✕

IE11 Not Supported

For optimal browsing, we recommend Chrome, Firefox or Safari browsers.

State CISO Marshall on Setting Baselines, Closing Gaps and Raising All Boats

As Cybersecurity Awareness Month kicks off, newly appointed state CISO Mike Marshall shared his strategic vision for the state and its local partners and his argument against the competitive AI mentality.

Bright blue cybersecurity-related symbols like a lock and an open laptop connected by bright blue dots and lines against a dark background.
Shutterstock
When state Chief Information Security Officer Vitaliy Panych announced his return to the private sector in July, Mike Marshall was soon after named as the man tasked with keeping the state’s cybersecurity machine on the rails.

Marshall is no stranger to state government IT, having spent nearly two decades with the California Public Employees' Retirement System, where he served as an information security architect, and the California Environmental Protection Agency, where he served as CISO and later agency CIO.

Now, his perspective has been expanded to a whole-of-state view at a time when policy, budgets and capabilities are racing to keep pace with dramatic technological changes.

California CISO Mike Marshall
One of Marshall’s top priorities is engaging with organizations outside state government — counties, cities, higher education and tribal nations — to help them reach what he calls “minimum viable security.”

The CISO acknowledged the significant financial headwinds that most public-sector cybersecurity shops face, but said that the state is well positioned to close some of those gaps with its service portfolio.

“A common theme for me is reaching more than just departments and agencies within the state; it's going to be opening that up to cities, counties, higher ed, tribal nations, things like that, to make sure that everyone has the ability to access the services that we are providing at CDT,” he said.

In recent years, the California Department of Technology (CDT) has made significant strides in this respect with more than 80 state departments and external partners leveraging the offerings, but Marshall said there is more work to be done to bump up that number.

In addition to the Security Operations Center services already available, Marshall said a new CISO-as-a-service or virtual CISO and CDT readiness audit can help underfunded or otherwise unable organizations identify the path to a minimum viable security baseline.

“We're trying to expand our SOC offering, our SOC service offering, and really trying to open that up to as many as possible to make sure that we can provide that minimum viable security for everyone that wants to be involved with that,” he said.

Beyond growing the department's partner network, the CISO, like CIO Chris Given, is focused on maintaining alignment and implementing the work of his predecessor. CDT recently released its Cal-Secure 2.0 strategic plan, which he calls the state’s “guiding light.”

“I'm not coming in trying to change directions. We're staying with the direction and trying to keep the momentum going,” Marshall said.

An obvious focal point for Marshall, and really anyone operating in the cybersecurity space in 2026, is the outsized implications of artificial intelligence. And while the state has positioned itself as an early adopter of generative AI for use in government operations, it also poses both significant risks and opportunities where cyber defenses are concerned.

Asked what approach he thinks the state needs to embrace with regard to federal, state and private-sector policies and advances, Marshal opted for the cautious, thoughtful route.

“We don't necessarily need to be on the cutting edge of everything. We can continue down our path and make sure, from my perspective, that we don't harm anything in the process,” he said. “I don't want to say that other states aren’t, but California is definitely taking the lead, and is really kind of leaning into this and making sure that the controls are in place.”

While AI will continue to change the cyber landscape with new capabilities such as real-time patching and automation, and new threats such as autonomous attacks, Marshall said CDT is looking carefully at how to attract the next generation of cyber professionals.

The department is working both internally and within higher education to spotlight the work it does and attract new talent. While Marshall admits that public service is a far cry from the flash and outsized salaries of Silicon Valley, the stability and impact are a considerable draw for some.

As far as where the private sector fits into Marshall’s vision of a secure CDT and state, he expects more from the vendors knocking on his door. It’s not enough to have a solution that may or may not add value; it has to fit within the department’s long-term strategies, namely Envision 2026 and Cal-Secure 2.0.

Vendors should be able to highlight where their solutions fit within those frameworks and should expect a relationship over one-off sales.

“I want them to really be a partner and lean in and be a long-term partner. I don't want to hear from someone every year the two months before the renewals are due,” he said. “I really want them to be a partner, and I really want them to help get us to where we're going.”

Marshall will be speaking at the upcoming California Cybersecurity Education Summit* Oct. 8.

*The California Cybersecurity Education Summit is hosted by Government Technology, Industry Insider — California's sister publication.
Eyragon is the Managing Editor for Industry Insider — California. He previously served as the Daily News Editor for Government Technology. He lives in Sacramento, Calif.