“We’re able to grow and put more modules in place that allow us to take advantage of the telemetry and data in our network so we can gain a better understanding of the threat environment as it affects us,” he says.
Today’s state cybersecurity budgets need to cover rising talent and technology costs — yet 55% received the same funding amount this year as in 2025 or saw an increase of less than 6%, according to a survey by the National Association of State Chief Information Officers and Deloitte. Eight states’ cybersecurity budgets were reduced.
More than half of CISOs (59%) identified insufficient funding as a barrier to effective security, propelling the issue to become one of 2026’s top three cybersecurity challenges.
States’ other main cybersecurity concerns include a reliance on legacy infrastructure and solutions, and escalating threat sophistication.
Legacy hardware and software can be prone to attacks, while more modern tech tools may be able to mitigate threats; workforce deficits may be another obstacle, says David Kertai, research assistant at the Information Technology and Innovation Foundation and author of an April ITIF report on improving state and local government cybersecurity.
Bad actors are using artificial intelligence to discover new vulnerabilities in government systems, but state agencies can also take advantage of the emerging technology, Kertai says.
“These models could be used to help find those vulnerabilities before the attackers do and make changes,” he says.
