National Cybersecurity Shift: State and Local Agencies on the Frontline

State and local agencies have been entrusted with protecting critical infrastructure from domestic and foreign cyber threats, following the release of the National Resilience Strategy. Federal budget reductions have further exacerbated the challenge, forcing states to fight for safeguarding election systems and public services infrastructure. With nearly 40% of chief information security officers reporting insufficient funding for adequate cybersecurity measures, the time for a new approach to consolidate tools and manage cyber risks effectively has arrived.

Key Takeaways:

  • The National Resilience Strategy places state and local agencies at the forefront of domestic and foreign cyber threat protection.
  • 40% of chief information security officers report insufficient funding for adequate cybersecurity measures (Route Fifty, 2024).
  • Relying on siloed tools is ineffective against advanced ransomware attacks and generative AI-powered cyberattacks.
  • The Risk Operations Center (ROC) framework provides a unified approach to strategic threat prioritization and infrastructure resilience.
  • ROCs prioritize proactive risk management, identifying systemic vulnerabilities before they become crises, and facilitate collaboration across agencies to collectively defend against emerging threats.
  • ROCs collect security data as risk telemetry, displaying complete threat and vulnerability insights across state and local agencies without requiring system replacements.
  • Centralizing expertise within a ROC maximizes the impact of skilled personnel while leveraging automation to handle routine tasks.
  • The National Association of State Chief Information Officers champions a whole-of-state approach to cybersecurity, emphasizing collaboration across state and local entities to address increasing cyberattacks.

Statistics:

  • 40% of chief information security officers report insufficient funding for adequate cybersecurity measures (Route Fifty, 2024).
  • 85% of organizations currently use more than 10 security tools, and 60% of those use more than 20 (Gartner, 2023).
  • 76% of organizations say it's difficult to get insight into potential threats (IBM Security, X-Force, 2023).
  • 99% of critical infrastructures are connected to the internet, making them vulnerable to cyber threats (Shodan, 2022).

Sources:

  • "National Resilience Strategy" (Whitehouse, 2025)
  • "Amid Tight Budgets, and Talent Gaps, Technology Chiefs Job Just Keeps Expanding" (Route Fifty, 2024)
  • "The American Water Cyberattack: Explaining How It Happened" (Tech Target)
  • "Risk Operations Center"

- "Risk Operations Center: A Strategic Framework for State and Local Cyber Risk Management"

- "National Association of State Chief Information Officers: A Whole-of-State Approach to Cybersecurity"