The Consequences of Inaction
The consequences of inaction, or even delayed action, can feel abstract, but they are very real. The loss or exposure of sensitive public data following a breach can be permanent. Once compromised, there is often no meaningful way to make it private again, and the damage to individuals and public trust can be lasting.
Additionally, a successful cyberattack on government or critical infrastructure could severely disrupt the services people depend on every day. Across the nation, government services, power grids and water services — as we have seen recently — rely on cybersecurity. The rapid adoption of powerful tools such as GenAI makes the need for attention all the more urgent. Without adequate guardrails, the risk enables serious harm.
READ MORE: GenAI holds the potential to transform citizen services.
What to Prioritize
The warning signs are clear, and state and local leaders can act now to strengthen their cyber resilience.
First, leadership at every level must treat cybersecurity as a governance priority, not an IT problem. In many states, governors and mayors convene annual cabinet-level exercises and statewide and citywide meetings that bring together multijurisdiction officials and critical infrastructure operators to build shared awareness and relationships for digital security. I have seen these efforts rewarded with success.
Beyond this, a sustained commitment to a modern statewide approach to cybersecurity with defined risks, measurable results against known standards and consistent funding is critical. Implemented well, a strong cybersecurity plan creates communities where economic development thrives.
Finally, the Department of Homeland Security’s State and Local Cybersecurity Grant Program remains a key effort to enable action. Congressional and administration leaders are actively working to reauthorize and fund the SLCGP, which is slated to end in September. Losing the momentum of this program would be a major setback for progress.
How Industry Can Help
Industry has an indispensable role to play. The most critical action industry can take right now is demonstrating clear value, including how solutions can reduce duplication, simplify operations and lower the long-term cost of managing a secure environment.
Industry partners must also work well with one another. Government agencies are already challenged by fragmented tools and environments that create complexity. They need integrated, interoperable approaches tailored to the actual operating environment of the agency being served.
Finally, industry must do more to explain the risk environment in plain terms that resonate with elected officials, budget writers and the public. Communicating risk is only half the responsibility. The other half is articulating the path to resilience in language that is accessible, actionable and credible.
LEARN MORE: Cyber resilience helps agencies harness AI infrastructure.
It Takes All of Us
Having a front row seat to the hard work public servants do on behalf of citizens has been a standout joy of my career. When a citizen discovers a new facet about how their government works, they are often surprised by the weight of responsibility public servants carry. More often than not, that enormous responsibility is shouldered with insufficient recognition and, in the worst cases, an outright lack of appreciation.
Government and critical infrastructure CIOs and CISOs are regularly unsung. They are charged with guiding and deploying an organization’s technology strategy and protecting data and IT infrastructure from growing cyberthreats. In short, they are a significant part of keeping services we rely on every day operating smoothly — and they are expected to deliver these efforts with a limited workforce and tight government budgets.
Ensuring CIOs and CISOs have sustained support and resources will make communities more resilient and help protect the public services and infrastructure on which all of us depend.
