical‑infrastructure owners, and private‑sector partners.
- The initiative builds on prior efforts, including the now‑sunset Indiana Executive Council on Cybersecurity, and complements newer programs such as the Indiana Civilian Cyber Corps.
- Indiana joins Arizona and New Jersey in placing a dedicated cybersecurity entity inside its homeland‑security apparatus, aligning with a growing trend of whole‑of‑state cyber approaches.
Creation of the Office of Cybersecurity
Governor Mike Braun signed Executive Order 26‑19 in July, formally establishing the Office of Cybersecurity inside Indiana’s Department of Homeland Security. The order provides the office with a clear statutory foundation and authority to act as the state’s central hub for cyber‑related activities. By embedding the office within an existing public‑safety agency, Indiana aims to leverage established emergency‑management structures while elevating cybersecurity to a priority comparable to natural‑disaster and terrorist‑threat preparedness.
Core Responsibilities and Mission
The new office is charged with developing and implementing a comprehensive statewide cybersecurity strategy. Its mission includes coordinating cyber preparedness efforts, managing incident‑response activities, and bolstering the resilience of state networks and critical infrastructure. Additionally, the office must oversee the execution of Indiana’s cybersecurity strategic plan and act as the primary coordinator for cyber policy across all branches of state government.
Interagency Collaboration and Partnerships
Under the executive order, the Office of Cybersecurity will work closely with the Indiana Office of Technology, the Indiana State Police, the Indiana National Guard, and other public‑ and private‑sector stakeholders. This collaborative framework is designed to break down silos, ensure timely information sharing, and synchronize defensive measures across jurisdictional boundaries. By involving local governments, critical‑infrastructure operators, and private‑sector partners, the office seeks to create a unified front against cyber threats.
Building on Prior Cybersecurity Initiatives
The creation of the office follows several earlier cybersecurity efforts in Indiana. Most notably, it succeeds the Indiana Executive Council on Cybersecurity, which had provided recommendations and planning guidance for years before its sunset. The office also complements recent legislation that authorized the Indiana Civilian Cyber Corps—a volunteer organization administered by the Indiana National Guard aimed at expanding cybersecurity awareness, capacity, and rapid response. Together, these initiatives reflect a layered approach to strengthening the state’s cyber posture.
Statewide Cyber Defense Investments
In addition to establishing the Office of Cybersecurity, Indiana has invested in cybersecurity services for local governments and has bolstered broader statewide cyber defense capabilities. These investments include funding for threat‑intelligence sharing, cybersecurity training programs, and the deployment of advanced defensive tools across state networks. By pairing institutional reforms with tangible resources, the state aims to translate policy intentions into measurable improvements in security posture.
Regional Context and National Trends
Indiana’s move aligns it with two other states—Arizona and New Jersey—that have placed dedicated cybersecurity organizations within their homeland‑security agencies. Arizona’s Department of Homeland Security houses a Cyber Command, while New Jersey’s Office of Homeland Security and Preparedness operates the New Jersey Cybersecurity and Communications Integration Cell. This pattern reflects a growing recognition among states that cyber threats require centralized, coordinated responses akin to those used for traditional emergencies.
Strategic Implications for State Government
By centralizing cybersecurity authority, Indiana expects to improve the speed and coherence of its response to cyber incidents. The office’s role as the primary policy coordinator should reduce duplication of effort, ensure consistent standards across agencies, and facilitate faster allocation of resources during crises. Moreover, the emphasis on collaboration with local and private partners is likely to enhance the overall resilience of Indiana’s critical infrastructure, which often relies on a mix of public and private assets.
Potential Challenges and Considerations
Despite the promising framework, the Office of Cybersecurity will face challenges typical of nascent organizations. These include securing sustained funding, attracting and retaining skilled cybersecurity personnel, and integrating legacy systems that may vary widely in maturity across state agencies. Effective governance will also require clear metrics for success, regular audits, and mechanisms for accountability to ensure that strategic goals translate into operational outcomes.
Future Outlook and Continuous Improvement
Looking ahead, the office will likely focus on maturing Indiana’s whole‑of‑state cybersecurity strategy, expanding participation in the Indiana Civilian Cyber Corps, and refining incident‑response playbooks based on lessons learned from exercises and real‑world events. Continuous improvement will be driven by periodic threat assessments, engagement with national cybersecurity frameworks (such as NIST), and ongoing stakeholder feedback. As cyber threats evolve, Indiana’s centralized approach positions the state to adapt swiftly while maintaining a unified defense posture.

