惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
MongoDB | Blog
MongoDB | Blog
Engineering at Meta
Engineering at Meta
云风的 BLOG
云风的 BLOG
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
T
The Exploit Database - CXSecurity.com
P
Privacy & Cybersecurity Law Blog
Know Your Adversary
Know Your Adversary
月光博客
月光博客
I
InfoQ
阮一峰的网络日志
阮一峰的网络日志
NISL@THU
NISL@THU
爱范儿
爱范儿
S
Securelist
博客园 - 叶小钗
C
CERT Recently Published Vulnerability Notes
Recorded Future
Recorded Future
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
aimingoo的专栏
aimingoo的专栏
D
DataBreaches.Net
G
GRAHAM CLULEY
P
Proofpoint News Feed
A
About on SuperTechFans
Google DeepMind News
Google DeepMind News
C
Cyber Attacks, Cyber Crime and Cyber Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Tor Project blog
Stack Overflow Blog
Stack Overflow Blog
T
Threat Research - Cisco Blogs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Recent Announcements
Recent Announcements
P
Proofpoint News Feed
The GitHub Blog
The GitHub Blog
The Cloudflare Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI
Y
Y Combinator Blog
Jina AI
Jina AI
大猫的无限游戏
大猫的无限游戏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
罗磊的独立博客
博客园 - 【当耐特】
H
Help Net Security
F
Fortinet All Blogs
T
The Blog of Author Tim Ferriss

Lohrmann on Cybersecurity

AI at Work: Employees Aren’t Waiting for Permission AI, Mind Reading and Microchip Brain Implants The Global State of Technology Risk in 2026 The Mythos Race: Trump’s New EO and Glasswing’s Expansion No Longer Invisible: When Cyber Attacks Go Physical How New College Grads Can Succeed in an AI Economy Protecting People and Infrastructure: A 2026 World Cup Security Preview ‘CI Fortify’ Is the New Road Map for State and Local Resilience The Great Stay: Why Tech Talent Is Choosing Stability Over Salary A History of Global Hacking — and Where It’s Going Next Why Anthropic’s Mythos Is a Systemic Shift for Global Cybersecurity Post-Quantum Cryptography: Moving From Awareness to Execution RSAC 2026 Highlights: From Agentic AI to Active Defense What Is Physical AI, and What Does It Mean for Government? New Federal Strategies, Rising Risk From Iran Top Cyber Themes Securing Critical Infrastructure in a Time of War From Michigan to Silicon Valley: A Conversation With Mohamad Yassine Defending Your Castle: Best Practices for Smart Home Security Your Smart Home Is Watching You: Privacy in the Age of AI Robots How Global Power Struggles Are Rewriting Cyber Defense After TikTok: Navigating the Complex Web of Foreign Tech Bans
A Tale of Two States: The 2026 Cybersecurity Paradox
https://www.govtech.com/authors/dan-lohrmann.html · 2026-05-03 · via Lohrmann on Cybersecurity

The cyber threat outlooks from CIOs and CISOs at the NASCIO Midyear Conference in Philadelphia ranged from the good to the bad to the ugly — with AI front and center.

Four people seated on a stage at an event.
From left to right, NASCIO Deputy Executive Director Meredith Ward; Kansas CISO John Godfrey; Massachusetts CISO and Chief Risk Officer Anthony O'Neill; and Mike Wyatt, partner/principal at Deloitte.

Government Technology/David Kidd

“It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness.”

This famous quote, from the opening of A Tale of Two Cities by Charles Dickens and written in 1859, could well describe the state of government technology and cybersecurity in mid-2026. As I attended sessions and networked with state CIOs and CISOs over the past week, I saw that there is a wide gap in the level of hope between different state leaders.

From the opening Corporate Member Exchange Meeting to the State Meet and Greets session to coverage of the NASCIO-Deloitte Cybersecurity Study, everyone was talking about how state CISOs (and CIOs) are losing confidence in their ability to stop and recover from cyber attacks against their governments.


Here are some of my notes from meetings and conversations with CIOs and CISOs:

  • Their governor’s support is high. But how do we measure cyber success? Lowered incident response from six days to 10 minutes. Fear of “double-bubble” — how can we eliminate the old tools? We don’t want to pay for tools twice.
  • Some states, like Texas, have a well-funded new Cyber Command organization.
  • Other states are seeing major budget cuts across the board. Not backfilling when people leave. Tightening belts. Must show cost savings. Hard savings needed.
  • Leaders are hoping SLCGP Cyber Grants are renewed. Also discussions on next steps for the MS-ISAC, which I will cover in a late June blog.
  • One state dealt with three ransomware attacks with locals in the past few months.
  • All states are working on AI projects. Most are using an outcome-focused approach, looking for real downstream impact and asking how their AI projects work with improving or replacing existing systems. AI governance is top of mind for CIOs and CISOs.
  • A lot of discussions about the recent developments with Anthropic’s Project Glasswing and Claude Mythos, along with other new AI developments and the impact on government cybersecurity.

NASCIO-DELOITTE CYBERSECURITY STUDY

The full 2026 NASCIO-Deloitte Cybersecurity Study can be downloaded here for free, and this year’s study includes insights from the CISOs of all 50 states, the District of Columbia and the U.S. Virgin Islands.

Here are the five major themes outlined by Meredith Ward of NASCIO and Mike Wyatt from Deloitte:

  • “Facing an evolving threat landscape: Rapid advances in attack sophistication are challenging state CISOs, with AI viewed as both an emerging threat vector and a powerful tool for cyber defense.
  • Getting future-ready: CISOs are adopting new tools and regulatory frameworks to meet the evolving technology landscape.
  • Looking at whole-of-state cybersecurity: The survey points to a growing interest in centralized state support for the cybersecurity efforts of local governments, public education and critical infrastructure.
  • The expanding CISO role: The proliferation of AI and generative AI (GenAI), as well as a growing appreciation of the need to safeguard public data, is bringing new responsibilities to the CISO role.
  • Dealing with a resource crunch: Compared with recent survey cycles, CISOs tell us that their funding shortfalls are growing more dire, while continuing to face challenges around maintaining a cyber workforce with the needed skills.”

In my view, this is another great report that is a must-read for anyone who is serious about improving cyber defenses in state and local governments nationwide.

The “bad and ugly” parts, unfortunately, come in the next section of the joint biennial report, highlighting the “key takeaways”:

  • “As threats become more sophisticated, far fewer CISOs expressed confidence in their ability to secure public data. The percentage of CISOs who characterized themselves as ‘extremely’ or ‘very confident’ has dropped dramatically, from 48 percent in 2022 to 22 percent in 2026 (figure 1).
  • CISOs are significantly less confident in the ability of local government and public higher education to secure public data. The percentage of CISOs who described themselves as ‘not very confident’ in these entities rose significantly, from 35 percent in 2022 to 63 percent in 2026 (figure 2). This lack of confidence may explain why roughly one-fifth of CISOs indicated that their states were moving forward with a whole-of-state approach to cybersecurity.
  • Generative AI also represents an area of increased responsibility, with 94 percent of CISOs indicating that they are actively involved with the development of GenAI security policies (figure 8).
  • CISOs overall reported a rapidly deteriorating budget picture. In the 2026 survey, only 22 percent of CISOs reported a budget increase of 6 percent or more, down from 40 percent in 2024. Perhaps more concerning, 16 percent of CISOs reported reductions to their budgets in this survey, compared with none in 2024 (figure 21).
  • Looking into the future, CISOs indicated their top three barriers to meeting cybersecurity challenges were: legacy infrastructure, increasing sophistication of threats and insufficient funding for cybersecurity (figure 7).”

OTHER HOT NASCIO MIDYEAR TOPICS

There were many other topics of discussion (cyber and otherwise) at the NASCIO Midyear Conference, and here are some of the GovTech articles that flowed from the event:


FINAL THOUGHTS

I realize that this piece is pretty depressing to read and comes across as a negative outlook for Government Technology readers and wider cyber initiatives in states.

Nevertheless, the networking camaraderie, relationships and coming together for a common set of government causes was also very evident throughout the conference.

There are now a record number of corporate members within NASCIO at over 280 companies (and some say too many members, which is a problem to be considered). But these numbers also show the interest and focus on governments solutions and reshaping the people, processes and technology for the public sector — again.

I’ll end this blog with a more optimistic quote commonly attributed to C.S. Lewis: “You can’t go back and change the beginning, but you can start where you are and change the ending.”

Daniel J. Lohrmann is an internationally recognized cybersecurity leader, technologist, keynote speaker and author.

Dan Lohrman

Dan Lohrmann

Creating robust government solutions demands fresh perspectives, inventive approaches and diligent effort. From fortifying cybersecurity defenses and leveraging AI to optimizing cloud infrastructure and securing mobile platforms, Dan offers practical ways to "get to yes" securely.