Whole-of-state cyber defense: The pathway for addressing today’s AI-fueled threats

Weiquan Lin via Getty Images
COMMENTARY | When every link in the chain is protected, the entire state is stronger, so they and their technology partners must operate as a unified, integrated force.
Nation-state actors, ransomware groups and cyber criminals have outpaced the traditional, siloed approach to government cybersecurity. Today’s sophisticated threat actors are exploiting that fragmentation faster than governments can respond.
State and local agencies sit on the front lines of defense while operating with varied resources and talent across teams. This requires these jurisdictions to lean on creative, integrated solutions that can raise the baseline of protection across the full government ecosystem.
The March 2026 Cyber Strategy for America makes collective defense a federal priority. It calls for “unprecedented coordination across government” and a “new level of relationship between the public and private sectors,” while reframing local and state security as a matter of national economic and social prosperity.
A whole-of-state cyber approach built on open, distributed architectures and artificial intelligence-driven security analytics is now an operational necessity. It enables shared visibility, stronger coordination and greater resilience while preserving data sovereignty — all of which are necessary to address the modern threat environment.
Adversaries Don’t Respect Jurisdictions
Cyber defense is only as strong as its most vulnerable endpoint. Threat actors don’t distinguish between a state agency, utilities, or critical infrastructure. Instead of targeting hardened state systems directly, they often compromise the least-defended point of entry, such as a small municipality, K-12 district or local utility, and move laterally from there.
Deloitte’s 2026 whole-of-state analysis confirms the pattern nationally. Cybercriminals are increasingly bypassing hardened state data centers to target cyber-underserved local entities, which often serve as the front doors to a state’s digital ecosystem.
They lack the budget for elite defense while remaining connected to vital networks, creating one of the greatest challenges to statewide resilience. A breach in any one of these organizations can halt 911 dispatch, disrupt emergency services, expose citizens’ personal information or shut down critical infrastructure. Stronger protection for one organization strengthens the broader ecosystem.
As a result, states face a great responsibility to build resilient, self-sufficient defensive postures. The question is how to act collectively and at scale.
Breaking Down Silos to Build Collective Resilience
A whole-of-state cybersecurity model is increasingly supported by federal frameworks. For instance, the CISA State Cybersecurity Governance Case Studies highlight how states like Georgia and Virginia have successfully used formal governance structures to manage cyber risk as a collective strategic priority. By establishing clear policies and shared resources, states can protect the most vulnerable local entities without infringing on their operational independence.
This model also treats the entire government ecosystem as a shared defensive perimeter, spanning state agencies, counties, cities, education, public safety organizations and more. Breaking down the traditional “islands” of security enables shared threat intelligence, unified tooling and coordinated incident response.
Larger state teams can then extend expertise to smaller, under-resourced entities and raise the starting point of protection for everyone. This shifts states from fragmented defense toward collective resilience.
These silos can be dismantled through a distributed data mesh approach, which:
- Delivers statewide visibility: It enables teams to search and analyze security data where it already resides. Because sensitive data cannot always be centralized, this avoids the massive costs, egress fees and compliance risks of moving log data into a single central repository.
- Preserves data sovereignty: By keeping citizen and student information within its originating department, it supports policy-aware access controls aligned to jurisdictional boundaries and enables affordable long-term retention rather than expensive cold storage.
Because whole-of-state cyber defense requires integration across agencies without forcing uniform tools or vendor lock-in, open security models are critical too.
State and local organizations operate with different budgets, policies and legacy systems, so an open security model enables collaboration by allowing agencies to participate without abandoning existing investments. Openness reduces long-term risk, preserves agency autonomy and makes sustained statewide collaboration achievable.
With the data context layer in place and searchable, analysts can then build AI-driven security practices right on top.
AI Isn't the Future of State Cybersecurity, It’s the Present
For the first time in over a decade, AI has overtaken cybersecurity as the number-one policy priority for state chief information officers, signaling a transition from AI as a future trend to AI as the primary operational tool for managing risk.
AI-powered security has become the force multiplier that makes whole-of-state cyber defense achievable.
- States can extend elite, AI-powered protection across the entire state ecosystem, including under-resourced entities that could never hire dedicated security teams.
- AI-driven analytics augment security analysts’ operations. Automated alert triage collapses hundreds of alerts into a handful of high-confidence incidents, guided investigation cuts noise and analyst fatigue, and faster response lets teams act before threats escalate. AI enables smaller teams to operate at the scale of much larger ones.
- It strengthens collective resilience too, helping to identify attack patterns across the whole ecosystem to stop multi-pronged campaigns before they spread laterally through connected networks.
The Arizona Department of Homeland Security offers a concrete example: facing more than 12 terabytes of daily logs from disparate sources, its small team adopted AI-driven security analytics to automate the detection of anomalies and malicious activity across billions of data events. Through pre-built detection rules, AZDOHS reduced false positives and alert fatigue, shifting away from reactive posture to a proactive one.
Texas A&M University System, a public, land-grant research institution with the second-largest student body in the U.S., did something similar. Handling tens of thousands of endpoints and billions of telemetry events every month, TAMUS saves over 100 analyst hours per month by automating documentation and security processes. AI-powered security also helps reduce the time to resolve from months to just two hours, a reduction of 99%.
AI-driven security is essential to maintain pace with today’s adversaries. It allows states to truly move from reactive firefighting to proactive, coordinated defense. This approach can extend AI-powered protection to every entity in the ecosystem regardless of size or budget.
The whole-of-state model can feel like a multi-year transformation, but the first step is smaller and more immediate. Map where your entities’ security data actually lives, bring your analytics to it rather than forcing a costly migration and layer AI-driven detection on top so your existing security team can properly cover.
Collective defense is now a matter of public safety, economic stability and national security. It improves resilience against adversary campaigns and helps government security teams operate efficiently despite staffing constraints.
The path forward requires states and their technology partners to operate as a unified, integrated force. When every link in the chain is protected, the entire state is stronger.
Jared Pane is senior director for field engineering of global public sector at Elastic.




