top of page

MANAGEMENT UPDATE.

ENHANCING CYBERSECURITY FOR CRITICAL INFRASTRUCTURE

Multiple challenges are facing critical technological infrastructure threats within local governments, special districts and public education systems, according to a September 9 report about cybersecurity from NASCIO and General Dynamics Information Technology, which focuses on the critical help that’s needed from states and the federal government.


In the 2026 NASCIO CIO survey, which will be published later this month, 90% of Chief Information Officers term the protection of critical infrastructure as a top concern.


Potential targets include communications networks, electric grids, water/wastewater systems and hospitals, as well as other susceptible infrastructure such as oil pipelines and data centers.


The report expresses particular concern about smaller local entities with limited resources or minimal cybersecurity expertise since they “can be more vulnerable and be an entry point for malicious actors.”



The report, co-authored by NASCIO deputy director Meredith Ward and Joshua Verville, director of State and Local at General Dynamics Information Technology, repeatedly calls out for more federal resources and raises concerns about the deep uncertainty regarding federal funding. 


Concerns are also raised about the danger of “escalating cyber-physical threats, fragmented authority and gaps in capabilities across local governments and special districts.”  But most of the research is devoted to the role that states need to play in providing better protections. Heavily emphasized is the “whole of states” approach that has been emerging for cybersecurity generally and as the “primary framework for improving statewide cyber resilience in critical infrastructure.


CICP stands for Critical Infrastructure Cyber Protection.
CICP stands for Critical Infrastructure Cyber Protection.


By expanding their services and assistance to local entities, states are working on building relationships, trust and collaborative cybersecurity training.  Citing interviews with several states, the NASCIO report notes the need for “centralized visibility, shared services and coordinated incident response,” and the importance of governments working together.


In New Jersey, for example, the Chief Information Security Officer, Michael Geraghty emphasized his state’s strong governance, robust sector engagement and practical operational partnerships. But the trust part is important, as well. “You can’t simply tell local governments that you’re from the state and you’re here to help,” Geraghty told NASCIO report researchers. “You have to demonstrate it through meaningful action.


When you consistently deliver on your commitments and provide real value, the communities you’ve helped become your strongest advocates.”


In Utah, CISO Phil Bates outlined his state’s shared services approach which includes “endpoint protection, patching, security awareness training and incident response support, which was funded through the State and Local Cybersecurity Grant Program. In addition, the Utah Department of Environmental Quality was the “public-facing lead” for a $1.5 million grant that’s focused on water-sector cybersecurity.


The report ends with the caution that “cyber threats to critical infrastructure are only growing and states must act now.” Although it acknowledges no “silver bullet”, it continues its call for more federal programs and funding and provides a robust list of steps that states can take to enhance critical infrastructure cyber protection within their borders.


These include:


  • Identifying and creating inventories to assess high-risk critical infrastructure systems which present the biggest threat to public health and safety.


  • Prioritizing high-risk threats


  • Preparing for the increasing threat of AI-enabled attacks


  • Building trust and coalitions throughout state government, the private sector, schools, higher education and other entities.


  • Encouraging (or even requiring, if possible) “critical infrastructure entities to employ basic cyber hygiene.”


  • Considering mandatory reporting of cyber incidents. (The report notes that at least 10 states do this already for critical infrastructure.)


  • Developing sustainable funding streams.


#CybersecurityForCriticalinfrastructure #CybersecurityWholeStateApproach #StateandLocalCybersecurityManagement #StateandLocalInfrastructureManagement #StateandLocalCyberProtections #StateLocalWaterSystemsCybersecurity #StateLocalEducationSystemsCybersecurity #CybersecurityAndSpecialDistricts #StateLocalCommunicationSystemsCybersecurity #StateandLocalCyberHygiene #CybersecurityAndInfrastructureVulnerability #NASCIOCybersecurityInfrastructureReport  #NationalAssociationStateChiefInformationOfficers #StateChiefInformationSecurityOfficers #NASCIO #GeneralDynamicsInformationTechnology #StateandLocalCybersecurityTraining #StateandLocalCybersecurityAndInfrastructureChallenge #StateLocalCybersecurityChallenges #StateLocalIntergovernmentalTrust #StateandLocalCybersecurityGrantProgram #StateandLocalManagementNews #StateandLocalCybersecurityNews

MANAGEMENT UPDATE ARCHIVES.

ECONOMIC DEVELOPMENT SHIFTING STATES TO A REGIONAL APPROACH

AI THE LATEST NEWS FROM THE STATES

PROMOTING ENERGY EFFICIENCY IN RENTAL HOUSING

THE KEY TO RAISING TAXES

THE CHALLENGE OF GRADING SCHOOL PERFORMANCE

THE POWER AND PITFALLS OF BRAINSTORMING

MILLIONAIRE TAXES IN THE STATES

CONNECTICUT EDUCATION INFORMATION MISSING IN ACTION

Barrett and Greene, Dedicated to State and Local Government, State and Local Government Management, State and Local Management, State and Local Performance Audit, State and Local Government Human Resources, State and Local Government Performance Measurement, State and Local Performance Management, State and Local Government Performance, State and Local Government Budgeting, State and Local Government Data, Governor Executive Orders, State Medicaid Management, State Local Policy Implementation, City Government Management, County Government Management, State Equity and DEI Policy and Management, City Equity and DEI Policy and Management, City Government Performance, State and Local Data Governance, and State Local Government Generative AI Policy and Management, inspirational women, sponsors, Privacy

 

Barrett and Greene, Dedicated to State and Local Government, State and Local Government Management, State and Local Managemen

SIGN UP FOR SPECIAL NEWS JUST FOR YOU.

Get exclusive subscriber-only links to news and articles and the latest information on this website sent directly in your inbox.

Thanks for Subscribing. You'll now recieve updates directly to your inbox.

Copyright @ Barrett and Greene, Inc.  |  All rights Reserved  |  Built By Boost  |  Privacy 212-684-5687  |  greenebarrett@gmail.com

bottom of page