Whole-of-state cyber defense: The pathway for addressing today’s AI-fueled threats

Weiquan Lin via Getty Images

COMMENTARY | When every link in the chain is protected, the entire state is stronger, so they and their technology partners must operate as a unified, integrated force.

Nation-state actors, ransomware groups and cyber criminals have outpaced the traditional, siloed approach to government cybersecurity. Today’s sophisticated threat actors are exploiting that fragmentation faster than governments can respond.

State and local agencies sit on the front lines of defense while operating with varied resources and talent across teams. This requires these jurisdictions to lean on creative, integrated solutions that can raise the baseline of protection across the full government ecosystem.

The March 2026 Cyber Strategy for America makes collective defense a federal priority. It calls for “unprecedented coordination across government” and a “new level of relationship between the public and private sectors,” while reframing local and state security as a matter of national economic and social prosperity.

A whole-of-state cyber approach built on open, distributed architectures and artificial intelligence-driven security analytics is now an operational necessity. It enables shared visibility, stronger coordination and greater resilience while preserving data sovereignty — all of which are necessary to address the modern threat environment.

Adversaries Don’t Respect Jurisdictions

Cyber defense is only as strong as its most vulnerable endpoint. Threat actors don’t distinguish between a state agency, utilities, or critical infrastructure. Instead of targeting hardened state systems directly, they often compromise the least-defended point of entry, such as a small municipality, K-12 district or local utility, and move laterally from there.

Deloitte’s 2026 whole-of-state analysis confirms the pattern nationally. Cybercriminals are increasingly bypassing hardened state data centers to target cyber-underserved local entities, which often serve as the front doors to a state’s digital ecosystem.

They lack the budget for elite defense while remaining connected to vital networks, creating one of the greatest challenges to statewide resilience. A breach in any one of these organizations can halt 911 dispatch, disrupt emergency services, expose citizens’ personal information or shut down critical infrastructure. Stronger protection for one organization strengthens the broader ecosystem.

As a result, states face a great responsibility to build resilient, self-sufficient defensive postures. The question is how to act collectively and at scale.

Breaking Down Silos to Build Collective Resilience

A whole-of-state cybersecurity model is increasingly supported by federal frameworks. For instance, the CISA State Cybersecurity Governance Case Studies highlight how states like Georgia and Virginia have successfully used formal governance structures to manage cyber risk as a collective strategic priority. By establishing clear policies and shared resources, states can protect the most vulnerable local entities without infringing on their operational independence.

This model also treats the entire government ecosystem as a shared defensive perimeter, spanning state agencies, counties, cities, education, public safety organizations and more. Breaking down the traditional “islands” of security enables shared threat intelligence, unified tooling and coordinated incident response.

Larger state teams can then extend expertise to smaller, under-resourced entities and raise the starting point of protection for everyone. This shifts states from fragmented defense toward collective resilience.

These silos can be dismantled through a distributed data mesh approach, which:

  • Delivers statewide visibility: It enables teams to search and analyze security data where it already resides. Because sensitive data cannot always be centralized, this avoids the massive costs, egress fees and compliance risks of moving log data into a single central repository.
  • Preserves data sovereignty: By keeping citizen and student information within its originating department, it supports policy-aware access controls aligned to jurisdictional boundaries and enables affordable long-term retention rather than expensive cold storage.

Because whole-of-state cyber defense requires integration across agencies without forcing uniform tools or vendor lock-in, open security models are critical too.

State and local organizations operate with different budgets, policies and legacy systems, so an open security model enables collaboration by allowing agencies to participate without abandoning existing investments. Openness reduces long-term risk, preserves agency autonomy and makes sustained statewide collaboration achievable.

With the data context layer in place and searchable, analysts can then build AI-driven security practices right on top.

AI Isn't the Future of State Cybersecurity, It’s the Present

For the first time in over a decade, AI has overtaken cybersecurity as the number-one policy priority for state chief information officers, signaling a transition from AI as a future trend to AI as the primary operational tool for managing risk.

AI-powered security has become the force multiplier that makes whole-of-state cyber defense achievable.

  • States can extend elite, AI-powered protection across the entire state ecosystem, including under-resourced entities that could never hire dedicated security teams.
  • AI-driven analytics augment security analysts’ operations. Automated alert triage collapses hundreds of alerts into a handful of high-confidence incidents, guided investigation cuts noise and analyst fatigue, and faster response lets teams act before threats escalate. AI enables smaller teams to operate at the scale of much larger ones.
  • It strengthens collective resilience too, helping to identify attack patterns across the whole ecosystem to stop multi-pronged campaigns before they spread laterally through connected networks.

The Arizona Department of Homeland Security offers a concrete example: facing more than 12 terabytes of daily logs from disparate sources, its small team adopted AI-driven security analytics to automate the detection of anomalies and malicious activity across billions of data events. Through pre-built detection rules, AZDOHS reduced false positives and alert fatigue, shifting away from reactive posture to a proactive one.

Texas A&M University System, a public, land-grant research institution with the second-largest student body in the U.S., did something similar. Handling tens of thousands of endpoints and billions of telemetry events every month, TAMUS saves over 100 analyst hours per month by automating documentation and security processes. AI-powered security also helps reduce the time to resolve from months to just two hours, a reduction of 99%.

AI-driven security is essential to maintain pace with today’s adversaries. It allows states to truly move from reactive firefighting to proactive, coordinated defense. This approach can extend AI-powered protection to every entity in the ecosystem regardless of size or budget.

The whole-of-state model can feel like a multi-year transformation, but the first step is smaller and more immediate. Map where your entities’ security data actually lives, bring your analytics to it rather than forcing a costly migration and layer AI-driven detection on top so your existing security team can properly cover.

Collective defense is now a matter of public safety, economic stability and national security. It improves resilience against adversary campaigns and helps government security teams operate efficiently despite staffing constraints.

The path forward requires states and their technology partners to operate as a unified, integrated force. When every link in the chain is protected, the entire state is stronger.

Jared Pane is senior director for field engineering of global public sector at Elastic.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.