MANAGEMENT UPDATE.
ENHANCING CYBERSECURITY FOR CRITICAL INFRASTRUCTURE
Multiple challenges are facing critical technological infrastructure threats within local governments, special districts and public education systems, according to a September 9 report about cybersecurity from NASCIO and General Dynamics Information Technology, which focuses on the critical help thatâs needed from states and the federal government.
In the 2026 NASCIO CIO survey, which will be published later this month, 90% of Chief Information Officers term the protection of critical infrastructure as a top concern.
Potential targets include communications networks, electric grids, water/wastewater systems and hospitals, as well as other susceptible infrastructure such as oil pipelines and data centers.
The report expresses particular concern about smaller local entities with limited resources or minimal cybersecurity expertise since they âcan be more vulnerable and be an entry point for malicious actors.â

The report, co-authored by NASCIO deputy director Meredith Ward and Joshua Verville, director of State and Local at General Dynamics Information Technology, repeatedly calls out for more federal resources and raises concerns about the deep uncertainty regarding federal funding.Â
Concerns are also raised about the danger of âescalating cyber-physical threats, fragmented authority and gaps in capabilities across local governments and special districts.â But most of the research is devoted to the role that states need to play in providing better protections. Heavily emphasized is the âwhole of statesâ approach that has been emerging for cybersecurity generally and as the âprimary framework for improving statewide cyber resilience in critical infrastructure.

By expanding their services and assistance to local entities, states are working on building relationships, trust and collaborative cybersecurity training. Citing interviews with several states, the NASCIO report notes the need for âcentralized visibility, shared services and coordinated incident response,â and the importance of governments working together.
In New Jersey, for example, the Chief Information Security Officer, Michael Geraghty emphasized his stateâs strong governance, robust sector engagement and practical operational partnerships. But the trust part is important, as well. âYou canât simply tell local governments that youâre from the state and youâre here to help,â Geraghty told NASCIO report researchers. âYou have to demonstrate it through meaningful action.
When you consistently deliver on your commitments and provide real value, the communities youâve helped become your strongest advocates.â
In Utah, CISO Phil Bates outlined his stateâs shared services approach which includes âendpoint protection, patching, security awareness training and incident response support, which was funded through the State and Local Cybersecurity Grant Program. In addition, the Utah Department of Environmental Quality was the âpublic-facing leadâ for a $1.5 million grant thatâs focused on water-sector cybersecurity.
The report ends with the caution that âcyber threats to critical infrastructure are only growing and states must act now.â Although it acknowledges no âsilver bulletâ, it continues its call for more federal programs and funding and provides a robust list of steps that states can take to enhance critical infrastructure cyber protection within their borders.
These include:
Identifying and creating inventories to assess high-risk critical infrastructure systems which present the biggest threat to public health and safety.
Prioritizing high-risk threats
Preparing for the increasing threat of AI-enabled attacks
Building trust and coalitions throughout state government, the private sector, schools, higher education and other entities.
Encouraging (or even requiring, if possible) âcritical infrastructure entities to employ basic cyber hygiene.â
Considering mandatory reporting of cyber incidents. (The report notes that at least 10 states do this already for critical infrastructure.)
Developing sustainable funding streams.
#CybersecurityForCriticalinfrastructure #CybersecurityWholeStateApproach #StateandLocalCybersecurityManagement #StateandLocalInfrastructureManagement #StateandLocalCyberProtections #StateLocalWaterSystemsCybersecurity #StateLocalEducationSystemsCybersecurity #CybersecurityAndSpecialDistricts #StateLocalCommunicationSystemsCybersecurity #StateandLocalCyberHygiene #CybersecurityAndInfrastructureVulnerability #NASCIOCybersecurityInfrastructureReport #NationalAssociationStateChiefInformationOfficers #StateChiefInformationSecurityOfficers #NASCIO #GeneralDynamicsInformationTechnology #StateandLocalCybersecurityTraining #StateandLocalCybersecurityAndInfrastructureChallenge #StateLocalCybersecurityChallenges #StateLocalIntergovernmentalTrust #StateandLocalCybersecurityGrantProgram #StateandLocalManagementNews #StateandLocalCybersecurityNews








