States Urged to Address Cybersecurity Risks as Responsibility Shifts Away from the Federal Government
Summary
Provide incentives, such as tax breaks, grants, or favored supplier status to companies that meet rigorous cybersecurity benchmarks, and encourage businesses to participate in threat intelligence-sharing initiatives to increase overall situational awareness.4. Expand Cyber Awareness and Training for Government EmployeesHuman error remains the largest vulnerability in cybersecurity as employees fall victim to phishing attacks and other social engineering tactics that can lead to data breaches and system compromises. Establish emergency response protocols integrating these units with state IT departments and local law enforcement, and run joint cybersecurity drills to ensure that all relevant agencies coordinate effectively in the event of an attack.7. States should provide free cybersecurity training materials to educate employees on phishing and social engineering tactics; encourage strong password policies, MFA adoption, and regular software updates/system patches; and promote cyber incident response planning.10. CRI provides a free one-hour certification program that has been taken by thousands of small and medium-sized businesses globally.“The Time For Action is Now”“Make no mistake – this shift in cybersecurity responsibilities is a wake-up call to state and local governments,” Koff said.