Executive Summary
The State of North Carolina’s 2025–2030 Cybersecurity Strategic Plan represents the most
comprehensive modernization of statewide cyber governance, risk management, and resilience in the
state’s history. In response to escalating cyber threats against state agencies, local governments, and
educational institutions, the plan establishes a unified enterprise approach that integrates statewide
policy, technology, workforce development, and governance. Developed by the N.C. Department of
Information Technology (NCDIT), the plan moves North Carolina from a decentralized, complianceoriented
model toward a holistic, risk-informed, and whole-of-state cybersecurity framework. The plan organizes North Carolina’s cybersecurity future around six strategic pillars:
- Threat surface management
- Statewide CISO accountability
- Governance
- Education
- Resilience
- Workforce development
Each pillar includes measurable objectives and enterprise-level actions that enable shared visibility,
common standards, and unified risk reduction across state agencies and broader public-sector partners.
The plan aligns and elevates cybersecurity efforts across state government, counties, municipalities,
universities, community colleges, and K–12 school districts. It establishes new enterprise governance
structures, strengthens statewide leadership accountability, expands workforce development programs,
and delivers shared cybersecurity services that raise baseline maturity for all public entities. As a result,
North Carolina is shifting from reactive cybersecurity practices to a coordinated, proactive enterprise
strategy that improves statewide readiness, reduces systemic risk, and protects North Carolinians.