20 September 2026

2026 NASCIO-Deloitte Cybersecurity Study

Deloitte Insights | Meredith Ward, Mike Wyatt

Deloitte Insights has launched its digital platform interface featuring a suite of proprietary research portfolios, including the 2026 Global Human Capital Trends and Tech Trends 2026. This centralised hub provides public and private sector organisations with strategic analysis across diverse industries, such as government, telecommunications, and financial services.

The platform serves as a critical resource for state and local government entities seeking data-driven operational guidance. Through specialised research hubs like the Centre for Government Insights, the publication delivers targeted analyses on defence, security, justice, and infrastructure. Additionally, the platform integrates interactive learning tools, offering professional development through Dbriefs webcasts. The portal offers CPE credits. These resources collectively aim to assist decision-makers in translating organisational aspirations into practical, actionable strategies amidst evolving technological and economic landscapes. Ultimately, the portal facilitates continuous executive education and cross-industry strategic planning.

Comment

The integration of state-level cybersecurity frameworks monitored by NASCIO reveals persistent vulnerabilities in sub-national digital defence architectures. While federal initiatives like the CISA State and Local Cybersecurity Grant Program provide essential funding, local government networks remain prime targets for ransomware syndicates such as LockBit. State-level networks operating without unified endpoint detection systems remain highly susceptible to advanced persistent threats. This disparity in cyber resilience between CISA-monitored federal networks and municipal administrations creates soft targets within critical infrastructure sectors like water treatment and emergency services.

This systemic vulnerability forces state governors to increasingly deploy National Guard cyber units, such as the 175th Cyber Operations Squadron, to remediate local municipal breaches. Such frequent domestic deployments deplete the operational readiness of these military assets for federal cyber warfare missions under US Cyber Command. Ultimately, municipal vulnerabilities monitored by NASCIO directly degrade the strategic availability of the 175th Cyber Operations Squadron for global US Cyber Command operations.

Strategic Question for Discussion
If state-level networks continue to rely on the CISA State and Local Cybersecurity Grant Program for basic defence, how does the resulting operational lag affect the mobilisation timelines of National Guard cyber units during a coordinated national-level cyber incident?
The current trajectory indicates that prolonged reliance on federal grant cycles delays the acquisition of real-time threat-hunting tools at the municipal level, leaving critical entry points exposed. My assessment is that this operational lag will force National Guard cyber units into reactive, prolonged remediation roles rather than rapid-response deployments. Consequently, the mobilisation timeline for these reserve forces during a wider crisis becomes highly unpredictable, directly compromising US Cyber Command's domestic shielding capabilities.
Share your assessment in the comments below.