State CIOs Can't Secure What They Don't Control
Back to Signal
State & LocalCybersecurityCritical InfrastructureGovernment

State CIOs Can't Secure What They Don't Control

September 24, 2026Jess Loban

The gap between responsibility and control

NASCIO and GDIT's September 2026 report, The Expanding Cyber Perimeter, describes an expanding coordination role for state CIOs and CISOs. Water utilities, electric cooperatives, hospital networks, transit authorities, and special districts operate essential services, often outside the central IT organization's management chain. The report says 73 percent of surveyed CIOs include critical infrastructure cyber protection in whole-of-state plans, while 31 percent report relevant funding in their budgets for local governments and special districts. The difference between the two measures matters: a plan can name an operator long before the state has the means to support it.

The useful question is whether the state has the agreements, people, visibility, and funding needed to help each participating operator. NASCIO and GDIT: The Expanding Cyber Perimeter.

Map authority before promising coverage

Whole-of-state does not imply uniform authority. A state CISO may offer threat intelligence, technical assistance, procurement access, or shared security services, while an operator retains responsibility for its systems. But it is too broad to say states cannot require incident reporting or security measures: state laws and sector rules differ. The NASCIO report describes mandatory approaches alongside voluntary ones; Nevada law, for example, contains incident response planning obligations for cities and counties. A program should distinguish executive-branch policy authority, sector regulation, contract obligations, and voluntary agreements.

Legal review should identify both the reach and limits of each instrument before a state promises standard reporting or universal adoption of a control.

Budget scope matters as much as budget size

The report's graphic identifies 88 percent of CIO respondents as highly concerned about critical infrastructure cyberattacks. It also reports that 22 percent of CIO budgets contain no dedicated critical infrastructure cyber protection funding. That does not establish that those states provide no support: the report explicitly notes that emergency management, environmental protection, homeland security, or other agencies may administer funding. The management problem is fragmented visibility. Budget owners should reconcile the full portfolio, identify gaps between agencies, and distinguish one-time grant purchases from recurring operations.

Survey responses help explain state priorities; local assessments reveal the conditions at a particular utility. Use local assessments to decide which weaknesses deserve resources first.

The separate 2026 NASCIO-Deloitte study reports that the share of state CISOs expressing high confidence in protecting public data fell from 48 percent in 2022 to 22 percent in 2026. That measures reported confidence, not objectively tested security effectiveness, and does not establish that jurisdictional expansion caused the change. Study findings.

Operational technology needs its own approach

Critical infrastructure cybersecurity is also an operational technology problem. Embedded controllers, supervisory control and data acquisition systems, and industrial protocols control physical processes. Applying an enterprise IT tool without understanding that process can affect availability or safety. Some devices cannot run standard endpoint agents; updates may require a planned outage or manufacturer validation. Engineering staff may own maintenance while a separate security team owns policy. These are reasons to coordinate, not to leave the equipment unprotected. Start with an asset and dependency inventory, authorized remote access, safe segmentation, protected backups, and response procedures agreed with operators.

The right controls depend on the equipment, operational constraints, and consequences of interruption. NIST OT security guidance.

Build services that partners can actually adopt

Shared services can bridge gaps where direct authority is limited. Examples include threat-sharing arrangements, pooled monitoring, utility-inclusive exercises, and procurement vehicles that let smaller entities obtain tools and support. Those mechanisms should be judged on participation and service quality, not assumed to make participating states the best performers. An operator must understand what it receives, what data it shares, what incidents the state will help handle, and what remains its own responsibility. Reliable service delivery gives operators a reason to trust the partnership.

A state that repeatedly offers a useful service can build durable participation; one that promises help without the people to deliver it can damage that trust.

Choose measures that match the mission

State program directors and CISOs should define the mission in terms that can be measured. State-agency compliance measures may suit a centrally governed environment. A program serving independent utilities and special districts also needs measures of outreach, adoption, technical readiness, response coverage, and restoration capability. Neither a mandatory rule nor voluntary enrollment proves that a control works. Identify entities that cannot currently be reached, the reasons for the gap, and the steps that would change it—funding, technical assistance, agreements, or legislation. Where authority exists, enforce it consistently; where it does not, build incentives and partnerships with clear responsibilities.

That produces a more credible strategy than treating the entire state as one centrally managed network.

Build an authority and coverage map

A useful working session brings the security team, counsel, emergency management, and service operators to the same map. Start here.

  1. Map each essential service. Record the operator, regulator, state support owner, incident contact, legal reporting requirement, and dependencies on other providers.
  2. Separate mandates from opt-in services. Have counsel validate which entities must comply and which need an agreement; avoid promising authority the program does not possess.
  3. Make enrollment practical. Offer a clear service catalog, costs, onboarding assistance, minimum technical prerequisites, and an escalation contact for small operators.
  4. Exercise with operators. Include engineering staff, emergency management, utilities, healthcare, and local leaders in a disruption scenario that tests communications and restoration priorities.
  5. Measure protection, not mailing lists. Track enrolled high-risk operators, working telemetry, restore tests, response times, unresolved coverage gaps, and recurring funding.

Sources and further reading

Spartan X's cybersecurity and engineering work sits at this intersection of authority and operations. Protection becomes credible when the technical design fits the operator, the response duties are clear, and the service can be sustained.

Share this article
LinkedIn

BUILD WITH US

Ready to Solve Hard Problems?

Spartan X builds AI systems, autonomous platforms, and cybersecurity solutions for defense and national security.