State chief information security officers are being asked to govern generative AI, defend aging systems, help local governments and protect critical infrastructure while their budgets flatten or fall — and the 2026 NASCIO-Deloitte study suggests the expansion has outrun the capacity to do the job. The clearest practical signal is financial: eight states reported year-over-year cybersecurity budget reductions, while only 22% reported increases of at least 6%, down from 40% in 2024.
Federal News Network highlighted the study’s warning that state CISOs are confronting more sophisticated threats with fewer dependable resources. The underlying NASCIO-Deloitte report makes the operational consequence sharper: states are trying to add whole-of-state services and AI governance on top of cybersecurity programs still constrained by legacy infrastructure, incomplete visibility into spending, staffing limits and uncertain federal grant support.
This is not simply a complaint about appropriations. The survey shows a job changing from security operations into enterprise risk management for systems the state CISO may not own or control. For IT leaders, that means the next budget conversation will increasingly turn on whether they can demonstrate service continuity, recovery readiness and measurable risk reduction — not whether they can name the latest threat actor or buy another security platform.
The survey’s main conclusion is unambiguous: state CISOs are much less confident in their ability to protect public data than they were four years ago. Deloitte’s full study says 22% of respondents were “extremely” or “very confident” that their state could protect information assets from external threats, down from 48% in 2022. Federal News Network reported the same figure.
But NASCIO’s April 27 press release and Deloitte’s matching news release state that 26% of CISOs had that level of confidence, using apparently the same question and the same 48% 2022 comparison. Neither public release explains the difference.
It is a small numerical gap but a meaningful reporting flaw, particularly in a study built around survey percentages. The report says responses came from all 50 states, the District of Columbia and the U.S. Virgin Islands, while one partially completed questionnaire meant some questions had 51 responses rather than 52. The public materials do not identify the denominator used for the confidence result or reconcile 22% with 26%.
Readers should not let that discrepancy obscure the larger result: whether the count was roughly one-fifth or one-quarter, confidence has collapsed by about half since 2022. But the mismatch is also an example of the reporting discipline the study says CISOs themselves now need. When cybersecurity leaders are being told to prove value through metrics, their own benchmark reports need definitions and denominators that can withstand a legislative budget hearing.
The confidence problem extends past state data centers. Deloitte reports that 63% of respondents were “not very confident” in the cybersecurity capabilities of local governments and public higher education, up from 35% in 2022. That is the more consequential number for residents: state systems routinely connect to county-administered benefits, public colleges, school districts, courts, utilities and outside service providers. A weak local environment can become an entry point, outage multiplier or recovery burden even where the state’s own security team is comparatively mature.
The immediate threat is not limited to AI-assisted phishing or automated vulnerability discovery. The report identifies a more mundane risk that Windows administrators and security teams already recognize: vendors adding AI functions to existing products, sometimes enabled by default or controlled from a cloud service rather than a local policy. Those changes can alter where data is processed, which users can access a feature, what is retained for model improvement and whether sensitive information can be pasted into an assistant.
For a state government, that creates a governance problem across thousands of agencies, contractors and endpoint configurations. An acceptable-use policy is necessary, but it is not a technical control. Agencies need an inventory of AI-capable features in their current SaaS, productivity and line-of-business software; a data classification standard that employees can follow; and controls that prevent regulated or sensitive data from reaching unauthorized services.
The survey also records states using AI for alert triage, event summarization, documentation, reporting and threat identification. Those uses are more defensible than broad public-facing deployments because they can reduce analyst workload without immediately making automated decisions about benefits, licensing, enforcement or health services. Still, the study does not say how states are validating AI-generated incident summaries, preserving evidence, or preventing prompt injection and data leakage within security operations tools. Those unanswered implementation details will determine whether AI improves response time or simply adds a faster path for bad conclusions to enter an incident record.
The report proposes operational, compliance and risk-oriented indicators such as incident-response time and phishing click rates. Those can be useful, but they must be handled carefully. A shorter response time may reflect stronger detection and better staffing; it may also reflect a change in what incidents get counted. A lower phishing click rate may show effective training, or may show that the test was easier. Metrics become valuable when they are tied to a defined service, baseline, target and consequence.
For state IT organizations, the better starting set is often less glamorous:
This is why effectiveness metrics are becoming a political necessity. A CISO who cannot demonstrate which systems received security coverage, where the remaining gaps are and what a dollar closes may be unable to defend funding against competing public-service demands. But metrics alone cannot repair an underfunded program. They can make the tradeoff visible — including the risk being accepted when a legislature funds another priority instead.
The appeal is obvious. Local governments and public education institutions often lack a 24/7 SOC, dedicated incident responders or procurement leverage for enterprise security tools. A state can pool expertise and negotiate services at a scale a small municipality cannot reach. It can also see cross-jurisdictional attack patterns that a county IT department would miss.
Yet “whole-of-state” should not be mistaken for a single, mature operating model. The study’s own respondents described highly uneven adoption: some already run broad centralized services, some are planning opt-in models, and others are still determining their authority and funding. The report also notes that local governments may welcome funded help while retaining a preference for independence. That makes the hard questions governance questions: who sets security baselines, who pays recurring costs, who owns incident decisions, and what support remains when emergency grants end?
Federal funding has helped create capacity for this work. The State and Local Cybersecurity Grant Program was established through the Infrastructure Investment and Jobs Act to fund state, local, tribal and territorial cybersecurity projects, and survey respondents identified it as a major driver of local-government collaboration. But the NASCIO-Deloitte study was fielded after its launch in late October 2025, when renewal uncertainty was already affecting state planning. A grant can build a SOC integration, deploy endpoint tooling or stand up a regional service; it does not guarantee the annual operating funds needed to retain analysts and renew licenses after the award period.
Texas is the prominent counterexample cited by Deloitte’s Mike Wyatt, and it is a real one. Texas created the Texas Cyber Command through House Bill 150 in 2025, with the Texas Department of Information Resources saying in April that cybersecurity functions were transitioning to the new centralized authority. State budget records show more than $135 million in general-revenue funding connected to the command in fiscal year 2026, along with additional staffing. That is state funding, not a short-lived federal grant.
But Texas also illustrates the scale required. The command is a new statewide agency with statutory responsibilities and a transition extending into late 2026. Other states cannot replicate the outcome simply by renaming an existing CISO office or directing a thinly staffed SOC to support every county, school district and public university.
That does not mean the staffing problem has been solved. Only 22% of CISOs said their staff had the competencies needed to meet current and future cybersecurity demands, down from 47% in 2024. The report’s evidence points to a shift from an applicant-shortage problem toward a capacity and skills-deployment problem. A state may be able to hire a security practitioner, yet still lack the headcount, pay flexibility, tooling or training budget to build an incident-response, cloud-security, identity or AI-governance capability at the required depth.
For Windows-heavy state environments, that distinction matters. Centralized identity, privileged access, endpoint telemetry, patch compliance and recovery testing require operators who understand the tools well enough to configure and sustain them. Buying a Microsoft security license, deploying an EDR agent or declaring a Zero Trust initiative does not create the personnel needed to tune detections, investigate alerts and fix the underlying identity or network weakness.
The survey’s warning is therefore more concrete than “cybersecurity is hard.” State CISOs are being turned into the accountable leaders for a larger public-sector attack surface while the money, authority and staff necessary to cover that surface remain uneven. The immediate test is whether states convert their new appetite for metrics into funded service commitments — published coverage targets, recurring operational budgets and clear responsibility for local partners — before the next ransomware event turns an acknowledged gap into a statewide outage.
This is not simply a complaint about appropriations. The survey shows a job changing from security operations into enterprise risk management for systems the state CISO may not own or control. For IT leaders, that means the next budget conversation will increasingly turn on whether they can demonstrate service continuity, recovery readiness and measurable risk reduction — not whether they can name the latest threat actor or buy another security platform.
Confidence Has Fallen, but the Survey’s Headline Number Is Inconsistent
The survey’s main conclusion is unambiguous: state CISOs are much less confident in their ability to protect public data than they were four years ago. Deloitte’s full study says 22% of respondents were “extremely” or “very confident” that their state could protect information assets from external threats, down from 48% in 2022. Federal News Network reported the same figure.But NASCIO’s April 27 press release and Deloitte’s matching news release state that 26% of CISOs had that level of confidence, using apparently the same question and the same 48% 2022 comparison. Neither public release explains the difference.
It is a small numerical gap but a meaningful reporting flaw, particularly in a study built around survey percentages. The report says responses came from all 50 states, the District of Columbia and the U.S. Virgin Islands, while one partially completed questionnaire meant some questions had 51 responses rather than 52. The public materials do not identify the denominator used for the confidence result or reconcile 22% with 26%.
Readers should not let that discrepancy obscure the larger result: whether the count was roughly one-fifth or one-quarter, confidence has collapsed by about half since 2022. But the mismatch is also an example of the reporting discipline the study says CISOs themselves now need. When cybersecurity leaders are being told to prove value through metrics, their own benchmark reports need definitions and denominators that can withstand a legislative budget hearing.
The confidence problem extends past state data centers. Deloitte reports that 63% of respondents were “not very confident” in the cybersecurity capabilities of local governments and public higher education, up from 35% in 2022. That is the more consequential number for residents: state systems routinely connect to county-administered benefits, public colleges, school districts, courts, utilities and outside service providers. A weak local environment can become an entry point, outage multiplier or recovery burden even where the state’s own security team is comparatively mature.
AI Has Made the CISO a Governance Office
Generative AI is one reason the state CISO role is broadening so rapidly. The study found 94% of CISOs are involved in developing GenAI security policies, and 84% are involved in GenAI strategy development. That is a substantial change in responsibility: the CISO is no longer being brought in solely after an agency selects a tool or a vendor asks for an exception. In many states, the office is now expected to shape whether and how AI is deployed in the first place.The immediate threat is not limited to AI-assisted phishing or automated vulnerability discovery. The report identifies a more mundane risk that Windows administrators and security teams already recognize: vendors adding AI functions to existing products, sometimes enabled by default or controlled from a cloud service rather than a local policy. Those changes can alter where data is processed, which users can access a feature, what is retained for model improvement and whether sensitive information can be pasted into an assistant.
For a state government, that creates a governance problem across thousands of agencies, contractors and endpoint configurations. An acceptable-use policy is necessary, but it is not a technical control. Agencies need an inventory of AI-capable features in their current SaaS, productivity and line-of-business software; a data classification standard that employees can follow; and controls that prevent regulated or sensitive data from reaching unauthorized services.
The survey also records states using AI for alert triage, event summarization, documentation, reporting and threat identification. Those uses are more defensible than broad public-facing deployments because they can reduce analyst workload without immediately making automated decisions about benefits, licensing, enforcement or health services. Still, the study does not say how states are validating AI-generated incident summaries, preserving evidence, or preventing prompt injection and data leakage within security operations tools. Those unanswered implementation details will determine whether AI improves response time or simply adds a faster path for bad conclusions to enter an incident record.
Metrics Are Becoming a Survival Tool, Not a Maturity Trophy
Nearly half of the surveyed CISOs — 49% in the NASCIO and Deloitte releases, described as half in the full report — named implementing effectiveness metrics as a top cybersecurity initiative. That is a telling shift. Identity and access management, Zero Trust and modernization projects are still on the agenda, but CISOs are prioritizing the ability to explain whether spending changes the risk picture.The report proposes operational, compliance and risk-oriented indicators such as incident-response time and phishing click rates. Those can be useful, but they must be handled carefully. A shorter response time may reflect stronger detection and better staffing; it may also reflect a change in what incidents get counted. A lower phishing click rate may show effective training, or may show that the test was easier. Metrics become valuable when they are tied to a defined service, baseline, target and consequence.
For state IT organizations, the better starting set is often less glamorous:
- Measure the percentage of critical systems with tested recovery procedures, rather than merely counting backup deployments.
- Track privileged-account coverage under phishing-resistant multifactor authentication and the time required to remove access for departed employees.
- Report the age and remediation status of internet-facing systems, especially legacy applications that cannot receive current patches.
- Distinguish between agencies receiving centrally managed endpoint detection, logging and incident-response support and agencies merely covered by policy.
This is why effectiveness metrics are becoming a political necessity. A CISO who cannot demonstrate which systems received security coverage, where the remaining gaps are and what a dollar closes may be unable to defend funding against competing public-service demands. But metrics alone cannot repair an underfunded program. They can make the tradeoff visible — including the risk being accepted when a legislature funds another priority instead.
Whole-of-State Security Needs Authority as Well as Funding
The report says roughly one-fifth of respondents were fully or partly moving forward with a whole-of-state cybersecurity approach. In practice, that can mean a state security operations center serving local governments, state-funded shared services for K-12 schools and counties, centralized threat intelligence, incident-response help, training, or regional field support.The appeal is obvious. Local governments and public education institutions often lack a 24/7 SOC, dedicated incident responders or procurement leverage for enterprise security tools. A state can pool expertise and negotiate services at a scale a small municipality cannot reach. It can also see cross-jurisdictional attack patterns that a county IT department would miss.
Yet “whole-of-state” should not be mistaken for a single, mature operating model. The study’s own respondents described highly uneven adoption: some already run broad centralized services, some are planning opt-in models, and others are still determining their authority and funding. The report also notes that local governments may welcome funded help while retaining a preference for independence. That makes the hard questions governance questions: who sets security baselines, who pays recurring costs, who owns incident decisions, and what support remains when emergency grants end?
Federal funding has helped create capacity for this work. The State and Local Cybersecurity Grant Program was established through the Infrastructure Investment and Jobs Act to fund state, local, tribal and territorial cybersecurity projects, and survey respondents identified it as a major driver of local-government collaboration. But the NASCIO-Deloitte study was fielded after its launch in late October 2025, when renewal uncertainty was already affecting state planning. A grant can build a SOC integration, deploy endpoint tooling or stand up a regional service; it does not guarantee the annual operating funds needed to retain analysts and renew licenses after the award period.
Texas is the prominent counterexample cited by Deloitte’s Mike Wyatt, and it is a real one. Texas created the Texas Cyber Command through House Bill 150 in 2025, with the Texas Department of Information Resources saying in April that cybersecurity functions were transitioning to the new centralized authority. State budget records show more than $135 million in general-revenue funding connected to the command in fiscal year 2026, along with additional staffing. That is state funding, not a short-lived federal grant.
But Texas also illustrates the scale required. The command is a new statewide agency with statutory responsibilities and a transition extending into late 2026. Other states cannot replicate the outcome simply by renaming an existing CISO office or directing a thinly staffed SOC to support every county, school district and public university.
The Workforce Finding Is More Nuanced Than a Hiring Shortage
The study offers one relative bright spot: fewer CISOs put the availability of cybersecurity professionals among their top five barriers, falling from 50% in 2022 to 22% in 2026. States are also placing greater emphasis on certifications and training, while more respondents say they are dropping four-year degree requirements for cyber roles.That does not mean the staffing problem has been solved. Only 22% of CISOs said their staff had the competencies needed to meet current and future cybersecurity demands, down from 47% in 2024. The report’s evidence points to a shift from an applicant-shortage problem toward a capacity and skills-deployment problem. A state may be able to hire a security practitioner, yet still lack the headcount, pay flexibility, tooling or training budget to build an incident-response, cloud-security, identity or AI-governance capability at the required depth.
For Windows-heavy state environments, that distinction matters. Centralized identity, privileged access, endpoint telemetry, patch compliance and recovery testing require operators who understand the tools well enough to configure and sustain them. Buying a Microsoft security license, deploying an EDR agent or declaring a Zero Trust initiative does not create the personnel needed to tune detections, investigate alerts and fix the underlying identity or network weakness.
The survey’s warning is therefore more concrete than “cybersecurity is hard.” State CISOs are being turned into the accountable leaders for a larger public-sector attack surface while the money, authority and staff necessary to cover that surface remain uneven. The immediate test is whether states convert their new appetite for metrics into funded service commitments — published coverage targets, recurring operational budgets and clear responsibility for local partners — before the next ransomware event turns an acknowledged gap into a statewide outage.
References
- Primary source: Federal News Network
Published: 2026-08-03T22:19:32+00:00
Loading…
federalnewsnetwork.com - Related coverage: nascio.org
Loading…
www.nascio.org - Related coverage: nascio.org
Loading…
www.nascio.org - Related coverage: deloitte.com
Loading…
www.deloitte.com - Related coverage: deloitte.com
Loading…
www.deloitte.com - Related coverage: cisa.gov
Loading…
www.cisa.gov - Related coverage: dir.texas.gov
Loading…
dir.texas.gov - Related coverage: cisa.gov
Loading…
www.cisa.gov