According to a new report published by the National Association of State Chief Information Officers (NASCIO) and General Dynamics Information Technology (GDIT), state governments are taking on more responsibility for protecting critical infrastructure from cyberattacks. While approaches to cybersecurity vary, the report highlights common difficulties, including lack of authority, clarity and funding.
The report pulls from two recent NASCIO surveys along with a round of interviews with state chief information officers (CIOs), blending hard data with firsthand insight into how states are approaching the problem.
According to the surveys, nearly all respondents said cyberattacks on critical systems were of high or moderate concern. These include infrastructure systems such as electrical grids, oil pipelines, data centers and hospitals.
The report also notes a core tension in the process, which is lack of clear authority from the state level. Most states cannot force local governments or districts to follow specific cybersecurity practices. As a result, survey respondents described an approach relying on mutual trust between the state and municipalities, with tools like partnerships and programs driving the change.
Given examples include states like New Jersey, which has built a coordinated model that ties local and state governments together on critical infrastructure protection. This means the state offers direct guidance, resources and support to help local governments strengthen their own defenses. Utah also runs a shared-services program, funded largely through the State and Local Cybersecurity Grant Program (SLCGP), that provides participating local governments with services like endpoint protection, patching and incident response support.
That program covers about 80 percent of the state’s local entities, with the state also adding a separate water-sector security effort backed by a $1.5 million grant.
Other states are approaching the problem differently. Kansas recently passed a law expanding which entities, including critical infrastructure providers, can access state cybersecurity and technology services. Minnesota has relied on an executive order and newer emergency directives to pull nonexecutive branch entities into statewide incident response. Outside of state government, a rural water trade group also launched a new support center over the summer to help small utilities detect and respond to attacks.
The report also notes that funding for infrastructure cybersecurity does not always fall under the state CIO’s office. In some states, that work falls to emergency management, environmental agencies or homeland security offices, complicating the process of obtaining stable funding.
Funding levels also vary by which part of state government is covered. About two-thirds of state CIO budgets cover cybersecurity work for executive branch agencies. Far fewer reach beyond that, with about a third funding other state agencies and about the same share supporting local governments and special districts. More than a fifth of states report no dedicated funding for this work at all.
The report also cites state officials expressing concern over the future of federal support services, such as the Cybersecurity and Infrastructure Security Agency (CISA), Multi-State Information Sharing and Analysis Center (MS-ISAC) and the SLCGP. This follows recent July cybersecurity attacks on municipal water systems in at least a dozen states, which prompted a Federal Bureau of Investigation (FBI) advisory.
Taken together, the report frames this as a mismatch, with states increasingly expected to lead on what amounts to a national security problem, but without the consistent authority or guaranteed funding needed to fully carry it out.
To help close that gap, the report recommends states identify and prioritize their highest-risk systems, formalize governance and incident-response roles and continue building trust with local governments even where participation is not mandatory.
The report also points to a shift in thinking among state officials, many of whom are now treating stable, state-level funding as a necessity rather than a fallback plan.
Photo by Antoni Shkraba from Pexels
For more of the latest from the expansive government marketplace, check Government Market News daily for new stories, insights and profiles from public sector professionals. Check out our national contracting newsletter here.




