IE11 Not Supported

For optimal browsing, we recommend Chrome, Firefox or Safari browsers.

Cal-Secure 2.0 Is Live — Here Are the Broad Strokes

It’s been five years since the state released its initial Cal-Secure roadmap. The new version just dropped, offering a comprehensive look at where agencies, departments and other entities will be aligning on cybersecurity.

Cyber security.jpg
The much-anticipated second iteration of the state’s cybersecurity roadmap is live.

Cal-Secure 2.0 was officially published Friday morning after several weeks of rumors and supposition, and amidst the news that one of its major contributors, state CISO Vitaliy Panych, would be leaving for the private sector.

Cal-Secure 1.0 was first made public in 2021, offering agencies, departments and the private sector a look at how the state should be approaching its cyber defense work. This latest iteration builds on that concept, highlighting new realities posed by emerging technologies, like artificial intelligence, as well as more internal organizational challenges such as hiring and retention in a competitive space.

“Our goal is simple: help every state entity understand its biggest risks, strengthen its defenses and respond quickly when threats arise,”Panych said in the state’s announcement. “This roadmap gives agencies the flexibility to improve over time while working together under a common statewide strategy for both the state and our partners in critical sectors.” 

The new document was developed in partnership with the California Cybersecurity Integration Center (Cal-CSIC), the California Governor’s Office of Emergency Services (CalOES), California Highway Patrol (CHP), California Military Department (CMD) and cybersecurity leaders from across the state. It outlines three overarching priorities: bolstering the cyber workforce, improved information sharing and continued technology modernization.

While the document is a statewide strategy, it’s a far cry from the removal of departmental autonomy. Agencies, departments, offices and boards will still have the ability “to execute individual cybersecurity strategies and capabilities.”

“Cyberthreats don’t stand still, and neither can we,” State CIO and CDT Director Chris Given said in the release. ”Cal-Secure 2.0 gives state agencies practical guidance and tools to strengthen security, adapt to new threats and better protect the services Californians depend on.” 

For vendors working in the cybersecurity space, the document should serve as a foundational guide for approaching any state entity with solutions. More information about the overhauled strategy, as well as the full document and tool kit, is available online.
Eyragon is the Managing Editor for Industry Insider — California. He previously served as the Daily News Editor for Government Technology. He lives in Sacramento, Calif.