Resources

Legislative Lens: Cybersecurity Without Borders - Why Whole-of-State Security Is Becoming a SLED Imperative

Written by Four Inc. | Jul 20, 2026 5:54:24 PM

By Sarah Chittick

 

Welcome to Legislative Lens, a series where I explore the policy priorities, legislative developments, and government trends shaping the future of state, local, and education (SLED) technology. In each edition, I'll take a closer look at what's happening, why it matters, and what SLED leaders, technology providers, and industry partners should keep an eye on.

Across the country, governors, legislatures, and state technology leaders are placing greater emphasis on strengthening cybersecurity across the entire public sector. While every state is approaching the challenge differently, the momentum behind whole-of-state cybersecurity continues to grow, and it's becoming an increasingly important policy conversation.

The cybersecurity divide between state and local government is becoming increasingly difficult to ignore.

While larger state agencies often have the resources, personnel, and technology to develop mature cybersecurity programs, many local governments, school districts, and public entities are facing the same sophisticated threat actors with significantly fewer resources. Small IT teams are being asked to protect expanding digital environments, aging infrastructure, sensitive citizen data, and essential public services, all while navigating workforce shortages and constrained budgets.

The challenge is simple to understand but difficult to solve: Cyber threats do not respect jurisdictional boundaries, yet our cybersecurity strategies often do.

Expecting every county, municipality, school district, or university to build and maintain an independent, enterprise-level cyber defense is neither realistic nor sustainable. Instead, states have an opportunity to rethink cybersecurity as a shared responsibility through a whole-of-state security model, one that brings together people, technology, threat intelligence, and operational resources across state and local government.

The concept is not about eliminating local autonomy. It is about recognizing that collective defense can create capabilities and scale that many individual jurisdictions simply cannot achieve on their own.

 

The Risk Is Concentrated at the Local Level

The data provides a compelling picture of where government cyber risk is concentrated.

Research highlighted by Deloitte, drawing on national cyber incident data compiled by the University of Maryland, suggests that local governments and K–12 public schools may account for approximately 75% of cyber events impacting government organizations. The trend is even more pronounced in Texas, where the Texas Department of Information Resources estimated that more than 90% of attacks against government entities in 2023 targeted local government organizations.

The organizations most vulnerable to cyberattacks are often the same organizations closest to the citizens they serve. Counties operate public safety and justice systems. Municipalities support water, emergency services, and critical community infrastructure. School districts maintain sensitive student and family data. Local health organizations support essential public health services.

A successful cyberattack against one of these entities is not simply a local IT problem. The impact can quickly become a statewide operational, economic, and public trust issue.

 

From Individual Defense to Collective Resilience

A whole-of-state approach changes the conversation to, "How do we strengthen the security of the entire public-sector ecosystem?"

That shift opens the door to shared cybersecurity services, coordinated incident response, broader threat intelligence sharing, common security standards, and greater access to tools and expertise for cyber-underserved organizations.

A small county may never have the resources to operate a sophisticated security operations center or maintain a large cybersecurity team. A rural school district may struggle to recruit specialized cyber talent. A municipality may have to choose between replacing aging infrastructure and investing in advanced security capabilities.

But through a coordinated statewide model, these organizations can potentially benefit from shared capabilities, centralized expertise, and technologies deployed at a greater scale as a force multiplier.

For technology providers and the broader SLED partner ecosystem, this also requires a shift in thinking. The opportunity is not simply to sell another cybersecurity tool to another agency. The greater challenge, and opportunity, is helping states build interoperable, scalable security ecosystems that can extend capabilities beyond the walls of the state enterprise and reach the local organizations that need them most.

 

Whole-of-State Is a Journey, Not a Product

One of the most important lessons emerging from whole-of-state cybersecurity initiatives is that there is no single blueprint that will work for every state.

Whole-of-state cybersecurity should not be viewed as one-size-fits-all, a one-time modernization project, or a single technology procurement. It is an evolving operating model that requires progress across governance, collaboration, shared capabilities, information sharing, workforce development, funding, and operational execution.

The goal is not perfection on day one. The goal is measurable progress and increasing collective resilience over time.

As cyber threats continue to evolve, the question is no longer whether states should explore whole-of-state cybersecurity strategies. The more pressing question is how quickly states can build and mature them.

Every step toward stronger coordination, shared visibility, and collective defense strengthens the broader public-sector ecosystem. More importantly, it helps extend cybersecurity capabilities to the local governments, schools, and public organizations that may otherwise remain the most vulnerable.

For technology providers and SLED partners, it means moving beyond product conversations and helping government leaders solve the harder questions around scale, interoperability, governance, and long-term sustainability.

Because the future of public-sector cybersecurity will not be defined by how well one agency can defend itself, but by how effectively a state can collaborate together.

Legislative Lens: What to Watch

As whole-of-state cybersecurity continues to gain momentum, here are a few trends worth watching:

    • Expansion of statewide cybersecurity initiatives and shared services.
    • Increased investment in cyber resilience for local governments, schools, and public entities.
    • Greater collaboration between state agencies and local jurisdictions.
    • Continued emphasis on information sharing and coordinated incident response.
    • Legislative and executive actions focused on strengthening critical infrastructure security.

 

The conversation around whole-of-state cybersecurity is far from over, and it's one that will continue shaping technology strategy across the SLED landscape. If you'd like to continue the conversation or have questions about how these evolving policies may impact your organization, reach out HERE.

Stay tuned for the next edition of Legislative Lens, where we'll explore another legislative or policy trend impacting the future of state and local government technology.