Published Wednesday, September 16, 2026 at 05:35 AM PT
BLUF: NASCIO reports that state CIOs are now shouldering primary responsibility for critical infrastructure cyber protection, with 90% identifying active threats. State agencies face significant capability and governance gaps that are expanding attack surface across power, water, transportation, and telecom sectors at state/local level.
DETAILS
Responsibility shift: State chief information officers have become de facto critical infrastructure defenders for their jurisdictions, moving beyond traditional IT security roles into operational technology (OT) and critical sectors.
Scope of awareness: 90% of state CIOs report identifying cyber risks to critical infrastructure assets within their states, indicating widespread recognition of the threat across SLTT (State, Local, Tribal, Territorial) governments.
Capability gaps: State agencies lack adequate technical resources, staff expertise, and tooling to defend critical infrastructure against modern cyber threats—particularly against coordinated, well-resourced attackers.
Governance deficits: Risk oversight, incident response coordination, and cross-agency critical infrastructure policies remain fragmented across state-level agencies, creating blind spots and delayed response.
Emerging threat vectors: Related reporting indicates concurrent pressure from nation-state APT campaigns (China, Russia-linked groups), insider threats, and AI-augmented attack tooling—all targeting critical infrastructure.
IMPACT
Affected entities: All U.S. state governments, local utilities, water authorities, transportation agencies, telecom providers, and energy operators in each state.
Geographic scope: All 50 states (NASCIO membership = state CIOs nationwide).
Operational risk: Fragmented defenses at state/local level create exploitable gaps between federal CISA guidance and ground-truth implementation. Critical services (power, water, emergency communications) depend on state-level CIO leadership that currently lacks adequate staffing and authority.
Recommended Actions
State CIOs: Audit critical infrastructure assets under your agency’s purview; catalog governance ownership (which agency owns each asset) and identify single points of contact for incident coordination.
SLTT leadership: Allocate dedicated budget for critical infrastructure cybersecurity staff and tool procurement; do not rely on general IT budgets.
Federal coordination: CISA should accelerate targeted assistance to states with lowest cyber maturity scores; consider temporary federal threat intelligence sharing and incident response surge capacity.
Cross-sector: Establish state-level critical infrastructure coordinating councils (ISACs) if not already active; test incident response playbooks across utilities, energy, and telecom.
SOURCES
- NASCIO (National Association of State Chief Information Officers) — primary report on state CIO critical infrastructure responsibilities and capability assessment.
- Related CISA guidance on insider threat strengthening and critical infrastructure isolation procedures.
- CYFIRMA APT campaign reporting (China, Russia-linked campaigns targeting telecom and critical sectors).
Status: DEVELOPING — NASCIO report summary is incomplete in available material. Recommend obtaining full NASCIO report for complete statistical breakdown and specific state assessments.
Recent high-severity events at publish time:
