State and Local Government Cyber Leaders Prioritize AI, Identity and Stopping Fraud
State and Local Government Cyber Leaders Prioritize AI, Identity and Stopping Fraud
As state and local chief information security officers (CISOs) and other cybersecurity leaders met in San Antonio, Texas, this past week, global headlines focused on existential threats about AI governance, the Iran war scaring stock markets as oil prices surged and cyber attacks continued against critical infrastructure, such as water systems.
The meeting was the first of its kind for Government Technology where state and local government cybersecurity pros engaged in sessions and networking opportunities that covered many unique aspects of their missions and duties. Sessions ranged from “AI Impact on the Future of Cyber Defense” for state and local governments to the future of the CISO role and managing risk in governments. There were also networking meals and small group discussions.
I was blessed to serve as one of the keynote moderators for two panels and as discussion leader for one of the breakouts. The conversation and interactions were excellent, and I am sure there will be more of these events to come in years ahead.
Here are some of the highlights — without attributing specific statements to any state or local CISO.
AI ROUNDUP FOR CYBER
As this blog has discussed before, frontier AI is a hot topic for CISOs, and OpenAI and Anthropic have programs to help state and local governments provide improved cyber defenses as we head into late 2026.
Almost every CISO is exploring or implementing some aspects of these grant programs with vendors, with varying results. Most leaders feel as if we are still in the early days — and it is too soon to show results. Also, there are many contractual questions and questions on privacy and the use of government data.
Still, there was plenty of sharing of best practices and tips among the security leaders. Everyone agreed that this was topic No. 1 and a hot issue for the foreseeable future.
After the event, I found this recently released report from Anthropic to be very helpful on this wider topic.
IDENTITY STILL CENTER STAGE AS ZERO-TRUST GATEWAY
As described in last week’s blog, the recent driver’s license breach and other ransomware attacks were discussed by the CISOs.
The importance of identity management to protecting government networks was clear and a top topic, both for internal state networks and to support residents. The link to zero-trust network architectures was also discussed.
This video discusses identity security details from Black Hat back in August:
FIGHTING FRAUD ROUNDUP
One interesting discussion revolved around the CISO’s role in fraud prevention in various programs, with most security leaders saying that they were involved, but not the lead, in their governments. It was clear that everyone was interested and engaged on this topic.
There have been numerous perspectives on this over the past year, and here are some of those themes/articles:
Governor Newsom convenes the first meeting of California’s Tech Fraud Task Force to help strengthen consumer protections
Excerpt: “California fights fraud on all fronts. From securing refunds for mortgage fraud victims to cracking down on deceptive practices by businesses, California is both protecting consumers from fraud and addressing fraud against the government. …”
Minnesota State prepares to pilot new technology to combat financial aid fraud. Is it enough?
“The Minnesota State system of 26 colleges and seven universities is preparing to pilot a new automated identity verification system that it says will help combat the ever-evolving problem of ghost students. The Legislature this spring allocated $3 million toward the effort, which Craig Munson, who oversees information security for the system, said should provide guardrails for a couple of years. …”
Red states target SNAP fraud, errors under threat of costly federal penalties
“State officials across the country are looking to crack down on fraud and mistakes in the nation’s largest food assistance program, spurred by looming federal rules that will force states with high error rates to pay more.
“But the Republican proposals mostly focus on more frequently verifying the eligibility of individual households that participate in the Supplemental Nutrition Assistance Program (SNAP), rather than on broader administrative shortcomings that allow most of the waste and fraud to occur.
“Policies such as verifying recipients’ eligibility each month — which can involve cross-checking multiple databases or collecting extra documentation — might increase state agencies’ workloads without lowering error rates. This is especially likely if states don’t boost funding to handle the extra paperwork, investigate fraud or resolve recipient and agency errors. …”
FINAL THOUGHTS
This event was the brainchild of Teri Takai, chief programs officer at e.Republic*, who has wanted to get this in-person dialogue going between state and local leaders in cybersecurity for more than five years. Everyone agreed it was a huge success, with hopes to grow the program for next year to include even more nationwide participation.
*e.Republic is Government Technology’s parent company.
