State chief information officers are increasingly taking responsibility for protecting critical infrastructure from cyber threats, with 90% identifying cyberattacks as a high concern and 73% incorporating protections into comprehensive state plans. However, fragmented authority, capability gaps, unstable funding, and vulnerable OT (operational technology) remain persistent obstacles. Drawing on the 2026 NASCIO State CIO Survey, the 2026 NASCIO-Deloitte Cybersecurity Study, and interviews with state CISOs, the National Association of State Chief Information Officers (NASCIO) and General Dynamics Information Technology (GDIT) research brief revealed that CIOs are not confident in the cyber practices of local governments. At the same time, there are questions about what the right approach is to assist local governments and special districts in securing critical infrastructure.
At the same time, state CIOs and CISOs are grappling with AI (artificial intelligence) advancing speed and sophistication of attacks, shortfall of qualified cybersecurity professionals, and expanding role of states in strengthening critical infrastructure from cyber threats.
“In the 2026 NASCIO State CIO Survey, CIOs overwhelmingly indicated that protecting critical infrastructure is a top-tier concern,” the joint report detailed. “Nearly 90 percent of respondents identified cyber attacks targeting critical systems, such as communications networks, electric grids, water/wastewater systems, data centers, hospitals, oil pipelines and others, as a high concern. The remaining CIOs identified cyber attacks targeting critical infrastructure as concerning at a moderate level, indicating a near-unanimous recognition of the cyber risks facing critical infrastructure and states.”
This comes as smaller local governments and special districts are particularly vulnerable due to limited staffing and aging infrastructure, though states are expanding support through assessments, incident response, and training—about 32% of state CIOs provide services to utilities and 24% to healthcare facilities.
The NASCIO-GDIT report found that sustained federal funding and stronger state-level governance are needed to maintain progress. Challenges include managing state-local relationships, closing technological gaps, and securing funding, covering concerns intensified by nation-state involvement in critical infrastructure attacks.
“Rising operational technology (OT), Supervisory Control and Data Acquisition (SCADA) systems and cyber‑physical risks further intensify pressure on states,” the report identified. “Our interviews found that the highest CICP risks often are in water and wastewater systems, dams and hydro-water systems, hospitals and transportation systems. These systems rely on operational technology to control and manage the physical equipment and processes. However, many states cited increased risk due to aging systems, broad remote-access exposure and emerging threats such as automated reconnaissance.”
States noted additional concerns about aging OT, proprietary systems and infrastructure that relies on outdated platforms that lack upgrade paths. Perhaps an even greater barrier is that, in some cases, there remains uncertainty about who is responsible when there is a critical infrastructure cyberattack, especially if legal authority, governance structures or partnerships are not in place.
One state’s approach requires all utilities to perform annual cybersecurity assessments, report SCADA incidents and engage in regular state‑led coordination. This structure enables proactive critical infrastructure visibility and oversight. Another state launched a grant program led by its environmental protection state agency with federal funding to harden water providers’ OT/SCADA systems. These risks will require a coordinated approach to assess, modernize and drive cross-sector and state-level support structures to meet escalating risks.
Advances in technology allow for more interconnected industrial environments, remote monitoring and enhanced process optimization. But modernizations can also blur boundaries and create broader attack surfaces with cascading risks and real-world consequences.
Data indicate that whole‑of‑state cybersecurity models are emerging as the primary framework for improving statewide cyber resilience in critical infrastructure. The 2026 State CIO Survey asked if critical infrastructure cyber protection is part of state whole-of-state comprehensive plans and majority of states (73%) said yes.
“Our interviews solidify this data point as states consistently described movement toward ‘whole‑of‑state’ cybersecurity coordination,” it added. “However, the