Key Takeaways
- Governors’ cybersecurity advisors from over 40 states and territories convened at the NGA’s 2026 Cybersecurity Advisors Annual Institute to address evolving threats and collaborative solutions.
- Discussions emphasized the integration of artificial intelligence, cross‑sector coordination, and the need for a skilled cyber workforce.
- Virginia Gov. Abigail Spanberger highlighted her state’s Unified Readiness Framework as a model for breaking down silos among government, first responders, private sector, nonprofits, and critical infrastructure.
- CISA Acting Director Nick Andersen stressed the importance of state‑federal partnership to build lasting resilience against relentless, infrastructure‑focused threats.
- Participants examined real‑world challenges such as ransomware targeting under‑resourced institutions and nation‑state pre‑positioning in critical systems.
- The institute showcased diverse state approaches, underscoring that while tactics vary, common needs include talent, sector‑wide coordination, and a shared operating picture.
- NGA’s Governors’ Cybersecurity Advisors Network and Homeland Security Advisors Council provide ongoing forums for peer exchange, resource access, and expert guidance.
- NGA continues to support whole‑of‑state strategies, vulnerability assessments, technology modernization, and K‑12 cyber training initiatives to strengthen national cybersecurity posture.
Overview of the 2026 NGA Cybersecurity Advisors Annual Institute
The National Governors Association (NGA) gathered governors’ cybersecurity advisors from more than 40 states and territories in Arlington, Virginia, for its 2026 Governors’ Cybersecurity Advisors Annual Institute. Over two days, participants engaged with federal officials, private‑sector experts, and peers to dissect the policy questions shaping state cybersecurity today. The agenda covered emerging technologies such as artificial intelligence, workforce development, and practical steps to harden critical infrastructure against evolving threats.
NGA Leadership Emphasizes Frontline Role of Governors
NGA CEO Brandon Tatum opened the event by underscoring that governors stand on the front lines of defending the systems essential to daily life—water supplies, electrical grids, hospital networks, and classroom connectivity. He noted that cyber threats ignore state and sector boundaries, necessitating defenses that are equally borderless. Tatum highlighted NGA’s mission to convene governors’ teams with federal and industry partners so states can accelerate learning, share proven practices, and build resilience capable of withstanding real‑world incidents.
Virginia’s Unified Readiness Framework as a Model
Virginia Gov. Abigail Spanberger, a former federal law enforcement officer and CIA case officer, shared her perspective on public safety as a core gubernatorial duty. She described Virginia’s Unified Readiness Framework, which integrates state government, local first responders, the private sector, nonprofits, and critical‑infrastructure partners to dismantle operational silos. By establishing relationships, information‑sharing channels, and resource pools before an incident occurs, the framework aims to ensure Virginians receive coordinated support when cyber events arise.
CISA’s View on State‑Federal Collaboration
CISA Acting Director Nick Andersen joined the discussion to outline federal priorities and opportunities for collaboration. Andersen affirmed that state and territory leaders are vital to safeguarding cybersecurity within their communities. He argued that a united front—where federal resources meet state‑level insight—is essential for building lasting resilience against threats that often target critical infrastructure. Andersen urged continued partnership to elevate the nation’s overall cybersecurity posture.
Threat Landscape Highlighted by State Officials
During breakout sessions, state officials and private‑sector partners detailed the threats they observe across their networks. Ransomware attacks on target‑rich but resource‑poor institutions—such as small municipalities, school districts, and rural hospitals—were repeatedly cited. Additionally, participants warned of nation‑state actors pre‑positioning malware and surveillance tools within critical‑infrastructure sectors, preparing for future disruption. These insights helped frame the institute’s focus on both defensive hardening and proactive threat hunting.
Innovative Coordination and Force Multipliers
Participants explored how states are improving coordination across agencies, sectors, and jurisdictions. Strategies included establishing joint cyber‑operations centers, adopting common incident‑response playbooks, and leveraging force multipliers such as state National Guard cyber units and civilian cyber corps. By integrating military‑trained personnel with civilian expertise, states aim to surge capacity during incidents while maintaining day‑to‑day readiness. The discussions also highlighted the value of regular tabletop exercises and cross‑state information‑sharing platforms.
Diversity of State Approaches Strengthens National Resilience
NGA Chief Policy Officer Timothy Blute observed that no two state cyber offices look alike, and that variety is a strength. Each governor tailors cybersecurity strategies to local risks, resources, and political environments. Yet all states share three fundamental needs: a skilled cyber workforce, seamless coordination across public‑private sectors, and a common operating picture that provides situational awareness during crises. The institute served as a venue for exchanging these lessons and for state leaders to present operational challenges directly to federal partners capable of action.
NGA’s Ongoing Networks and Support Mechanisms
The NGA maintains the Governors’ Cybersecurity Advisors Network as a permanent forum for advisors, state chief information security officers, and other governor‑designated officials. Through periodic calls, webinars, and workshops, members troubleshoot challenges, share best practices, and access subject‑matter expertise. Parallel to this, the Governors’ Homeland Security Advisors Council addresses broader homeland‑security policy areas. The concurrent meeting of both groups this week enabled joint discussions on enhancing cyber resiliency and improving response to threats.
Policy Initiatives and Future Directions
NGA supports governors’ cybersecurity ambitions by collaborating with other state and local government associations to advance whole‑of‑state approaches, assess local vulnerabilities, and modernize technology systems nationwide. Governors have already instituted centralized cybersecurity offices, unveiled statewide strategies, crafted innovative regulations, and launched K‑12 cyber‑training platforms to cultivate the next generation of defenders. These efforts aim to embed cybersecurity into the fabric of state governance and ensure long‑term resilience.
Resources for Further Exploration
For those interested in diving deeper, NGA provides a suite of resources detailing its work supporting governors’ cybersecurity priorities. These include policy briefs, case studies of state‑level initiatives, recordings of institute sessions, and guides on building cyber‑workforce pipelines. Stakeholders are encouraged to consult these materials to replicate successful models and contribute to the national effort to secure critical infrastructure against ever‑evolving cyber threats.

