TL;DR: The 2026 NASCIO-Deloitte Cybersecurity Study surveyed CISOs from all 50 states and two territories. The headline number: only 22% of state CISOs say they're "extremely" or "very" confident they can protect their state's data. That's down from 48% in 2022. For local government and higher education? 63% of CISOs say they're "not very confident" those institutions can defend themselves, up from 35%. Budget cuts hit 16% of states for the first time in the survey's history. And only 2% feel "very confident" they can stop AI-enabled attacks. These aren't outside critics. These are the people running state cybersecurity programs, saying on the record that they're losing.
The Confidence Collapse, by the Numbers
Every two years, NASCIO and Deloitte survey every state CISO in the country. The 2026 edition, published in late April, reads like a distress signal [1].
In 2022, nearly half of state CISOs (48%) said they were "extremely" or "very" confident their state's information assets were protected from cyber threats. By 2026, that number fell to 22%. Not a dip. A collapse.
The numbers get worse when you look at the sectors CISOs are supposed to protect beyond their own state agencies. Asked about local governments and public universities, 63% of CISOs said they were "not very confident" in those institutions' cybersecurity posture. In 2022, that figure was 35% [2][3].
Read that again. Nearly two-thirds of the people responsible for state cybersecurity are telling us that local governments and universities can't defend themselves. These aren't hypothetical concerns. These are the institutions getting hit right now.
The Canvas Breach Proves Them Right
While CISOs were filling out this survey, ShinyHunters was exfiltrating 3.65 terabytes of data from Instructure's Canvas learning management system, affecting 275 million students across 9,000 institutions. The ransom deadline is Monday, May 12.
The institutions breached are exactly the ones CISOs flagged as indefensible: public universities, community colleges, K-12 school districts. The survey results and the breach timeline overlap perfectly. CISOs said they couldn't protect higher education. ShinyHunters proved it.
This isn't coincidence. It's causation. Underfunded institutions with legacy infrastructure, shared vendor dependencies, and no dedicated security teams are the softest targets in government IT. CISOs know it. Attackers know it. The survey just puts numbers on what both sides already understood.
The Budget Numbers Tell the Rest of the Story
For the first time in the survey's history, 16% of state CISOs reported budget cuts. In 2024, that number was zero [1][3].
Only 22% reported budget increases of 6% or more, down from 40% in 2024. Just 10% saw increases above 10%. And 40% of CISOs said the State and Local Cybersecurity Grant Program funding was "inadequate" [3].
NASCIO's Director of Government Affairs Alex Whitaker requested a $300 million appropriation for the grant program in FY 2027 and called it "a starting point", not a solution [4].
Massachusetts CISO Anthony O'Neill pointed directly at the source: "One of the things that we've seen over the past year is the general pressure coming from Washington on finances" [2].
So here's the math. Threats are accelerating. Budgets are shrinking. The gap between what CISOs need and what they're getting is widening for the first time in years. And the grant programs that were supposed to fill that gap are being called inadequate by the people who depend on them.
AI Is Making Everything Worse, Faster
The AI numbers in this survey are the most alarming data points. Only 2% of state CISOs feel "very confident" in their ability to defend against AI-enabled attacks. That's down from 10% in 2024. Meanwhile, 47% report low or no confidence in AI attack defense, up from 41% [3].
Deloitte cyber principal Michael Wyatt put it bluntly: "There's been substantive change in the last couple of years. AI-accelerated attacks, sophisticated threats, third-party vendor risk, budget challenges, it all adds up" [3].
The specific AI threats CISOs flagged: deepfakes for social engineering, AI agents conducting autonomous reconnaissance, and AI-driven ransomware-as-a-service that lowers the barrier to entry for attackers [1].
States aren't ignoring AI entirely. 94% of CISOs are involved in developing generative AI security policies. 84% are helping shape AI strategy for their states. 23 states actively use GenAI in security operations [1][3]. But there's a gap between writing AI policies and stopping AI-powered attacks. States are doing the governance work. They're not confident it's enough.
The Third-Party Problem
78% of CISOs identified third-party breaches as their top concern [3]. That tracks. The Canvas breach was a third-party vendor breach. The Cushman & Wakefield breach that ShinyHunters just escalated was a Salesforce-hosted data extraction. Attack after attack follows the same pattern: hit the vendor, compromise every customer at once.
65% of CISOs cited legacy infrastructure as a major barrier to security [3]. State and local systems run on aging platforms that weren't designed for current threat levels. Upgrading costs money states don't have. Not upgrading costs data they can't replace.
Kansas CISO John Godfrey framed it as a speed problem, not a knowledge problem: "The fundamentals of cyber have not changed. The issue is really just about the speed by which we need to take action" [2][4].
The "Whole-of-State" Approach: Too Little, Too Late?
About one-fifth of states are moving toward a "whole-of-state" cybersecurity model, where the state CISO's office extends protection to local governments and higher education institutions instead of leaving them to fend for themselves [1][2].
Deloitte's Mike Wyatt described this as "extending protection downward" to underfunded local entities. It's the right idea. It's also an admission that the current model (where local school districts and county governments are responsible for their own cybersecurity) has failed.
But even the states adopting this model are doing it with shrinking budgets, growing attack surfaces, and AI-enabled adversaries that move faster than procurement cycles. The whole-of-state approach assumes states have the capacity to protect themselves and everyone underneath them. The survey says they're not confident they can do the first part.
CISOs Want Proof They're Working
One trend in the survey stands out as potentially positive: 49% of CISOs now prioritize implementing effectiveness metrics, up from 25% in 2024 and just 15% in 2022 [1][2][4].
That's a meaningful shift. For years, state cybersecurity measured inputs: tools purchased, policies written, staff hired. CISOs are now demanding outcome measurements. Did the phishing training reduce click rates? Did the endpoint detection actually catch an intrusion? Is the whole-of-state model reducing breach incidents in local government?
The cynical read: when you're losing confidence, you start measuring to prove you're still worth funding. The charitable read: CISOs are growing up, moving from compliance theater to operational accountability. Either way, better data about what's working is the only path to better decisions about what to fund.
What This Means for You
If you interact with state or local government services (and you do), this survey matters. Your DMV records, your property tax data, your kids' school records, your state unemployment claims, your public university transcripts. All of it sits in systems that the people responsible for defending them say they can't adequately protect.
- Freeze your credit if you haven't already. State and local breaches expose SSNs, addresses, and financial data. A credit freeze is free at all three bureaus and takes five minutes
- Check your state's breach notification portal. Most states maintain a list of reported breaches. If your school, employer, or local government agency shows up, act on it
- Use unique passwords for government portals. Your state tax portal, your municipal utilities account, your university login. Credential stuffing from one breach cascades across every account that shares a password
- Ask your local officials about cybersecurity funding. City council meetings, school board meetings, county commissioner sessions: cybersecurity is a budget line item. Ask whether it exists, what it covers, and whether it's going up or down
The Bottom Line
The people who defend state government systems are telling us, in a formal survey with their names attached, that they're losing ground. Confidence is crashing. Budgets are getting cut. AI threats are accelerating. And the institutions they're most worried about (schools and local governments) are the ones actively getting breached.
This isn't a forecast. The Canvas breach, the Cushman & Wakefield data dump, the Medtronic compromise: these are the consequences of the gap this survey measures. CISOs aren't predicting failure. They're documenting it.
References
- Deloitte: "State CISOs Report Lower Confidence Across the Public Sector Cyber Ecosystem, 2026 NASCIO-Deloitte Survey Finds" (April 2026)
- StateTech Magazine: "NASCIO 2026 Midyear: State CISOs Report Falling Confidence as AI Threats Accelerate" (May 2026)
- Bank Info Security: "State CISOs Are Losing Confidence as AI Threats Surge" (May 2026)
- Route Fifty: "State Cyber Officials' Confidence Is Down, Survey Finds" (May 2026)
- Cybersecurity Dive: "State CISOs Losing Confidence in Ability to Manage Cyber Risks" (May 2026)
Published: May 10, 2026