Governors’ Cyber Advisers Meet CISA as Infrastructure Risks Grow
Cybersecurity advisers from more than 40 states and territories met with CISA Acting Director Nick Andersen and private-sector experts this week as governors’ offices examined how to protect essential services from ransomware, artificial-intelligence risks and other cyber threats.
The National Governors Association announced the two-day Governors’ Cybersecurity Advisors Annual Institute on August 26, 2026, describing it as a gathering held during the week of August 24. The institute was a policy discussion and coordination forum—not a new federal mandate, funding award or binding agreement.
The meeting highlighted a widening state-federal challenge. Governors and state agencies are expected to coordinate cyber defense across state departments, local governments, utilities and private infrastructure owners, while many smaller jurisdictions lack the staff and money to maintain strong defenses on their own.
Threats reach systems residents depend on
Participants discussed ransomware aimed at “target-rich, resource-poor” institutions and the risk of nation-state actors pre-positioning themselves inside critical infrastructure before attempting disruptive operations. The agenda also included artificial-intelligence risks, cross-sector coordination, support from state National Guards and civilian cyber corps, and the need to expand the cybersecurity workforce.
For residents, the concern is practical. A serious cyber incident can disrupt government communications, delay public services, interfere with hospital operations or affect systems that manage water, electricity, transportation and emergency response. Schools and local public-safety networks also depend on connected systems that require continuous maintenance and monitoring.
States often serve as the coordinating layer between federal agencies and local organizations. They can share threat information, organize incident-response plans, help smaller governments obtain technical assistance and connect public agencies with utilities and other private-sector operators.
Federal tools are available, but funding is unsettled
The Cybersecurity and Infrastructure Security Agency currently offers no-cost Cyber Hygiene Services to eligible U.S. federal, state, local, tribal and territorial governments, as well as public- and private-sector critical-infrastructure organizations. The services include vulnerability scanning and web-application scanning to help identify exposed systems and misconfigurations.
CISA also lists the State and Local Cybersecurity Grant Program as a federal mechanism for helping state, local and territorial governments address information-system risks. Its financial-assistance programs also describe cooperative support for the Multi-State Information Sharing and Analysis Center, or MS-ISAC, which helps government entities exchange threat intelligence and technical guidance.
Those existing tools are not the same as guaranteed long-term funding. Route Fifty reported in June that Sen. Mark Warner had introduced legislation that would direct CISA to support MS-ISAC and authorize $50 million annually beginning in fiscal year 2027. That amount is part of proposed legislation and has not been enacted.
Local governments show the resource gap
South Dakota offers one example of the pressure facing states that try to extend cybersecurity help to local governments. Recent reporting by Route Fifty and South Dakota Searchlight said the state’s $7 million SecureSD program provides local governments with tools, training and technical support, but the funding is scheduled to expire on June 30, 2028.
The reporting also described cyber incidents affecting South Dakota local governments in 2026 and the difficulty of sustaining services for jurisdictions with limited budgets and few specialized employees. The incidents illustrate the resource problem facing smaller communities, but they were not identified as the reason for the NGA institute.
What to watch next
The next policy questions are whether Congress preserves or expands federal grant and information-sharing support, how states finance local assistance and whether workforce programs can produce enough trained personnel for public agencies and critical-infrastructure operators.
Governors’ offices are likely to keep emphasizing incident coordination, critical-infrastructure mapping, secure government communications, National Guard and civilian cyber support, and training pipelines. The central test will be whether those efforts provide sustained protection for smaller communities, rather than short-term assistance after an attack has already begun.
Sources
- National Governors Association institute announcement
- CISA Cyber Hygiene Services
- Route Fifty / South Dakota Searchlight reporting
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.