{"id":5545,"date":"2024-09-30T15:43:03","date_gmt":"2024-09-30T20:43:03","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/state-cisos-struggle-budgeting-staffing"},"modified":"2024-09-30T15:43:03","modified_gmt":"2024-09-30T20:43:03","slug":"overtaxed-state-cisos-struggle-with-budgeting-staffing","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/30\/overtaxed-state-cisos-struggle-with-budgeting-staffing\/","title":{"rendered":"Overtaxed State CISOs Struggle With Budgeting, Staffing"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltb53135d57f129261\/66fb0032357c9616a9ad52c8\/License_plates-Timothy_Swope-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Chief information security officers (CISOs) of US states are being stretched thin by widening responsibilities and insufficient resources to achieve them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Today, and for some time now, every state and the District of Columbia has had its own, dedicated CISO office.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In the early 2000s, the advent of the Internet and the desire to develop citizen-facing applications accessible from the Internet really started that trend,&#8221; explains Srini Subramanian, co-author of the newly released <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www2.deloitte.com\/us\/en\/insights\/industry\/public-sector\/2024-deloitte-nascio-cybersecurity-study.html#uncomfortably-murky\" rel=\"noopener\">biennial cybersecurity report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from Deloitte and the National Association of Chief Information Officers (NASCIO). State governments, he notes, are as attractive as cyber targets as any company.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;States collect, share, and use data of residents from birth, including school, driving records, health records, and more,&#8221; he explains. &#8220;So they do have very comprehensive information about people in very large volumes, which makes them attractive targets.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like CISOs of corporations, these individuals are responsible for building and managing statewide IT security programs and policies, managing cyber-risks and incident response efforts, ensuring compliance with relevant regulations and standards, and more. Also like CISOs of corporations, state CISOs face the same hindrances to their jobs.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/dark-reading-confidential-the-ciso-and-the-sec\" target=\"_self\" rel=\"noopener\">Dark Reading Confidential: The CISO and the SEC<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Among all 51 US state CISOs surveyed in the Deloitte\/NASCIO report, many report an expansion of their responsibilities with regard to protecting data privacy, risk management, and more. At the same time, plenty report having insufficient funds and personnel for actually handling those responsibilities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;State systems don&#8217;t have as many resources as the private sector,&#8221; Subramanian says. For example, &#8220;When we make a comparison to a financial services institution \u2014 they have thousands of full-time [cybersecurity employees]. In this report, 80% of states report anywhere from five to 50 people. States are being asked to do a lot more with very few resources, and it is a real challenge in terms of how they can accomplish their goals.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"More Work for State CISOs\">More Work for State CISOs<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, state CISOs are doing more today than ever before. More CISO&#8217;s offices now provide support to stage agencies in the realms of strategy, governance, and risk management (up 17%), security management and operations (up 8% over 2022), incident response (up 17%), and network and infrastructure (up 7%).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Most starkly: 86% of CISO&#8217;s offices now handle data privacy, up from 60% just two years ago, thanks, perhaps, to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/biden-administration-unveils-data-privacy-executive-order\" rel=\"noopener\">new data privacy rules<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> spreading across the nation.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/shadow-ai-sensitive-data-exposure-workplace-chatbot-use\" target=\"_self\" rel=\"noopener\">Shadow AI, Data Exposure Plague Workplace Chatbot Use<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The lone counterpoint is that state CISOs today have markedly less to worry about when it comes to physical security, providing a kind of counterbalance.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 2020 (52%) and 2022 (54%), a majority of CISO&#8217;s offices handled physical security for data centers and other pertinent facilities, but in 2024 that number plummeted to 35%. Today, just six state cybersecurity budgets allocate anything toward physical security. That, Deloitte posited, may indicate that states have been consolidating their data centers, or outsourcing to third-party providers.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Budgets, Staffing Lag Behind\">Budgets, Staffing Lag Behind<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Compared to their increased workloads, however, state CISOs offices are not being financed and staffed with equivalent fervor.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Most respondents didn&#8217;t even know what percentage of their states&#8217; IT budgets were allocated to cybersecurity, specifically. Among those who did, four reported that it made up somewhere between 0% and 1% of their states&#8217; funding for IT. On the flip side, just one in five reported rates of 3% and above.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For a sense of just how low those figures are, consider that out of the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2024\/03\/ap_15_it_fy2025.pdf\" rel=\"noopener\">$75 billion in IT spend<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that the White House proposes for civilian agencies in the 2025 fiscal year, $13 billion \u2014 about 17% \u2014 is set aside for cybersecurity-related activities.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/how-to-navigate-sec-cybersecurity-disclosure-rules\" target=\"_self\" rel=\"noopener\">How Should CISOs Navigate the SEC Cybersecurity and Disclosure Rules?<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The rigor and emphasis on cyber has always been greater in the federal government,&#8221; Subramanian notes. As a result, &#8220;State CISOs have to go and seek resources from the CIOs as part of their technology budget. Whereas in the federal government, all federal agencies have had to, for the last several years, submit a cyber budget request, and really outline how they are going to spend that money on cyber.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Budget constraints and a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cyber-staffing-shortages-remain-cisos-biggest-challenge\" rel=\"noopener\">talent shortage<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> help explain why nearly four in five state CISOs cite staffing as a challenge. Though the number of scarily understaffed offices has dropped \u2014 just two respondents reported having one to five full-time employees, down from six in 2022 \u2014 more than half of state CISOs report that their staff lack the competencies necessary to deal with the demands of the job.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Why the Same CISO Issues Keep Cropping Up\">Why the Same CISO Issues Keep Cropping Up<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Whether it be a private company or a government organization, large or small, the issues that face CISOs today are pretty consistent across the board, because the underlying gap between security leaders and their colleagues always tends to take a similar shape.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Until the security program is not perceived as a &#8216;cost&#8217; but rather a 100 times unplanned-for-cost-avoiding department, CISOs will struggle with budget and relevance,&#8221; says Pete Nicoletti, global field CISO at Check Point Software. &#8220;CISOs and security practitioners typically have a hard time justifying their programs to leadership. We are too technical and are worried that the sky is falling 24\/7. We can usually get the minimum budget approved based on compliance mandates, but we all know that is not enough.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To close that gap, he suggests, security leaders need to get more people whose jobs don&#8217;t involve security involved in the security process: &#8220;Involve your directors and leaders in every tabletop exercise, share every report on external threats, and teach them all the terms they need to know, so they can see it your way!\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some states, actually, are already employing this tactic to interesting effect. Subramanian recalls how, &#8220;in Texas, there is a regional security operations center that has been set up with a combination of a university, private sector, and the government. The first level of triaging is done by students who are working part time, as they are doing cybersecurity studies. So this can address both the talent issues facing CISOs, as well as getting things done for states and local governments.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/state-cisos-struggle-budgeting-staffing\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chief information security officers (CISOs) of US states are being<\/p>\n","protected":false},"author":12,"featured_media":5546,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5545","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/overtaxed-state-cisos-struggle-with-budgeting-staffing-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5545"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5545\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5546"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}