How Should States Confront Cybersecurity Risks?

TL;DR
States should adopt shared cybersecurity protocols because attackers can exploit a weak state or connected provider to reach data held elsewhere. Virginia's approach combines the NIST framework, an information sharing organization, cross-sector coordination, education, scholarships, veteran training, and private-sector partnerships to strengthen both security and the cyber workforce.
Transcript
Your governor. We're grateful to have with us a governor who understands that cybersecurity is an economic imperative for our nation. It's my great pleasure to introduce the 72nd governor of the Commonwealth of Virginia, the Honorable Terry McAuliffe. Thank you, everybody. Well, thank you, everybody. What an honor to be with you today. It's, um, on... Read More
Key Insights
- State cybersecurity is a collective security problem because a well-protected state can still be exposed through a shared healthcare provider or another connection involving a less-prepared state. McAuliffe therefore calls for all 50 states to implement basic, common cybersecurity protocols.
- State governments possess highly sensitive information, including tax returns, healthcare records, and driver's license data. The concentration of this information makes state systems persistent targets and gives governors direct responsibility for protecting residents, public institutions, and businesses from cyber threats.
- Virginia recorded 86 million cyberattacks in the previous year, which McAuliffe describes as three attacks every second. Its risk profile also includes 27 military installations and major defense and intelligence institutions, increasing the importance of protecting government, military, and commercial information.
- Virginia's security program is built around established governance and coordination mechanisms. The state implemented the NIST framework, created an ISAO, issued executive orders, passed seven pieces of legislation, and formed a cyber commission that met seven times across the Commonwealth.
- Cross-sector collaboration is a core part of Virginia's cybersecurity strategy. Cyber commission meetings brought together businesses, university presidents, the FBI, DHS, and the Department of Defense to examine what the state needed to do to advance its cyber capabilities.
- Cybersecurity education begins before college in Virginia through state-funded cyber camps for children and the inclusion of computer science in standards of learning tests. McAuliffe argues that students should begin thinking about cyber topics from pre-K through the end of secondary school.
- Virginia's workforce pipeline connects education with public service through scholarships that pay for cyber degrees when recipients agree to work for the state for several years. A matriculation agreement also gives community-college cyber coursework credit toward transfer into four-year degree programs.
- Veterans are a targeted source of cybersecurity talent because Virginia has many veterans, including female veterans and veterans under age 28. The state's dedicated program credits military service and moves participants through community colleges toward cyber qualifications and employment opportunities.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: Why should all states adopt common cybersecurity protocols?
All states should adopt basic cybersecurity protocols because their systems and service providers are interconnected. Even if Virginia keeps attackers out of its own systems, an attacker could compromise a less-prepared state that uses the same healthcare provider, enter through that connection, and pursue Virginia's information. McAuliffe describes national cybersecurity as limited by the weakest state-level link.
Q: What sensitive information do state governments need to protect?
State governments hold substantial quantities of sensitive information, including state tax returns, healthcare records, and driver's license data. McAuliffe says states collectively possess more data than the federal government and face constant attempts to obtain it. Protecting these records is therefore a central responsibility for governors and an economic concern for businesses operating within their states.
Q: How significant was the cyber threat facing Virginia?
Virginia experienced 86 million cyberattacks in the previous year, a rate McAuliffe characterizes as three every second. The state also contains 27 military installations, including the Pentagon, the CIA, Quantico, Langley, Oceana, and the world's largest naval base. These government, defense, intelligence, state, and business assets make Virginia a frequent target for attempted data theft.
Q: What cybersecurity measures did Virginia implement?
Virginia implemented the NIST framework, established an ISAO, created a cyber commission, issued executive orders, and passed seven pieces of legislation intended to build the cyber sector. McAuliffe presents these measures as reusable models for other governors, arguing that states can adopt existing executive orders and legislative approaches instead of independently recreating the same basic policies.
Q: How did Virginia coordinate government, business, and universities on cybersecurity?
Virginia held seven cyber commission meetings across the Commonwealth to bring relevant organizations into the same discussion. Participants included private-sector businesses, university presidents, DHS, the FBI, and the Department of Defense. Their shared task was to determine what Virginia needed to do next to strengthen cybersecurity, expand capabilities, and connect public policy with education and industry requirements.
Q: How did Virginia introduce cybersecurity education to children?
Virginia funded cyber camps that allowed children, including students around ages 10, 11, and 12 as well as younger participants, to explore cybersecurity. McAuliffe also advocated introducing cyber concepts as early as pre-K and said computer science had become a core component of the state's standards of learning tests, linking early exposure with continued school instruction.
Q: How did Virginia prepare college students for cybersecurity careers?
Virginia used scholarships for service to pay for students' cyber degrees when they committed to working for the state for several years. It also created a matriculation agreement that awarded credit for cyber courses taken through community colleges and supported transfer into four-year programs. McAuliffe additionally wanted higher-education institutions and community colleges recognized as cyber centers of excellence.
Q: How did Virginia help veterans enter cybersecurity careers?
Virginia created a cybersecurity program specifically for veterans that recognized their military service and directed them through community colleges toward cyber qualifications. McAuliffe viewed veterans as a valuable workforce because of their dedication, loyalty, and work experience. The initiative was also intended to connect veterans with the state's 36,000 open cyber jobs, which had starting pay of $88,000.
Summary & Key Takeaways
-
State governments hold tax returns, healthcare records, driver's license information, and other sensitive data that attackers continually target. McAuliffe argues that inconsistent protections create nationwide exposure because an attacker could compromise a shared provider through a less-prepared state and then use that connection to pursue another state's information.
-
Virginia's cybersecurity strategy combines governance, technical standards, legislation, and collaboration. The state adopted the NIST framework, established an ISAO, passed seven pieces of legislation, and convened a cyber commission involving businesses, universities, the FBI, DHS, and the Department of Defense to identify needs and coordinate improvements.
-
Workforce development is central to Virginia's approach because the state had 36,000 open cyber jobs with starting pay of $88,000. Its pipeline includes children's cyber camps, computer science in school standards, scholarships for service, community-college transfer agreements, higher-education cybersecurity programs, and training that credits veterans' military experience.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator