Can States Protect Critical Infrastructure From Cyberattacks?

Can States Protect Critical Infrastructure From Cyberattacks?

State officials are expressing deep concern regarding the security of electric and gas utilities, telecommunications, transportation networks, and healthcare facilities. This anxiety is not merely theoretical; it is grounded in the reality of increasingly frequent and sophisticated intrusions that target the foundation of daily life. The traditional model of isolated defense is crumbling under the weight of coordinated attacks from state-sponsored actors and professional criminal syndicates. As digital infrastructure becomes more interconnected, the attack surface expands, leaving local governments and utility providers in a precarious position. The urgency of this situation has forced a reevaluation of how federal and state resources are distributed, as the current trajectory suggests that the frequency of these incidents will only increase from 2026 to 2028. State leaders now recognize that protecting a water treatment plant in a rural district is just as critical to national security as defending a federal data center.

Shifting Threats: The New Defense Burden

Targeted Attacks: Vulnerabilities in Public Utilities

Recent data indicates a surge in coordinated attacks by Iran-nexus actors targeting water and wastewater utilities across at least 12 states. These attackers specifically exploit exposed industrial devices known as programmable logic controllers, which are essential for monitoring and managing flow rates within treatment facilities. By gaining access to these systems, malicious actors have forced service suspensions and locked local operators out of vital equipment, highlighting a terrifying lack of basic security hygiene in municipal systems. These incidents serve as a wake-up call for administrators who previously believed their geographic isolation provided a layer of protection.

Beyond water systems, the healthcare sector remains a primary target due to the sensitive nature of patient data and the critical need for constant uptime. Errol Weiss of the Health-ISAC noted that the burden of defense has shifted heavily toward individual states as federal direct resource allocations have failed to keep pace with modern threats. This shift leaves regional facilities vulnerable, as they often lack the dedicated cybersecurity staff needed to repel advanced persistent threats and sophisticated ransomware groups that threaten patient safety and data integrity on a daily basis.

Resource Gaps: Funding and Staffing Shortfalls

A joint report by NASCIO and GDIT reveals a significant gap between rising threat volumes and current funding levels. State budget cycles often lag behind the rapid evolution of cyber threats, resulting in a reactive rather than proactive security posture across various jurisdictions. This financial shortfall prevents states from upgrading legacy systems that were never designed to be internet-facing, yet are now integral to the state’s digital footprint and public safety. Without sustainable investment, the technological debt continues to grow, making critical systems easier targets for exploitation by professional hackers and foreign adversaries.

Compounding the financial issue is a severe shortage of qualified cybersecurity professionals willing to work in the public sector. While federal agencies are working to fill national vacancies, state-level entities struggle to compete with private sector salaries and benefits. To address this, some states have initiated pilot programs to create a cyber-reserves force, but these efforts are currently regionalized and lack the long-term investment required to provide a robust defense for smaller districts that cannot afford their own dedicated security operations centers or high-level incident response teams.

Strategic Frameworks: Building Unified Defense

Collaborative Models: The Whole-of-State Approach

To combat these systemic weaknesses, a consensus is emerging around the whole-of-state strategy. This model involves state governments centralizing their security resources and then sharing those services, training, and threat intelligence with local municipalities and special districts that lack their own defenses. New York has already implemented a $9 million grant program aimed specifically at helping local water utilities bolster their defenses, serving as a template for how centralized funding can have a decentralized impact on security. This approach ensures that the most vulnerable links in the chain receive the attention they require to maintain public stability.

States like New Jersey, Utah, and Oregon are also developing cross-jurisdictional frameworks that bridge the gap between state-level expertise and local implementation. The underlying philosophy is that because digital attackers do not respect geographical or administrative boundaries, a fragmented defense is no longer a viable option in 2026. By treating the entire state as a single interconnected entity, officials can provide high-level monitoring and response capabilities to even the smallest rural utility providers, effectively raising the security baseline for the entire region and reducing the overall risk of localized failures.

Future Resilience: Establishing New Security Standards

Moving forward, experts recommended five primary actions to bridge the current security gaps, starting with exhaustive inventories of high-risk systems impacting public health. It is impossible to protect what cannot be seen, and many states still lack a comprehensive map of their industrial control systems and legacy networks. Additionally, adopting a whole-of-government risk management strategy ensured that every department followed uniform security standards, reducing the likelihood of a weak link being exploited in a lateral attack. These systematic improvements were designed to create a culture of vigilance that extended beyond IT departments.

Legislative bodies mandated basic cyber hygiene standards and incident reporting requirements to improve overall situational awareness. This collective transparency allowed for faster response times and better coordination during large-scale outages or ransomware events. By expanding support services to reach the smallest local entities, states created a more resilient and unified front against digital adversaries. These actions established a sustainable model that prioritized the collective stability of critical infrastructure, ensuring that public services remained functional and secure despite persistent digital hostility.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later