States and Localities Face Cybersecurity Threats as Federal Support Wanes

As the number of cyber threats against governments continues to rise, states and localities are facing increasing pressure to strengthen their cybersecurity efforts. However, efforts to do so are being hindered by federal cuts and a lack of preparedness. According to Chase Fopiano, a cybersecurity expert and regional task force leader, thousands of attempts are made to compromise networks and organizations every day, with a significant number of those targeting government agencies.

The Multi-State Information Sharing and Analysis Center has reported a rise in cyber threats, including threats to critical infrastructure, increased activity from foreign actors, and continued ransomware attacks. Budget restrictions, staff issues, and the increasing use of AI are also posing significant challenges to states' cybersecurity efforts. Despite these threats, some states are taking steps to address the problem, including establishing new penalties for tampering with critical infrastructure and centralizing state IT personnel.

In 2023, only 22 states reached or surpassed the recommended levels of security in their systems, as determined by the Nationwide Cybersecurity Review. Samir Jain, Vice President of Policy at the Center for Democracy & Technology, has expressed concerns about the notion that the federal government could withdraw its support and expect states and localities to step in on their own. "The federal government has traditionally played at least some role in trying to fill some of those gaps," Jain said.

The State and Local Cybersecurity Grant Program, which provided over $1 billion in funding for states and localities to address cybersecurity risks and threats, is set to expire in September with no current plans to renew it. Meanwhile, the Trump administration is cutting as many as 1,300 employees from the Cybersecurity and Infrastructure Security Agency, which administers the grants alongside the Federal Emergency Management Agency.

Key Takeaways:

  • The number of cyber threats against governments continues to rise, with thousands of attempts made to compromise networks and organizations every day.
  • Budget restrictions, staff issues, and the increasing use of AI are posing significant challenges to states' cybersecurity efforts.
  • In 2023, only 22 states reached or surpassed the recommended levels of security in their systems, as determined by the Nationwide Cybersecurity Review.
  • The State and Local Cybersecurity Grant Program is set to expire in September with no current plans to renew it.
  • The Trump administration is cutting as many as 1,300 employees from the Cybersecurity and Infrastructure Security Agency, which administers the grants alongside the Federal Emergency Management Agency.
  • Some states, such as New Mexico and Indiana, are taking steps to address the problem, including establishing new penalties for tampering with critical infrastructure and centralizing state IT personnel.
  • Arkansas has enacted legislation to create a new state cybersecurity office, which will monitor the state's computer networks and respond to cyber threats.
  • Alabama is considering legislation that would give the Alabama Office of Information Technology central authority to maintain the needs of all of the state's departments, making it easier to pursue cybersecurity initiatives.

Statistics:

  • Thousands of attempts are made to compromise networks and organizations every day, with a significant number of those targeting government agencies.
  • Only 22 states reached or surpassed the recommended levels of security in their systems in 2023, as determined by the Nationwide Cybersecurity Review.
  • The State and Local Cybersecurity Grant Program has provided over $1 billion in funding for states and localities to address cybersecurity risks and threats since its inception.
  • As many as 1,300 employees are being cut from the Cybersecurity and Infrastructure Security Agency, which administers the grants alongside the Federal Emergency Management Agency.
  • 33 states adopted resolutions or enacted legislation regarding cybersecurity in 2024, according to the National Conference of State Legislatures.

Sources:

  • National Conference of State Legislatures, "Cybersecurity 2024 Legislation"
  • Stateline, "Budget restrictions, staff issues and AI are threats to states' cybersecurity"
  • Security Intelligence, "When Ransomware Kills: Attacks on Healthcare Facilities"
  • State Court Report, "State and Local Courts Struggle to Fight Increasing Cyberattacks"
  • Multi-State Information Sharing and Analysis Center, "Strengthening Critical Infrastructure SLTT Progress Priorities Brief Report Vol 1"
  • Rhode Island Current, "Rhode Island state government hit by major cyberattack"
  • Washington Post, "Virginia attorney general's office hit by 'sophisticated cyberattack'"