VYPR
advisoryPublished Sep 17, 2026· 1 source

States Expand Cybersecurity Support to Local Critical Infrastructure

US states are increasingly providing cybersecurity assistance to local utilities and critical infrastructure operators beyond their direct control, facing challenges with funding and expertise.

States are stepping up to provide crucial cybersecurity support to local utilities, water systems, hospitals, and other essential municipal services that they do not directly control. This expansion of state-level cyber assistance acknowledges a growing threat landscape that impacts communities regardless of jurisdictional boundaries. However, the initiative is encountering significant hurdles, primarily related to funding and the practicalities of delivering effective support to entities with limited resources and technical capacity.

A recent report from the National Association of State CIOs (NASCIO) highlights the urgency of the situation. A staggering 88% of state CIOs identify cyberattacks against critical infrastructure as a high concern. While 73% of states have integrated critical infrastructure protection into their statewide cybersecurity plans, a stark reality emerges when examining budgets: only 31% of state CIO budgets include dedicated funding for supporting local governments and special districts. Even more concerning, 22% of states have no specific funding allocated for critical infrastructure protection at all.

The varying degrees of authority states hold over local governments and special districts further complicate matters. In many cases, state programs rely on voluntary cooperation, as local entities remain responsible for their own infrastructure unless state law mandates otherwise. This fragmented approach to cybersecurity is ill-suited to the persistent and borderless nature of cyber threats, as attackers do not respect jurisdictional lines.

Despite these challenges, several states are making tangible efforts to assist local operational technology (OT) organizations. Utah, for instance, provides endpoint protection, patching, security awareness training, and incident response support to nearly 80% of its local government entities. Oregon is leveraging federal grants to conduct assessments of water districts through a collaborative effort involving state, federal, National Guard, and higher education partners. More than half of state CIOs report offering services such as assessments, vulnerability management, monitoring, and incident response to local entities.

However, the effectiveness of these services is often hampered by the significant personnel and resource constraints faced by local operators. Dawn Cappelli, director of OT-CERT at Dragos, notes that small utility operators often wear multiple hats, managing IT, OT, plant operations, and even groundskeeping. This lack of dedicated IT or cybersecurity staff means they may lack the expertise to implement or manage the security solutions provided, even if the technology itself is donated.

Furthermore, the technological infrastructure at the local level can be a bottleneck. Some utilities lack the basic hardware required to run donated security software, with costs for necessary equipment running into thousands of dollars. Even when monitoring technology is deployed, there may be no personnel available to analyze the alerts generated, rendering the investment ineffective. Inadequate log retention further hinders incident response and forensic investigations, as seen in a past attack on the Littleton Electric Light and Water Department.

Experts like Josh Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, caution against measuring state assistance solely by the number of security products deployed. He emphasizes that many cybersecurity tools are designed for information confidentiality, not the availability of life-saving services, which is paramount for critical infrastructure. The long-term cost and operational burden of maintaining these solutions often fall back on the under-resourced local entities, potentially turning the security control into a liability.

Ultimately, state assistance must be judged by its ability to help small, resource-constrained utility operators maintain essential services. The focus should be on practical solutions that alleviate the management burden rather than adding to it, ensuring that these vital community services can withstand the growing tide of cyber threats.

Synthesized by Vypr AI
States Expand Cybersecurity Support to Local Critical Infrastructure · VYPR