Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Sep 03 2026
Security

Government CISOs Sound the Alarm on Growing Security Challenges

State and local cyber leaders need sustained funding, stronger governance and industry partnerships to build resilience.

In April 2026, NASCIO and Deloitte published their biennial cybersecurity survey. The study stuck with me — and not in a good way. Only 22% of CISOs are extremely or very confident in their ability to secure public data, down significantly from 48% just four years ago. At the same time, 94% of CISOs are actively involved in developing generative artificial intelligence (GenAI) security policies. This is “more duties as assigned” at a moment when confidence to perform the core function of the job is in decline.

CIOs, to whom CISOs often report, are under similar pressure. CIOs are asked to deliver IT services at lower costs while matching the speed and innovation of Fortune 500 companies. Meanwhile, legacy infrastructure, the increasing sophistication of threats and insufficient funding are cited as the three greatest barriers to addressing cyber challenges. 

These pressures do not exist independently. Aging infrastructure can be harder and more expensive to secure. Limited budgets delay modernization and make it harder to recruit and retain cybersecurity professionals, while fragmented systems reduce visibility and complicate incident response. Government has long been good at rallying after a crisis.

In cybersecurity, however, waiting for an incident before acting can carry severe consequences.

Addressing these pressures requires more than reacting to the next breach. State and local leaders need to treat cybersecurity as an ongoing governance and resilience priority, backed by sustainable funding, modern technology and strong partnerships with industry. The stakes are too high for anything less.

Click the banner below to weigh today’s most pressing security challenges.

 

The Consequences of Inaction

The consequences of inaction, or even delayed action, can feel abstract, but they are very real. The loss or exposure of sensitive public data following a breach can be permanent. Once compromised, there is often no meaningful way to make it private again, and the damage to individuals and public trust can be lasting. 

Additionally, a successful cyberattack on government or critical infrastructure could severely disrupt the services people depend on every day. Across the nation, government services, power grids and water services — as we have seen recently — rely on cybersecurity. The rapid adoption of powerful tools such as GenAI makes the need for attention all the more urgent. Without adequate guardrails, the risk enables serious harm.

READ MORE: GenAI holds the potential to transform citizen services.

What to Prioritize

The warning signs are clear, and state and local leaders can act now to strengthen their cyber resilience.

First, leadership at every level must treat cybersecurity as a governance priority, not an IT problem. In many states, governors and mayors convene annual cabinet-level exercises and statewide and citywide meetings that bring together multijurisdiction officials and critical infrastructure operators to build shared awareness and relationships for digital security. I have seen these efforts rewarded with success.

Beyond this, a sustained commitment to a modern statewide approach to cybersecurity with defined risks, measurable results against known standards and consistent funding is critical. Implemented well, a strong cybersecurity plan creates communities where economic development thrives.

Finally, the Department of Homeland Security’s State and Local Cybersecurity Grant Program remains a key effort to enable action. Congressional and administration leaders are actively working to reauthorize and fund the SLCGP, which is slated to end in September. Losing the momentum of this program would be a major setback for progress.

How Industry Can Help

Industry has an indispensable role to play. The most critical action industry can take right now is demonstrating clear value, including how solutions can reduce duplication, simplify operations and lower the long-term cost of managing a secure environment. 

Industry partners must also work well with one another. Government agencies are already challenged by fragmented tools and environments that create complexity. They need integrated, interoperable approaches tailored to the actual operating environment of the agency being served. 

Finally, industry must do more to explain the risk environment in plain terms that resonate with elected officials, budget writers and the public. Communicating risk is only half the responsibility. The other half is articulating the path to resilience in language that is accessible, actionable and credible.

LEARN MORE: Cyber resilience helps agencies harness AI infrastructure.

It Takes All of Us

Having a front row seat to the hard work public servants do on behalf of citizens has been a standout joy of my career. When a citizen discovers a new facet about how their government works, they are often surprised by the weight of responsibility public servants carry. More often than not, that enormous responsibility is shouldered with insufficient recognition and, in the worst cases, an outright lack of appreciation.

Government and critical infrastructure CIOs and CISOs are regularly unsung. They are charged with guiding and deploying an organization’s technology strategy and protecting data and IT infrastructure from growing cyberthreats. In short, they are a significant part of keeping services we rely on every day operating smoothly — and they are expected to deliver these efforts with a limited workforce and tight government budgets.

Ensuring CIOs and CISOs have sustained support and resources will make communities more resilient and help protect the public services and infrastructure on which all of us depend.

Nitat Termmee/Getty Images