Full Report
State governments are taking on a growing role in protecting critical infrastructure from cyber threats as risks increase across water and wastewater systems, healthcare, transportation, energy and other essential services. Drawing on the 2026 NASCIO State CIO Survey, the 2026 NASCIO-Deloitte Cybersecurity Study and interviews with state CISOs, a new NASCIO and GDIT research brief…
Analysis Summary
# Industry News: The Expanding Cyber Perimeter: States and Critical Infrastructure Protection
## Summary
A comprehensive new research brief from NASCIO and GDIT reveals that state governments are rapidly assuming a pivotal role in securing critical infrastructure (CI) against sophisticated nation-state actors and AI-driven threats. The report highlights a shift toward "whole-of-state" cybersecurity models to bridge the dangerous gap between state-level oversight and the vulnerable systems managed by local governments and special districts.
## Key Details
- **Date:** September 14, 2026
- **Companies Involved:** National Association of State Chief Information Officers (NASCIO), General Dynamics Information Technology (GDIT), Deloitte.
- **Category:** Market Research / Strategic Policy Framework
## The Story
The research brief, drawing on the 2026 NASCIO State CIO Survey and 2026 NASCIO-Deloitte Cybersecurity Study, identifies a critical vulnerability in the U.S. domestic defense posture: local governments and special districts. While these entities manage essential services like water, wastewater, healthcare, and energy, they often lack the technical capacity and funding to defend against modern cyberattacks.
State CISOs are increasingly transitioning from focusing solely on state agencies to becoming the "security coordinators" for the entire state ecosystem. However, this expansion faces significant friction. The report cites a lack of confidence among state CISOs regarding local government practices, complicated by unclear legal authority, the rapid advancement of AI-driven attacks, a persistent talent shortage, and the inherent vulnerabilities of legacy Operational Technology (OT) in critical infrastructure.
## Business Impact
### For the Companies Involved
- **GDIT & Deloitte:** Positioned as the primary strategic advisors to the public sector. Their involvement in this research suggests a long-term pipeline for consulting services, managed security services (MSSP), and large-scale infrastructure modernization contracts.
### For Competitors
- **Pure-play Cybersecurity Firms:** Will need to pivot their sales motions to account for state-level procurement that covers local municipalities. Companies specializing in OT security (e.g., Dragos, Claroty) will find an expanding market as states prioritize wastewater and energy systems.
### For Customers
- **Local Governments/Utilities:** Can expect increased state-level oversight but also greater access to "shared services" (e.g., centralized SOCs, threat intelligence feeds), potentially reducing their individual capital expenditure (CapEx) for security.
### For the Market
- **The "Whole-of-State" Market Trend:** This marks a shift from fragmented local purchasing toward centralized, state-led procurement models. This consolidation will favor vendors capable of delivering scalable, multi-tenant solutions.
## Technical Implications
The report emphasizes the convergence of IT and Operational Technology (OT). Technical solutions must now address the "air-gap" myth in water and energy sectors. Furthermore, the focus on AI-driven attacks necessitates the adoption of AI-enhanced defensive tools at the state level to match the speed of automated adversarial exploits.
## Strategic Analysis
- **Market Positioning:** States are positioning themselves as the "middle management" between federal mandates (CISA) and local execution.
- **Strategic Advantage:** A centralized governance model allows for better threat intelligence sharing and economies of scale in technology purchasing.
- **Challenges:** Funding remains "unstable," and the political friction between state oversight and local autonomy (special districts) remains a significant barrier to implementation.
## Industry Reactions
- **Analyst Opinions:** Analysts view this as an inevitable response to the systemic risk posed by "soft targets" in critical infrastructure that nation-states have begun to exploit.
- **Market Response:** There is a growing expectation for increased federal grants (e.g., SLCGP) to be funneled through these new state-led frameworks.
## Future Outlook
- **Consolidation of Services:** Expect more states to launch centralized Security Operations Centers (SOCs) that offer monitoring services to small towns and water districts.
- **Legislative Action:** Watch for state-level mandates requiring local governments to meet specific cybersecurity standards to qualify for state funding.
## For Security Professionals
Practitioners in the public sector or CI sectors should prepare for higher compliance standards and standardized reporting frameworks. There will be a high demand for professionals who understand the intersection of state policy and OT security. If you are a vendor, align your product roadmap with "shared services" capabilities to fit the whole-of-state procurement model.