Cybersecurity strategy: Lessons from the states
- By Sara Friedman
What: “Cybersecurity for the States: Lessons from Across America,” a report from New America
Why: With their responsibility to protect databases full of citizens' personal information, secure critical infrastructure, support local government and train the next generation of workers, states must be "laser focused" on information technology and cybersecurity.
Findings: States are responding to the cybersecurity threat in a number ways. The report highlights three mature, scalable state programs that demonstrate different approaches toward cybersecurity.
Arizona is using a community approach. It has partnered with the Arizona Cyber Threat Response Alliance to facilitate cyber threat information sharing. The partnership with ACTRA acts as a buffer between the state and the private sector that encourages participation and "engenders faith in the anonymity and effective dissemination of information," the authors said.
New Jersey has applied a bureaucratic superstructure approach. Its New Jersey Cybersecurity and Communications Integration Cell is a central operations center that coordinates cybersecurity monitoring and incident response services with internal and external stakeholders. The shared services model has increased the breadth and quality of monitoring services, expanded information sharing and offered state and external partners a single point of contact for cyber concerns.
Washington uses a multidisciplinary model that extends cybersecurity responsibility beyond the IT offices to state-based emergency management and military departments. The state's use of the National Guard to improve the defensive posture of critical infrastructure has also contributed to broader avenues for information sharing prior to incidents.
To help states improve their cybersecurity operations, the report lays out three recommendations for the federal government:
- Dedicate specific funding mechanisms that are tied to federal priorities that go beyond emergency services and counterterrorism.
- Synchronize federal responsibilities and authorities to be able to respond better to threats in the states.
- Prioritize the expansion of localized assistance programs through the Departments of Homeland Security and Defense.
Read the full report here.