State CIOs Rank Security as No. 1 Priority for 9th Year
Cybersecurity and data privacy are not only top of mind for state CIOs, but also integral to their evolution toward digital government and citizenship.
- State governments represent a big target for cyberattacks.
- State CIOs continue to prioritize this risk, but with limited resources.
- Recent research shows how state governments’ risk profile is evolving.
State governments have a lot on their plates — especially in light of the COVID-19 pandemic. Yet what preoccupies state CIOs the most is cybersecurity, according to the National Association of State Chief Information Officers (NASCIO). In fact, for the 9th year in a row, cybersecurity held the top spot in the 2022 edition of the organization’s “State CIO Top 10 Priorities.”
The need for such focus was again driven home just days after the survey’s publication earlier this month, when yet another high-profile state government cyberattack made the news. In this case, a ransomware attack took Virginia’s state legislature offline.
The public sector has been hit with increasing frequency since the beginning of the pandemic, when more than half of public sector security officers said it was “likely” to “inevitable” that an email-borne attack would inflict serious harm to their organizations, according to Mimecast’s 2020 State of Email Security in the U.S. Public Sector.
As it turned out in 2020, one estimate showed that over 1,790 federal, state and municipal governments and schools in the U.S. were impacted by one of the most pernicious cybercrimes — ransomware. While public sector statistics are still being tallied for the current year, general trends show a 17% increase in reported data breaches of all kinds in the U.S. through the third quarter of 2021. The public sector is generally hit harder than most, mainly because its organizations hold highly sensitive information and have weaker defenses that make them an easier target for cybercriminals.
Looking ahead to the new year, state CIOs expressed determination to take action in several key areas, according to NASCIO’s annual survey for 2021, which complements the Top 10 list. Over 80% said they intend to adopt or expand identity and access management solutions in the next two to three years. The same goes for performing continuous enterprise cybersecurity assessments (69%), introducing or expanding a zero-trust framework (67%) and conducting cybersecurity awareness training (56%).
But in the face of one of the biggest enduring changes brought on by the pandemic — remote work — the NASCIO survey also revealed little new funding heading to state governments in the coming year. Over 80% of CIOs reported no budget increases to address new or increased remote work needs, which have complicated security and expanded their states’ attack surfaces.
Security and Privacy Themes Run Through CIO Priorities
Not only is cybersecurity the top priority of state CIOs, but many of their other priorities reflect specific security and privacy needs. For example, Priority No. 2 is “digital government/digital services,” which is broken out to include identity management and privacy while “improving and digitizing citizen experience.”
CIOs are also intent on “legacy modernization,” a goal that made it back on the list for the first time in five years, coming in at Priority No. 5. Among its many values, updating legacy systems is recognized as a necessity for closing security gaps.
And so the list goes on through a range of security-relevant policies and management processes, including “identity and access management” as Priority No. 6. CIOs also emphasized the security, privacy and data governance aspects of other big priorities, such as “cloud services” (Priority No. 4) and “data and information management” (Priority No. 9).
How the Pandemic Response Has Changed State Cybersecurity
In NASCIO’s annual survey, CIOs described how their states’ responses to the pandemic have changed their cybersecurity systems and procedures. Generally, the report said: “With the shift to an increasingly digital government and remote work here to stay, CIOs have evolved their approach to cybersecurity to further address the distributed environment and human element of cyber threats.”
Specific survey results include:
- 67% have enhanced encryption and security for online work at home.
- 65% now have standards for cloud security.
- 57% see security driving their cloud strategies.
- 41% see disaster recovery and risk management driving their transition to the cloud.
- 60% have at least partially implemented identity and access management.
- 60% have accelerated the modernization of their insecure legacy systems.
Many state CIOs (57%) described ransomware as a key motivator for change. “Ransomware will continue to be a significant threat for government agencies,” according to Cybersecurity in Government 2021, an Osterman Research report commissioned by Mimecast.
Yet ransomware is not the only threat to states’ data and operations. “Governments are under attack from a wide range of cyberattacks, including ransomware, phishing, business email compromise, data breaches and misconfigured cloud storage accounts,” the Osterman report said. Most attacks originate with email phishing, it said.
Will State Cybersecurity Budgets Rise to the Challenge?
Cybersecurity budgets would have to stretch far to meet all the needs described in the Top 10 report. Yet state cybersecurity funding remains tight.
State governments allocate less than 3% of their IT budgets to cybersecurity, compared with about 7% in the federal Department of Transportation and 11% in the U.S. Social Security Administration, according to a 2020 NASCIO-Deloitte report. While IT funding improved during the early part of the pandemic, as emergency projects were accelerated, CIOs polled in NASCIO’s annual survey see this as a blip. As mentioned above, fewer than 20% expect an increase in 2022, even as remote and hybrid work arrangements are expected to continue.
Some help is on the way, with $1 billion in state and local cybersecurity grants included in the Biden administration’s infrastructure package, plus $100 million for cyber response and recovery, among other allocations. The funds are expected to be rolled out from 2022 to 2025 to address cybersecurity risks, and they must address rural populations, which can be hit even harder than urban areas. As for cyber response and recovery funding, this nontraditional grant will be disbursed by the Cybersecurity and Infrastructure Security Agency (CISA) to governments affected by cyberattacks, demonstrating a partnership between federal and state groups to deliver critical response and recovery including vulnerability assessments, mitigation, and malware analysis. In another promising development for public sector CIOs, the StateRAMP cloud security standards group recently published its first list of authorized vendors, including Mimecast.
The Bottom Line
For nine years running, CIOs serving state governments have listed cybersecurity as their top priority. They’re taking many steps to reduce their risk, but tight budgets and legacy systems continue to make them more vulnerable than most organizations.
 “State CIO Top Ten Policy and Technology Priorities for 2022,” National Association of State Chief Information Officers
 “Ransomware Attack Hits Virginia Legislature,” CNN
 “Number of Data Breaches in 2021 Surpasses All of 2020,” Identity Theft Resource Center
 “2021 Data Breach Investigations Report,” Verizon
 “Why Government Institutions Are the Perfect Target for Hackers,” Government Technology
 “The 2021 State CIO Survey,” National Association of State Chief Information Officers
 “2020 Deloitte-NASCIO Cybersecurity Study,” Deloitte and National Association of State Chief Information Officers
 “StateRAMP Authorized Vendors,” StateRAMP
Subscribe to Cyber Resilience Insights for more articles like these
Get all the latest news and cybersecurity industry analysis delivered right to your inbox
Sign up successful
Thank you for signing up to receive updates from our blog
We will be in touch!