The Expanding Cyber Perimeter: States and Critical Infrastructure Protection

A joint research report from the National Association of State Chief Information Officers (NASCIO) and General Dynamics Information Technology (GDIT) 

Primary Authors: Meredith Ward, Deputy Executive Director, NASCIO & Joshua Verville, Director, State and Local, GDIT 

State governments are taking on a growing role in protecting critical infrastructure from cyber threats as risks increase across water and wastewater systems, healthcare, transportation, energy and other essential services. Drawing on the 2026 NASCIO State CIO Survey, the 2026 NASCIO-Deloitte Cybersecurity Study and interviews with state CISOs, this NASCIO and GDIT research brief examines how states are expanding whole-of-state cybersecurity models, supporting local governments and special districts and addressing persistent challenges including limited authority, local capacity gaps, unstable funding and vulnerable operational technology. The report also outlines actions states can take now to strengthen governance, build trusted partnerships, expand shared cybersecurity services and improve long-term resilience.

The Current Landscape | Expansion of Whole‑of‑State Cybersecurity Models |Local Government and Special District Capacity Gaps  | Funding Instability and Federal Retrenchment | OT/SCADA Vulnerabilities and Rising Cyber‑Physical Threats | The Road Ahead and Action Needed Now 

State governments across the United States are facing a rapidly evolving cybersecurity landscape. A recent topic of discussion in the state technology and cyber world surrounds critical infrastructure cyber protection (CICP) and what role states have in assisting local governments and special districts. (Note: for this document, we are using the National Institute of Standards and Technology—NIST—definition of critical infrastructure). State chief information security officers (CISOs) are not confident in the cyber practices of local governments. At the same time, there are questions about what the right approach is to assist local governments and special districts in securing critical infrastructure. Concerns range from how to appropriately manage and build those relationships, address technological gaps and standards and how to fund the necessary assistance. Recent global events have heightened these questions, as nation-states often play a big role in cyber attacks on critical infrastructure.  

At the same time state chief information officers (CIOs) and CISOs are grappling with artificial intelligence (AI) advancing the speed and sophistication of attacks, a shortfall of qualified cybersecurity professionals and the expanding role of states in strengthening critical infrastructure from cyber threats.  With these challenges in mind, NASCIO and GDIT partnered to conduct research on this important issue. Building upon data in the 2026 NASCIO State CIO Survey (to be released in September 2026), the 2026 NASCIO-Deloitte Cybersecurity Study and several interviews with state CISOs, our findings are presented in this report. 

The Current Landscape 

In the 2026 NASCIO State CIO Survey, CIOs overwhelmingly indicated that protecting critical infrastructure is a top-tier concern. Nearly 90 percent of respondents identified cyber attacks targeting critical systems, such as communications networks, electric grids, water/wastewater systems, data centers, hospitals, oil pipelines and others as a high concern. The remaining CIOs identified cyber attacks targeting critical infrastructure as concerning at a moderate level, indicating a near-unanimous recognition of the cyber risks facing critical infrastructure and states.  As one CIO said, “How could it not be high?” 

The 2026 NASCIO-Deloitte Cybersecurity Study highlights that, in a hyper-connected world, smaller local governments, public education systems and special districts can be more vulnerable and be an entry point for malicious actors. So, it is not surprising that state CISOs have been expanding support in protecting critical infrastructure from escalating cyber attacks. Our research revealed a set of shared challenges—chief among them deep uncertainty about federal funding, escalating cyber‑physical threats, fragmented authority and gaps in capabilities across local governments and special districts. Together, these trends illustrate a national landscape where states are increasingly responsible for safeguarding essential services—often without adequate authority or sustained resources.  

With limited statutory authority, states rely heavily on relationship-building, trust and collaborative service models to coordinate incident response, encourage adoption of best practices and maintain visibility into statewide threats. Relationship capital is often more influential than statutory authority in critical infrastructure cybersecurity, which often cuts across typical organizational and jurisdictional boundaries. As one state said, “winning the hearts and minds” can be the most challenging aspect. At the same time, states are making notable strides through whole-of-state service models, collaborative governance and increasingly sophisticated operational partnerships.   

Expansion of Whole‑of‑State Cybersecurity Models 

Whole‑of‑state cybersecurity models are emerging as the primary framework for improving statewide cyber resilience in critical infrastructure. The 2026 State CIO Survey asked if critical infrastructure cyber protection is part of state whole-of-state comprehensive plans and the majority of states (73 percent) said yes.  

Our interviews solidify this data point as states consistently described movement toward “whole‑of‑state” cybersecurity coordination. However, the level of centralization, authority and maturity varies widely. During our interviews, several states indicated that centralized visibility, shared services and coordinated incident response significantly strengthened protection for high‑risk sectors like water, wastewater, healthcare, transportation and energy.  

For example, in New Jersey, CISO Michael Geraghty told us of his state’s highly integrated model where cybersecurity is treated as an all-hazards, whole-of-state responsibility. The New Jersey critical infrastructure cyber coordination model favors strong governance, robust sector engagement and practical operational partnerships. As Geraghty told us, “You can’t simply tell local governments that you’re from the state and you’re here to help, you have to demonstrate it through meaningful action. When you consistently deliver on your commitments and provide real value, the communities you’ve helped become your strongest advocates, and their trust encourages others to seek your assistance. Conversely, failing to follow through on your promises can quickly become your greatest liability, undermining confidence in your organization.” 

In Utah, CISO Phil Bates told us of the state’s cybersecurity shared services model for cities, counties and special districts that provides services including endpoint protection, patching, security awareness training and incident response support. The program, funded heavily through the State and Local Cybersecurity Grant Program (SLCGP), covers nearly 80 percent of Utah’s local government entities. Additionally, Utah received a $1.5 million grant to launch a program focused on water-sector cybersecurity, with the Utah Department of Environmental Quality serving as the public-facing lead.  

Other states are expanding their CICP activities and response, allocating funding and support to this issue. In Oregon, CISO Ben Gherezgiher told us that his state is working on building a CICP coalition involving state government agencies, the National Guard, higher education institutions, federal agencies and other partners. Oregon is using SLCGP funds to assess water sector special district entities’ cyber preparedness. 

Conversely, many states rely on collaborative or advisory-only structures, where participation depends entirely on relationships, building trust and voluntary adoption. States are offering services to local governments and/or the ability to purchase off state contracts, but do not necessarily have the authority to require participation. One state CISO labeled this an “all carrots, no sticks” approach.  

Local Government and Special District Capacity Gaps  

Local governments and special districts can represent the greatest cyber vulnerability. Many small communities lack staffing with cyber expertise, have highly variable infrastructure relying on aging equipment and manage complex operational technology systems with limited security controls. These smaller communities have hundreds of entities with limited cybersecurity support which offers an expanded entry point for malicious actors. CISOs across the states noted rising cyber activity against water districts and hospitals with the increasing potential for convergence of cybersecurity and real-life physical threats. 

In the 2026 NASCIO State CIO Survey, CIOs reported offering a range of cybersecurity services from training, assessments and recovery services beyond the executive branch. About a third (32 percent) offer services to public electric, water and wastewater utilities and about a quarter (24 percent) offer services to public hospitals and healthcare facilities. 

respondents allowed to make multiple selections

Yes, other branches57%
Yes, local governments, public libraries and special districts55%
Yes, K-12 school districts53%
Yes, higher education35%
Yes, tribal governments28%
Yes, public hospitals and health care facilities24%
No24%
Yes, public electric, water and wastewater utilities22%

Source: The 2026 NASCIO State CIO Survey

To help offset these capacity gaps, states are proactively providing local governments and special districts with critical infrastructure cybersecurity services such as training, multifactor authentication, endpoint protection, vulnerability management, incident response, cybersecurity assessments and security operations center (SOC) services. From our research, we surfaced the following top five services states are offering.

Advisory/assessment 

Governance/collaboration 

Grants/funding 

Incident response 

Shared services  

Source: The 2026 NASCIO State CIO Survey

Funding Instability and Federal Retrenchment 

The 2026 NASCIO State CIO Survey reveals that 65 percent of state CIO budgets include CICP funding for executive branch agencies. A third (33 percent) of CIO budgets across the country provide funding for all state agencies including agencies with separately elected officials and about another third (31 percent) provide CICP funding to local governments and special districts. A little over one-fifth (22 percent) of budgets have no funds dedicated to CICP at all.  

In researching for this project, we found that, in some cases, the state CIO organization may not be responsible for funding CICP services and that those services may be administered through other agencies such as emergency management, environmental protection or homeland security.  

The 2026 NASCIO-Deloitte Cybersecurity Study indicated that cyber budgets are failing to keep pace with rising demands in technology, talent and costs. Further complicating this challenge are concerns almost every state CISO expressed regarding the uncertainty of future federal funding, particularly Cybersecurity and Infrastructure Security Agency (CISA) programs, the Multi-State Information Sharing and Analysis Center (MS‑ISAC) and the State and Local Cybersecurity Grant Program.  

There is growing apprehension that the progress made through whole‑of‑state programs may stall or collapse without sustained federal investment, pushing states to explore legislative appropriations and sector‑specific grants to maintain essential services. States have limited resources and funding mechanisms to offer CICP outside of executive branch agencies and federal support is crucial to assisting vulnerable localities and other critical infrastructure sectors.  

OT/SCADA Vulnerabilities and Rising Cyber‑Physical Threats 

Rising operational technology (OT), Supervisory Control and Data Acquisition (SCADA) systems and cyber‑physical risks further intensify pressure on states. Our interviews found that the highest CICP risks often are in water and wastewater systems, dams and hydro-water systems, hospitals and transportation systems. These systems rely on operational technology to control and manage the physical equipment and processes. However, many states cited increased risk due to aging systems, broad remote-access exposure and emerging threats such as automated reconnaissance.  

States noted additional concerns about aging operational technology, proprietary systems and infrastructure that relies on outdated platforms that lack upgrade paths. Perhaps an even greater barrier is that, in some cases, there remains uncertainty about who is responsible when there is a critical infrastructure cyber attack, especially if legal authority, governance structures or partnerships are not in place. One state’s approach requires all utilities to perform annual cybersecurity assessments, report SCADA incidents and engage in regular state‑led coordination. This structure enables proactive critical infrastructure visibility and oversight. Another state launched a grant program led by its environmental protection state agency with federal funding to harden water providers’ OT/SCADA systems. These risks will require a coordinated approach to assess, modernize and drive cross-sector and state-level support structures to meet these escalating risks. 

Advances in technology allow for more interconnected industrial environments, remote monitoring and enhanced process optimization. But modernizations can also blur boundaries and create broader attack surfaces with cascading risks and real-world consequences.

The Road Ahead and Action Needed Now 

Overall, the findings show a nation in transition: states are stepping into broader cybersecurity leadership for critical infrastructure because the risks demand it. Yet without clearer governance authority, stronger local capacity and stable federal support, national resilience will remain uneven. State CIOs and CISOs play an increasingly important role in facilitating collaborative partnerships across sectors. Growing whole‑of‑state models, deeper regional/cross-sector collaboration and sustained investment offer the most viable paths toward securing essential services and mitigating the increasingly cyber‑physical risks facing communities nationwide. The cyber threats to critical infrastructure are only growing and states must act now. There is no “silver bullet” to solve these challenges, but there are steps that can be taken now to address critical infrastructure cyber protection: 

  • States must identify, inventory and assess high-risk critical infrastructure systems that pose the greatest risk to public health and safety and prioritize the cyber posture of those systems. 
  • States must prepare for increased AI-enabled attacks on critical infrastructure. Even without funding or authority, states must continue to lean into their whole-of-state models and collaboration with local government entities.  
  • States must also continue to build trust and coalitions with all branches of state government, the private sector, K-12, higher education and other relevant entities to collectively strengthen critical infrastructure cyber protection capabilities.  
  • States must continue to strengthen and formalize their whole-of-state governance structures for critical infrastructure, clarifying roles and defining incident prevention and response capabilities and responsibilities.  
  • States should strongly encourage (or require when possible) critical infrastructure entities to employ basic cyber hygiene such as multifactor authentication, daily backups and cyber awareness training.  
  • State legislators and/or regulators should consider mandatory reporting of cyber incidents from local governments, utilities and special districts. There are at least 10 states that mandate this reporting for CICP.  
  • States should maintain or expand critical infrastructure cyber protection services (including access to state contracts) to local governments and special districts, even when the adoption of which is not mandatory.  
  • As a critical part of our nation’s homeland security, the federal government must fund federal grants and other programs that have been crucial to the strides made in critical infrastructure cyber protection.  
  • States must also develop sustainable funding streams beyond federal assistance to ensure long-term resilience.  

About NASCIO

Founded in 1969, the National Association of State Chief Information Officers (NASCIO) represents state chief information officers (CIOs) and technology executives and managers from the states, territories and District of Columbia. NASCIO’s mission is to advance government excellence through trusted collaboration, partnerships and technology leadership. NASCIO provides state CIOs and state members with products and services designed to support the challenging role of the state CIO, stimulate the exchange of information and promote the adoption of IT best practices and innovations. From national conferences to peer networking, research and publications, briefings and government affairs, NASCIO is the premier network and resource for state CIOs.

About GDIT 

General Dynamics Information Technology is global technology and professional services company that delivers solutions and mission services to every major agency across the U.S. government, defense, intelligence community and to state and local government. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. GDIT is a business unit of General Dynamics (NYSE:GD), a global aerospace and defense company. More information about General Dynamics Information Technology is available at www.gdit.com.


Related Resources