Maine’s whole-of-state cybersecurity strategy is focused on the edge. That means cities, schools and other organizations where users need to be protected online but may not be able to afford top-of-the-line cybersecurity systems.
“It’s that first line of defense for any network,” said Maine CISO Charlie Rote at the National Association of State Chief Information Officers (NASCIO) Annual Conference in September.
Maine has leaned on the State and Local Cybersecurity Grant Program to fund its efforts, which Rote explained focus a lot on education and training. Part of the reasoning is to make those users at the edge more cyber aware, but part of it is also because it’s a good investment, particularly when funding may no longer be available.
“Most grants typically come to an end, right?” Rote said. “So what do you give an organization that they don’t have to continue to pay for after the fact? And one of those things is instilling knowledge.”
Video Transcript:
So we’re totally on a whole-of-state journey. We’re predominantly leveraging the state and local grant program, so we’ve developed our planning committee, we’ve written our security plan. The high-level mark for the plan is really security at the edge. So users, training, education, where at the edge of security, it’s that first line of defense for any network so the two major initiatives that we’re doing in that regard is deployment of individual training to include phishing exercises, and the other is the deployment of tokenized multifactor authentication.
So the tokenized multifactor authentication basically breaks most of your attack cycles. So our localities are much more safer than they ever have been and frankly in a lot of enterprises that don’t leverage that type of technology. The other is in the education space. And the real advantage of the education space is we’ve had a lot of churn in the federal government retrenchment with changes or halting of funding and challenges in that regard.
But even at the end of a grant, most grants typically come to an end, right? So what do you give an organization that they don’t have to continue to pay for after the fact? And one of those things is instilling knowledge. So even if the program were to end today, any efforts that we’ve done in the education space has just furthered our cybersecurity capabilities across the organization and the state.
