Today’s cyber environment is dynamic and increasingly perilous. Artificial Intelligence is intensifying the speed, sophistication and complexity of cyber threats across the United States. Risks to the critical infrastructure we all rely on, including water supplies, hospitals, energy networks and transportation systems, are growing every day. In this rapidly evolving cybersecurity landscape, state governments across the country play a crucial role in protecting our critical infrastructure.
According to a new report from General Dynamics Information Technology (GDIT) and the National Association of State Chief Information Officers, almost 90% of state CIOs now rank cyberattacks on critical infrastructure as a big concern. This is especially true for smaller municipalities and special districts that are particularly vulnerable to malicious actors.
States are also navigating a wide variety of challenges, including deep uncertainty about federal funding, escalating cyber‑physical threats, fragmented authority and gaps in capabilities across local governments and special districts. Given this scenario, building trust and collaborative relationships has become as crucial as legal authority, and innovative governance models are propelling progress.
Unified, statewide cyber defense strategies are emerging as powerful tools for enhancing infrastructure security. Many states now embed critical infrastructure protections within their overall cybersecurity frameworks.
New York’s recent funding initiative for water systems and Utah’s shared cybersecurity services, covering most local entities, are prime examples. Oregon is assembling diverse partners to fortify sector-wide defenses, while some states rely on voluntary programs and service offerings instead of mandates.
Small communities and specialized districts remain the most vulnerable, often lacking cyber-trained staff and operating legacy systems. To bridge these gaps, states are providing hands-on support like education, incident response services, risk management and security assessments.
For example, Kansas has widened access to state cyber services, and Minnesota has enacted executive orders to mobilize support during incidents. The most popular offerings include expert guidance, governance partnerships, financial support, coordinated responses and shared solutions.
Funding uncertainty is a persistent challenge. Most state CIO budgets cover executive branch cybersecurity, but few extend support to local agencies and districts. The possibility of reduced federal funding could threaten progress, making legislative and targeted grants increasingly important. Continued national investment remains essential for safeguarding vulnerable infrastructure.
Operational technology and supervisory control and data acquisition (SCADA) systems present pressing risks, especially for water, health and transit services, due to their reliance on older equipment, remote connections and unclear responsibility boundaries.
States are shifting toward regular assessments and coordinated oversight to reduce cyber risks. Recent cyber incidents targeting water utilities have prompted federal guidance and underscored the need for stronger cyber protection.
Looking forward, states must act decisively to protect our critical infrastructure. Below are three low-cost, realistic steps that authorities across a state can take:
1. Map high-risk systems, prepare for advanced threats like AI-driven attacks, reinforce partnerships and clarify oversight frameworks. Determine which systems would have the most real-world impact if targeted and focus resources there. Ensure you know the right points of contact of vendors, partners, third-party contractors, and state and federal partners before an incident occurs.
2. Promote best practices such as cyber hygiene, incident reporting and expanding support services. Change all default passwords and choose a long and strong pass phrase instead. Run a 60-minute incident response tabletop exercise with your frontline operators to discuss the basics: what triggers outreach and communication? How do communications flow within and outside of the organization? How do you reach external government resources (i.e.: State & Federal Partners, Cybersecurity and Infrastructure Security Agency (CISA), FBI, etc.)? Prioritize patching based on operational risk in your environment. And ensure manual mode remains an option for operators.
3. Cultivate independent funding sources at the state level, when possible, to ensure cyber resilience, while maintaining sustained federal funding. Take maximum advantage of free resources, such as CISA best practices, Information Sharing and Analysis Center (ISAC) membership and open-source threat feeds. Describe cyber risks in mission and business impact language when advocating for funding. Translating cyber risks into plain language about impact to citizens and customers helps ensure that risk-based decisions are fully understood.
As cyber risks mount, proactive state leadership and cross-sector cooperation will be vital to protecting essential services and the public’s well-being. Critical infrastructure cybersecurity directly shapes Americans’ safety, security and daily lives. From citizens to government officials to frontline operational technology and IT operators to cybersecurity professionals, we all must understand what is at stake and do our part. It is imperative that we get this right.
______

About Dr. Mischa Beckett:
Dr. Mischa Beckett is senior director of cyber threat intelligence at GDIT and deputy chief information security officer of its federal civilian division.
Join our LinkedIn group Information Security Community!
