Title: State CISOs Confront Resource and Expertise Deficits Amid Expanding Cyber Threats
In the face of an expanding 'attack surface' stemming from increased digital reliance, state chief information and security officers (CISOs) across the United States are grappling with significant challenges. A new survey by Deloitte & Touche LLP has revealed that many of these key figures overseeing cyber defences lack the necessary budget, resources, staff, and expertise to adequately protect government networks from cyber threats.
The biennial cybersecurity report, which surveyed officials from all fifty states and Washington, D.C., underscored the increasing complexity and importance of CISOs' roles. Srini Subramanian, principal at Deloitte & Touche LLP, commented on the situation, stating, "The attack surface is expanding as state leaders’ reliance on information becomes increasingly central to the operation of government itself." Despite the vital role CISOs play, many report a lack of sufficient tools and talent to effectively combat evolving cyber threats.
State governments' reliance on digital infrastructure is rising, incorporating servers for information storage, Internet of Things (IoT) devices, and connected sensor technologies. These advancements, while enhancing efficiency, also introduce numerous vulnerabilities that cybercriminals seek to exploit. Infrastructure systems, including transit and power networks, heavily depend on technology, thereby creating increased opportunities for cyberattacks.
A significant concern highlighted in the report is the emergence of artificial intelligence (AI) as a tool both for safeguarding and compromising cybersecurity. While AI facilitates advanced phishing schemes and sophisticated audio-visual deepfakes, it also presents an opportunity for security teams to bolster their defensive strategies. Around 71% of surveyed CISOs consider AI a ‘high’ threat, with 41% expressing uncertainty in their team’s ability to manage such risks.
Nevertheless, states are recognising the potential benefits of AI, with 21 already integrating some form of AI into their security operations and 22 more planning to do so within the next year. The implementation of AI in cybersecurity varies, with some states opting for a case-by-case legislative approach. One respondent mentioned that their state is in the "discovery phase", following an executive order to study generative AI's impact on security. Another respondent indicated the establishment of a committee to assess relevant use cases and establish effective policies.
While the role of CISOs has been prioritised across state governments, with some states granting these leaders greater authority through new statutes, the fundamental challenges of funding and talent acquisition persist. Nearly 40% of CISOs reported insufficient funds for key projects, including those aimed at meeting regulatory or legal standards. Additionally, about half reported staffing shortages, with 31% citing a lack of cybersecurity professionals.
Staff retention among CISOs is also problematic, exacerbated by burnout—a trend that has intensified since the COVID-19 pandemic. The report notes that nearly half of all states have experienced turnover in chief security officers since 2022, with the median tenure now reduced to 23 months, down from 30 months recorded in previous surveys.
Despite these barriers, the report outlines several strategies to help CISOs navigate their pressing challenges. Recommendations include collaborating with government partners, innovative budgeting solutions, diversifying talent pipelines, advancing AI policy discussions, and reinforcing the role of CISOs in the digital transformation of government operations.
The survey underscores the delicate balancing act that state CISOs must perform: managing constrained resources while addressing both longstanding and emerging cyber threats in an ever-evolving digital landscape.
Source: Noah Wire Services