惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
D
Docker
J
Java Code Geeks
腾讯CDC
Blog — PlanetScale
Blog — PlanetScale
G
Google Developers Blog
M
MIT News - Artificial intelligence
L
LangChain Blog
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
MyScale Blog
MyScale Blog
博客园 - Franky
GbyAI
GbyAI
Hugging Face - Blog
Hugging Face - Blog
aimingoo的专栏
aimingoo的专栏
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
N
Netflix TechBlog - Medium
B
Blog RSS Feed
Y
Y Combinator Blog
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google DeepMind News
Google DeepMind News

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
State CISOs losing confidence in ability to manage cyber ...
David Jones · 2026-04-29 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

Deloitte-NASCIO study shows AI, budget pressures are forcing states to make tough decisions.

Published April 29, 2026

a digital padlock illustration with the letters AI

BlackJack3D via Getty Images

Dive Brief:

  • Statewide chief information security officers are losing confidence in their ability to manage cyber risk amid a rising threat landscape and declining resources, according to a study released Monday by Deloitte and the National Association of State Chief Information Officers.
  • About one-quarter of statewide CISOs said they were “extremely” or “very” confident that state assets were protected from cyber threats in the current survey. In 2022, nearly half of respondents said so.
  • CISOs also reported rising concerns about the ability of local governments and higher education institutions to secure public data. Almost two-thirds of respondents said they were “not very confident,” compared with 35% in 2022.

Dive Insight:

The growing concerns about cyber risk come at a time of increased threats from state-sponsored hackers, rising use of AI and increased pressure on budgets. 

State and local governments increasingly have become the targets of criminal ransomware groups and state-sponsored hackers. In addition, federal budget cuts under the Trump administration have shifted much of the cyber risk burden to state and local officials, who must increasingly take the lead for securing critical infrastructure. 

“So, one of the big discussions with CISOs is how to articulate the business benefit of investment in cybersecurity,” Michael Wyatt, state, local and higher education cyber risk leader at Deloitte, told Cybersecurity Dive. 

About half of all statewide CISOs said implementing effective metrics was their top priority, compared with only 15% in 2022. State CISOs have also been grappling with adoption of AI and managing those risks.

The report comes about six months after Nevada issued an after-action report on a 28-day ransomware attack it suffered in August 2025. Nevada’s cyberattack was linked to an accidental malware download by an employee. The state refused to pay an extortion demand, but incurred about $1.3 million in recovery expenses.

Meanwhile, the state of Rhode Island was impacted by a December 2024 attack against the RIBridges social services portal, which was managed by Deloitte. The company agreed to pay $5 million to cover those expenses.