A new biennial survey from the National Association of State CIOs (NASCIO) and Deloitte reveals a stark decline in confidence among U.S. state and territorial chief information security officers (CISOs). The 2026 study found that only 26% of state CISOs are highly confident in their ability to protect state government data, a dramatic drop from 48% in 2022. This erosion of confidence is attributed to a 'perfect storm' of rapidly advancing threats, particularly those powered by Artificial Intelligence (AI), coupled with stagnant or decreasing cybersecurity budgets. As a result, CISOs are pivoting their strategic priorities towards metrics and demonstrating program effectiveness to secure necessary resources.
The survey polled top cybersecurity officials from all 50 states, Washington D.C., and two territories, providing a comprehensive view of the challenges facing public sector security leaders. The findings highlight a growing gap between the capabilities of threat actors and the resources available to state defenders.
Key Findings:
The study's findings are relevant to all U.S. state and territorial governments. Furthermore, the lack of confidence extends to the broader public sector ecosystem. 63% of state CISOs reported being 'not very confident' in the security of local government and public higher education data, up from 35% in 2022. This indicates a systemic risk across the public sector, not just at the state agency level.
While the report doesn't detail specific compliance mandates, it underscores the pressure CISOs face to meet various federal and state regulations with limited resources. The shift towards a 'whole-of-state' cybersecurity approach, mentioned by 20% of states, suggests a move towards more centralized compliance and security service delivery to local governments and schools, aiming to raise the baseline security level for all public entities.
The declining confidence and budget constraints have significant real-world implications. Underfunded and under-resourced state cybersecurity programs are less able to defend against sophisticated nation-state actors and organized cybercrime groups. This increases the risk of:
The focus on metrics is a double-edged sword. While it can help secure funding, it also puts immense pressure on CISOs to demonstrate ROI, which can be challenging in cybersecurity where success is often the absence of incidents.
Based on the report's findings, state and local government IT leaders should consider the following actions:
State officials urge Congress to renew the expiring $1 billion State and Local Cybersecurity Grant Program (SLCGP) to combat rising AI threats and resource gaps.
Cybersecurity leaders from Florida, New York, and Tennessee are urgently calling on Congress to reauthorize the State and Local Cybersecurity Grant Program (SLCGP), a critical $1 billion federal initiative. This program provides essential funding for state, local, tribal, and territorial (SLTT) governments to bolster defenses against sophisticated cyber threats, including AI-powered attacks. Officials warn that without renewal, SLTT entities will be dangerously exposed, exacerbating the resource disparity between well-funded attackers and under-resourced local jurisdictions. The proposed 'Protecting Information by Local Leaders for Agency Resilience Act' aims to reauthorize the program, which is vital for national security and preventing disruption of public services.
Previous NASCIO-Deloitte survey found 48% of state CISOs were highly confident.
The 2026 NASCIO-Deloitte survey is released, showing CISO confidence has dropped to 26%.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.