SACRAMENTO — Public-sector cybersecurity professionals gathered in Sacramento Thursday for the annual California Cybersecurity Education Summit* to compare notes on the landscape and the big risks and opportunities on the horizon. Here’s what we walked away with.
Some Solace on Quantum: There were a couple different takes on quantum computing and what it would mean for government cybersecurity. The more pessimistic take was that it would unlock a cryptographic hellscape where previously collected encrypted data could be unlocked for all to see — think spicy search histories, stolen medical records, etc. The other end of that conversation was more muted: It’ll be disruptive, but there’s still time to prepare and react.
Officials in one conversation said the real challenge here will be preparing for Q Day within the limits of the state’s tight and lengthy budget process. Departments have, by some estimates, around three years to prepare, but should start now to make sure they have the funds and policies in place. More on that later.
Picking a Lane: CISO Mike Marshall said numerous times throughout the event that the state is trying to align departments to its CalSecure 2.0 roadmap. While the document is meant to guide departments, vendors should be tuning in and aligning their own products and approaches to where the state is heading. Marshall said they're looking to move the needle, not just add more tools and layers. Another thing the California Department of Technology wants in this area is constructive feedback on the roadmap.
Meeting Minimums: One priority Marshall reiterated is his desire to identify what he calls “minimum viable security” for state departments, the education sector and local and tribal governments. He plans to share more on that.
More AI, More Problems? While most speakers and sources we talked to seemed almost reluctant to belabor the woes of the artificial intelligence revolution, they all acknowledged the challenges it has brought into their lives. The main takeaway we noted is that organizations want visibility and to be able to move at machine speed. Multiple officials noted that the days of patching once a week are long gone, though many organizations are struggling to keep up with the tools they have. In a similar vein, phishing attacks have become exponentially more convincing, which is also posing a problem throughout the government’s less IT-focused workforce.
The State of Nation-State Attacks: In what will come as a shock to absolutely no one, officials and some sources we talked to in passing said the number of nation-state attacks has increased since the U.S.-Iran war kicked off. Critical infrastructure continues to be in the crosshairs of online ne’er-do-wells. Education and water infrastructure seem to be drawing more than their fair share of enemy fire.
*The California Cybersecurity Education Summit is hosted by Government Technology, Industry Insider — California's sister publication.
5 Takeaways From the Cybersecurity Summit
Public-sector cybersecurity professionals gathered in Sacramento Thursday for the annual California Cybersecurity Education Summit. Here is a small taste of what we heard.