States confront growing cyber gaps as critical infrastructure threats rise, report finds
State governments are taking on a larger role in protecting critical infrastructure from cyberattacks, as local governments and special districts struggle with limited cybersecurity staffing, aging technology and growing cyber-physical threats, according to a new report from the National Association of State Chief Information Officers and General Dynamics Information Technology.
The report, released on Wednesday, found that nearly 90% of state CIOs surveyed identified cyberattacks against critical infrastructure as a high concern, including threats to water and wastewater systems, hospitals, transportation, energy and communication networks. Seventy-three percent said critical infrastructure cyber protection is part of their whole-of-state cybersecurity plans. The Multi-State Information Sharing and Analysis Center has echoed calls for a “whole-of-state” approach to protecting critical infrastructure.
Dr. Mischa Beckett, senior director of cyber threat intelligence at GDIT and deputy chief information security officer for federal civilian work, said the report was prompted in part by the changing threat landscape and the fact that many of the systems Americans rely on are operated by state, local and private-sector entities.
“So, both [those] external forces of the threat landscape and the reality of who’s kind of on the front lines now, wanting to take their temperature with regard to the realities they’re facing,” Beckett explained in an interview. “We need to go right to the source and ask the folks who control the budgets and the technology what their perceptions and understandings are about how this is going for them in real life.”
The cybersecurity threats themselves aren’t necessarily new, Beckett said, noting that critical infrastructure has been considered a valuable target for decades, but public awareness has increased significantly in recent years.
“I think we haven’t talked about it very openly until the last five or 10 years,” she said. “People really are much, much more aware of cyber as a threat and the ways it touches their day-to-day life.”
But that growing awareness, she said, has not been matched by resources.
States and localities are increasingly expected to mount a collective defense as cyber threats outpace the resources of smaller jurisdictions. However, the report found that 65% of state CIO budgets include critical infrastructure cybersecurity funding for executive branch agencies, where only 31% provide funding to local governments and special districts. Twenty-two percent of CIO budgets have no dedicated critical infrastructure cybersecurity funding.
“What really hit me about the study is that disconnect,” Beckett said, pointing to smaller water facilities that may have only four or five employees, none of whom necessarily have information technology or cybersecurity expertise.
The report also highlights operational technology systems as a growing concern.
Unlike conventional IT systems, Beckett explained, OT systems can remain in service for decades, sometimes predating widespread internet connectivity. Yet many systems have been connected to the internet in recent years to make remote monitoring and operation management easier, but also introducing more opportunities for attacks.
“You can have things that have been running for 25 or 30 years,” Beckett said. “You’re looking at old technology that was stood up prior to everything being internet connected, prior to the cyber threat landscape with AI [and] with nation states that we’re dealing with now.”
She emphasized that cybersecurity, rather than being treated as a separate concern, also needs to be incorporated into operational risk discussions, such as reducing unnecessary internet exposure, identifying vendor contacts and conducting short tabletop exercises to determine who would make decisions during an incident or whether a facility could switch to manual operations.
“We’ve got to not silo cybersecurity and really put it into the same operational risk understanding, so that we stop kind of butting heads between what OT folks focused on their mission and what the cybersecurity folks are telling them they should do,” she explained.
The report recommends states inventory high-risk infrastructure, formalize whole-of-state governance, expand shared cybersecurity services and implement basic protections such as multifactor authentication and regular backups.
It also urges states to develop sustainable funding mechanisms as federal cybersecurity support remains uncertain, including Cybersecurity and Infrastructure Security Agency programs and the State and Local Cybersecurity Grant Program, which tops NASCIO’s congressional priorities for the upcoming year. Beckett pointed to Texas’ Project Watershed 250 pilot, a six-month test program that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector, as an example.
Despite the challenges, Beckett said she remains optimistic that states and localities can improve their defenses.
“I think watching how much progress has been made in education and awareness just for the average person out there, including critical infrastructure operators, that makes me hopeful,” she said.