State CISOs facing new set of challenges as role expands, survey finds | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


State chief information security officers have more responsibilities than ever.

A new survey from the National Association of State Chief Information Officers and Deloitte found state CISOs are facing growing demands that are not being matched by more resources.

State CISOs say they are dealing with more work and tightening budgets, especially with the rise of artificial intelligence and the funding from COVID drying up.

Meredith Ward, the deputy executive director of the National Association of State CIOs, said before anyone jumps to the conclusion that it’s all “doom and gloom” for state CISOs, there are plenty of positive signs that demonstrate the impact these security experts are having on their states.

“CISOs are involved. They’re at the table. They are involved in policy. They’re involved in acceptable use and safe use of artificial intelligence. That’s really good,” Ward said on Ask the CIO. “But there was really bad headlines too. CISO confidence is way down in a lot of things, in the cyber practices of local governments, the cyber practices of third parties and in being able to combat AI-enabled threats. A lot of times, I like to describe the state CISO job as almost like playing a game of whack-a-mole. If anyone else is old and remembers playing that, that it’s like what’s going to come up next. It’s just a constant level of not knowing.”

Only 22% of the respondents say they are “extremely or very confident” in their state’s ability to protect against external threats. This is down from 48% in 2022.

Additionally, CISOs say their confidence in local governments and public higher education cyber capabilities is at the lowest ever, reaching 63% of the respondents this year from 35% in 2022.

“I think that there is a sense of exhaustion all the way around. It’s also that you can’t just have one thing in place that’s going to solve everything,” she said. “I tell everyone cyber is like a toolbox. You have a ton of different things in your toolbox, and if anybody says if you get this one thing you’re going to be completely safe, that’s not true. So I think it is daunting. That’s the word that I would use.”

To help combat that constant and ever-changing challenge, respondents say their top priorities have shifted, with half of CISOs saying implementing effectiveness metrics is a main focus area.

“Capturing the effectiveness of spending on cyber can be difficult, but without metrics it is hard to show the benefits from investments. Tracking operational, compliance and risk-based key performance indicators — for example, incident response time and phishing click rate — can help show the return on cyber investment,” the survey found.

 

Meanwhile, CISOs say as threats become more sophisticated, their legacy infrastructure is making it more difficult to keep up.

“When we asked CISOs about the challenges they face in addressing their cybersecurity challenges, a clear picture emerged: Confronting ever more sophisticated threats, CISOs are often constrained by a reliance on legacy infrastructure — which is often more difficult to safeguard from cyberattack — as well as outdated solutions. Fighting back may require new software, which can be expensive, as well as other up-to-date high-tech countermeasures — along with staff capable of wielding these tools. Without adequate funding, CISOs can’t properly protect states’ information and systems. Our survey shows striking increases in the number of respondents citing budget shortages and legacy infrastructure — another consequence of limited funding — as barriers to addressing cybersecurity challenges,” the survey found.

Mike Wyatt, the state, local and higher education cyber risk leader for Deloitte, said despite these and other challenges, another trend that has emerged is some states are taking a “whole of state” approach to cybersecurity that includes more funding.

“States like Texas with the investment in Texas Cyber Command is a good example. The funding was provided by the state legislature without a dependency on federal dollars,” he said. “There’s a lot of ambiguity, shall we say, on federal funding these days, and so other states are looking at what Texas is doing, and some states are moving out with new legislation, new funding to take responsibility to provide that whole of state cybersecurity posture that is clearly needed in today’s world.”

Wyatt said one reason CISOs are making progress obtaining funding from state legislatures and the governor’s office is they’re improving how they are talking to stakeholders about cybersecurity and cyber risk.

“The successful CISOs tend to communicate in enterprise risk terms and impact to mission as opposed to using highly technical talk, which especially for legislatures where you’ll see eyes glaze over,” he said. “If you bring it back to mission continuity and the criticality of being able to provide constituent services, there tends to be a better, more receptivity to making the investments necessary to improve the security posture of the state.”

The better communication also is how CISOs are creating a “whole of state” approach to cybersecurity, Ward added.

“We are seeing CISOs take on a greater role and responsibility with that, even if many CISOs will tell you they don’t have the authority to take over, nor do they want to for local governments, and they may or may not have the funding either,” Ward said. “There’s states like Texas that have funded it. Utah has gotten funding. Massachusetts has gotten funding for training things like that. That’s where I see a lot of this coming from increased CISO responsibility.”

The whole of state approach is helpful but also putting downward pressure on CISOs’ budgets. Ward said one of the biggest surprises from the respondents was 16% of respondents said their budgets dropped since 2024. And at the same time, only 22% of CISOs reported increases of 6% or more in their budgets, down from 40% in the 2024 survey.

“It should be noted that state cybersecurity funding is often challenging to precisely quantify, as spending is typically embedded in broader IT, agency, or program budgets. Even in states that have statewide cybersecurity line items, these may not be comprehensive. This lack of visibility in operations may help explain why metrics and reporting capabilities were a priority for CISOs this year, as such metrics can help demonstrate the benefits of cybersecurity expenditures,” the survey found. “Nonetheless, these survey results signal that CISOs are reporting a decline in funding increases, especially when compared with their growing responsibilities. Moreover, rising costs — in terms of both talent and technology — means that flat or slightly increased budgets may feel like budget reductions.”

Wyatt said he expected, at minimum, cyber budgets to stay flat.

Ward added that two factors may have played into the decreases in cyber funding. One was the uncertainty of federal funding, including the expiration of the state and local cyber grant funding from the Department of Homeland Security. The other is the end of funding from the COVID era.

“One of the big things that’s on the top of my mind right now is critical infrastructure. I know that there are several states that have used the grant funds to educate local governments on critical infrastructure and shore up those defenses. As soon as the conflict in Iran started, I thought critical infrastructure was the big thing that came to mind because a lot of these foreign states are the usual suspects when it comes to some of these attacks,” Ward said. “In 2010 when we first did this survey, people would say cyber is just a nerd thing. It’s not really important, but I think we see now again with attacks on pipelines, attacks on hospitals, it is life and death because so much is run by technology, which again then has a cyber component. State and local cyber grants have been extremely beneficial to local governments since 80% of the money goes to local governments. States have been able to provide really great services. It’s been a really great thing. We hope it continues.”

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW