MANAGEMENT UPDATE.
ENHANCING CYBERSECURITY FOR CRITICAL INFRASTRUCTURE
Multiple challenges are facing critical technological infrastructure threats within local governments, special districts and public education systems, according to a September 9 report about cybersecurity from NASCIO and General Dynamics Information Technology, which focuses on the critical help that’s needed from states and the federal government.
In the 2026 NASCIO CIO survey, which will be published later this month, 90% of Chief Information Officers term the protection of critical infrastructure as a top concern.
Potential targets include communications networks, electric grids, water/wastewater systems and hospitals, as well as other susceptible infrastructure such as oil pipelines and data centers.
The report expresses particular concern about smaller local entities with limited resources or minimal cybersecurity expertise since they “can be more vulnerable and be an entry point for malicious actors.”

The report, co-authored by NASCIO deputy director Meredith Ward and Joshua Verville, director of State and Local at General Dynamics Information Technology, repeatedly calls out for more federal resources and raises concerns about the deep uncertainty regarding federal funding.
Concerns are also raised about the danger of “escalating cyber-physical threats, fragmented authority and gaps in capabilities across local governments and special districts.” But most of the research is devoted to the role that states need to play in providing better protections. Heavily emphasized is the “whole of states” approach that has been emerging for cybersecurity generally and as the “primary framework for improving statewide cyber resilience in critical infrastructure.

By expanding their services and assistance to local entities, states are working on building relationships, trust and collaborative cybersecurity training. Citing interviews with several states, the NASCIO report notes the need for “centralized visibility, shared services and coordinated incident response,” and the importance of governments working together.
In New Jersey, for example, the Chief Information Security Officer, Michael Geraghty emphasized his state’s strong governance, robust sector engagement and practical operational partnerships. But the trust part is important, as well. “You can’t simply tell local governments that you’re from the state and you’re here to help,” Geraghty told NASCIO report researchers. “You have to demonstrate it through meaningful action.
When you consistently deliver on your commitments and provide real value, the communities you’ve helped become your strongest advocates.”
In Utah, CISO Phil Bates outlined his state’s shared services approach which includes “endpoint protection, patching, security awareness training and incident response support, which was funded through the State and Local Cybersecurity Grant Program. In addition, the Utah Department of Environmental Quality was the “public-facing lead” for a $1.5 million grant that’s focused on water-sector cybersecurity.
The report ends with the caution that “cyber threats to critical infrastructure are only growing and states must act now.” Although it acknowledges no “silver bullet”, it continues its call for more federal programs and funding and provides a robust list of steps that states can take to enhance critical infrastructure cyber protection within their borders.
These include:
Identifying and creating inventories to assess high-risk critical infrastructure systems which present the biggest threat to public health and safety.
Prioritizing high-risk threats
Preparing for the increasing threat of AI-enabled attacks
Building trust and coalitions throughout state government, the private sector, schools, higher education and other entities.
Encouraging (or even requiring, if possible) “critical infrastructure entities to employ basic cyber hygiene.”
Considering mandatory reporting of cyber incidents. (The report notes that at least 10 states do this already for critical infrastructure.)
Developing sustainable funding streams.
#CybersecurityForCriticalinfrastructure #CybersecurityWholeStateApproach #StateandLocalCybersecurityManagement #StateandLocalInfrastructureManagement #StateandLocalCyberProtections #StateLocalWaterSystemsCybersecurity #StateLocalEducationSystemsCybersecurity #CybersecurityAndSpecialDistricts #StateLocalCommunicationSystemsCybersecurity #StateandLocalCyberHygiene #CybersecurityAndInfrastructureVulnerability #NASCIOCybersecurityInfrastructureReport #NationalAssociationStateChiefInformationOfficers #StateChiefInformationSecurityOfficers #NASCIO #GeneralDynamicsInformationTechnology #StateandLocalCybersecurityTraining #StateandLocalCybersecurityAndInfrastructureChallenge #StateLocalCybersecurityChallenges #StateLocalIntergovernmentalTrust #StateandLocalCybersecurityGrantProgram #StateandLocalManagementNews #StateandLocalCybersecurityNews








