✕

IE11 Not Supported

For optimal browsing, we recommend Chrome, Firefox or Safari browsers.

State CISO Urges Focus on Fundamentals, Understanding Risk

State CISO Mike Marshall called on public-sector cybersecurity professionals to redouble their efforts to leverage relationships and foundational practices during the California Cybersecurity Education Summit in Sacramento Thursday.

California CISO Mike Marshall on stage and gesturing with both hands while speaking at the 2026 California Cybersecurity Education Summit in Sacramento.
California CISO Mike Marshall speaking at the 2026 California Cybersecurity Education Summit in Sacramento.
Photo by Eyragon Eidam.
SACRAMENTO, Calif. — The times they are a-changing, and so too must public-sector cybersecurity, state CISO Mike Marshall told a banquet room full of state and local cyber professionals Thursday.

Marshall was speaking at the California Cybersecurity Education Summit*, an event geared toward government cybersecurity professionals working in what he calls “an unusual team sport.”

While many in the space are keen to go straight for the outsized impacts of AI on the space, Marshall instead used the opportunity to highlight the fundamentals of cybersecurity, calling for stronger relationships across government organizations and a deep understanding of risk.

He noted that nowadays, executives must understand the myriad risks facing their organizations as well as their ground-level developers.

“Our environment has changed and will continue to change,” he said.

Marshall also urged an approach that goes beyond adherence to standard checkbox compliance, saying meeting the bare minimum is “not the finish line.”

The CISO also underscored the importance of the team dynamics and building working relationships both inside and outside the walls of government ahead of any crises.

“Nice to meet you; our network is down,” should not be how a relationship begins, Marshall said.

The private sector plays a big role in this environment, Marshall said, and needs to bring forward solutions that move the needle for its public partners.

“We want to work with vendors who can demonstrate that their solutions move the needle on actual risk reduction,” he said. “For those of you who've already embraced that approach in your own offerings, thank you. You're ahead of the curve.”

Marshall also acknowledged the complexity of the current government environment and the varying levels of sophistication throughout the more than 150 state departments and entities.

“The goal isn't to make every organization approach cybersecurity the same way, but to establish a common direction and expectations, all while providing organizations the flexibility to focus their resources on the risks that matter to their missions most,” he said.

He urged the adoption of a common direction forcing the adoption of a singular homogeneous identity, pointing to the recently released CalSecure 2.0 document as the quintessential guide in these efforts.

With regard to the path forward, Marshall called out four critical requirements: be candid about the risks, share what is learned, invest in people and build real relationships.

“We cannot direct the wind, but we can adjust the sails,” he closed with a quote, widely attributed to the late Dolly Parton.

*The California Cybersecurity Education Summit is hosted by Government Technology, a sister publication to Industry Insider — California.
Eyragon is the Managing Editor for Industry Insider — California. He previously served as the Daily News Editor for Government Technology. He lives in Sacramento, Calif.