incident-responsetrade-pressNewsThe Broadside2 min read

NASCIO: states need clearer cyber authority over critical infrastructure

States are being asked to do more for water, power, and healthcare cybersecurity under a model that relies on voluntary relationships (not statutory authority) and the maturity of those relationships varies sharply across jurisdictions.


TL;DR

NASCIO's latest research briefing, based on interviews with state CISOs and survey data, documents a gap between what states are increasingly expected to do for critical infrastructure cybersecurity and what they're legally empowered to do. Under the whole-of-state model, 73% of states include CI security in their plans, but only 32% provide services to public electric and water utilities and 24% to public hospitals. State CISOs told NASCIO they rely on relationship-building and voluntary coordination because statutory authority is limited, and they rate local governments and special districts as the least prepared. Federal funding uncertainty, including the looming September 30 expiration of the State and Local Cybersecurity Grant Program, compounds the problem.

NASCIO: states need clearer cyber authority over critical infrastructure
Editorial illustration · drawn by The Broadside

The Trump administration's March 2025 executive order shifted more cybersecurity responsibilities to state governments. NASCIO's new research briefing, co-authored with GDIT and drawing on the NASCIO-Deloitte biannual cybersecurity study and interviews with state CISOs, maps what that shift actually looks like on the ground.

What it finds is a patchwork. States are moving toward "whole-of-state" coordination, but the centralization, authority, and maturity of those efforts vary widely. With limited statutory authority, states lean on relationships and collaborative service models to coordinate incident response, encourage best practices, and maintain threat visibility. Several states told NASCIO that centralized visibility and shared services significantly strengthened protection for high-risk sectors (water, wastewater, healthcare, transportation, and energy) where they exist. But the model is only as good as the relationships underneath it.

The numbers tell the story. 73% of state governments say securing critical infrastructure is part of their whole-of-state cybersecurity plan. That's the ambition. The delivery: 32% actually provide cybersecurity services to public electric, water, and wastewater utilities; 24% do so for public hospitals and healthcare facilities. The services cited range from training and multifactor authentication to endpoint protection, vulnerability management, incident response, assessments, and SOC operations, a broad menu, inconsistently available.

Not confident in local readiness

State CISOs are blunt about where the weak points are. The briefing says they "are not confident" in the ability of local governments to manage cybersecurity best practices. Local governments and special districts, in NASCIO's framing, "represent the greatest cyber vulnerability" to a state, lean staffing, legacy technologies, operational technology systems with limited security controls. CISOs reported rising cyber activity against water districts and hospitals, with the potential for convergence of cyber and physical threats. Hundreds of small entities with minimal cybersecurity support, the briefing notes, offer "an expanded entry point for malicious actors."

The funding cliff

Sixty-three percent of state CIO budgets include federal funding for critical infrastructure cyber protection, but almost every CISO interviewed expressed concern about the uncertainty of future federal support, particularly CISA programs. The State and Local Cybersecurity Grant Program, administered by FEMA and funded through CISA, is set to lapse September 30. NASCIO warns that "progress made through whole-of-state programs may stall or collapse without sustained federal investment." States are already exploring legislative appropriations and sector-specific grants as fallbacks.

NASCIO's conclusion is measured but clear: states are stepping into broader cybersecurity leadership because the risks demand it. But without clearer governance authority, stronger local capacity, and stable federal support, national resilience will remain uneven. The briefing treats formalized governance structures and clarified roles (not just more money) as the missing piece.


Published ·Deep Fathom