Read the confidence measure and its source carefully
The 2026 NASCIO–Deloitte Cybersecurity Study reports a substantial decline in state CISO confidence. Deloitte's current study page states that 22 percent were extremely or very confident about protecting state information assets, compared with 48 percent in 2022. A NASCIO communication cites 26 percent. That discrepancy should be resolved against the study's underlying figure before reusing the number in a presentation; the broad decline is clear, but the exact figure should not be silently mixed across sources.
More importantly, a confidence score is a self-reported perception, not a direct measurement of breach risk or control effectiveness. It should trigger a closer look at operations rather than serve as a security scorecard.
Test the measurement hypothesis instead of assuming it
One plausible interpretation is that stronger measurement makes previously hidden gaps more visible. The study says approximately half of CISOs named effectiveness metrics among their top initiatives. That does not establish that improved measurement caused confidence to fall, or that earlier confidence was unwarranted. Threat sophistication, legacy systems, budget pressure and changing responsibilities are also relevant. The operational recommendation is to measure behavior alongside compliance: time to detect and contain incidents, tested recovery, realistic phishing results and verified endpoint coverage.
An audit can confirm that a process is documented without proving it works under pressure. Lower confidence may reflect a better understanding of exposure, worsening conditions or both; leadership needs trend evidence to distinguish them.
Build whole-of-state services around actual authority
The study's more structurally revealing number is not the state CISO's self-assessment but their assessment of others. Sixty-three percent of state CISOs described themselves as not very confident in the ability of local governments and public higher education to secure public data — up from 35 percent in 2022. This highlights one part of the whole-of-state governance problem. State CISOs have formal authority over executive branch agencies. Authority over municipalities, counties, school districts and public universities varies by state and entity; it cannot be described as uniformly zero. "Whole-of-state cybersecurity" describes a service-and-incentive model: a state can offer shared security operations, consolidated licensing, tabletop exercises, and technical assistance, but it cannot mandate adoption without an applicable source of authority.
States that publish a whole-of-state policy without building the operational infrastructure to back it — the shared SOC, the joint procurement vehicles, the technical assistance teams — are producing the appearance of coverage. The 63 percent figure records CISO perceptions of those entities; it does not directly measure their controls or prove that a particular shared service failed.
Connect AI tools to operational response
The AI threat vector is compounding both gaps simultaneously. The study describes AI-enabled attack risks — AI-driven phishing campaigns that generate contextually accurate lures at scale, AI-assisted targeting and ransomware risks, and AI agents that probe network perimeters for misconfigured authentication paths without human direction. State defenders are using AI differently: 94 percent of state CISOs report being involved in developing generative AI security policies, and respondents describe exploring AI for alert triage and threat reporting alongside security automation. The report does not establish how widely those uses have reached production.
Those uses can help, but the survey does not establish that every participating state operates an unchanged security stack. The practical concern is whether defensive tools connect to reliable telemetry, identity controls and response procedures. Buying more AI security tooling does not close the gap if the underlying infrastructure cannot ingest, correlate, and act on the signals those tools generate. State networks running on end-of-life platforms and fragmented identity systems can struggle to integrate and act on new security signals.
Buy measurable security outcomes
The practical implication for state security buyers is that the 2026 NASCIO-Deloitte findings identify three distinct decision points, not one. Whole-of-state requires shared services, not shared policy: jurisdictions that want to extend protection to counties and municipalities have to build the operational infrastructure those entities can actually join and use, which means shared SOC capacity, joint procurement, and technical assistance staffed at a level that makes participation practical. AI threat response is an operational capability question before it is a policy question: policies that define acceptable use of generative AI by state employees do not address adversarial AI targeting state networks, and conflating the two produces a false sense of completeness.
And the metrics question is also a vendor accountability question: state procurement specifications that do not include measurable security outcomes may lack the contractual evidence needed to assess operational performance. Firms that can demonstrate operational performance metrics — detection time, false-positive rates, coverage across enrolled endpoints — are structurally different from firms that can demonstrate only certification posture. The NASCIO-Deloitte study is useful not because the numbers are alarming, but because they surface concerns that should be tested against operational evidence.
State security programs that treat the findings as a diagnostic rather than a headline will come out of 2026 better positioned than those that don't.
Questions for the next security review
- Reconcile the baseline. Record source, question wording, population and year for every survey statistic. Keep perception measures separate from operational performance in leadership reports.
- Measure a small set well. Track verified endpoint enrollment, detection and containment times, restoration success and unresolved high-impact vulnerabilities. Define scope and denominator so apparent improvement cannot come from excluding difficult systems.
- Test shared-service participation. Confirm which local entities are enrolled, what telemetry they provide, which incidents the state handles and who has authority to act. An invitation is not coverage.
- Exercise an AI-enabled scenario. Test a persuasive phishing attempt or malicious input alongside normal failure cases. Evaluate response and human escalation instead of assuming a new AI product closes the gap.
- Tie procurement to evidence. Require performance reporting, accessible logs, validation exercises and remediation for missed commitments. Keep independent government access to the evidence used to judge the vendor.
Sources and further reading
- 2026 NASCIO–Deloitte Cybersecurity Study — study methodology, confidence, priorities, whole-of-state and AI findings
- NASCIO study communication — first-party communication showing the conflicting 26 percent figure
Spartan X's cybersecurity and program-execution work connects a security objective to the evidence a buyer can inspect. Coverage, response and recovery should be part of the delivery conversation from the start.



