Actionable Threat Intelligence Is Where NASCIO's Top Two Priorities Meet

Managing Director, Government and Critical Infrastructure, Cyware

I have been looking forward to NASCIO this year more than usual, and one key reason is the State’s Top Initiative's list.
Artificial intelligence, including generative AI, agentic AI, and machine learning, sits at number one on the 2026 State CIO Top 10. Cybersecurity and risk management sits at number two. What stood out to me is not that both rank highly. I’sthat in most states, these priorities will be pursued as two separate programs, with two committees, two budget lines, and two sets of vendors.
For whole-of-state security programs,these two priorities meet in one place, and that place is statewide collective defense. I want to take them in reverse order, because priority two defines the problem and priority one supplies the answer, and the argument only lands if you see the scale of the problem first.
Priority Two: Cybersecurity and Risk Management Is Larger Than It Looks
The cybersecurity priority lists governance, budget and resource requirements, security frameworks, data protection, training and awareness, insider threats, third-party risk, and whole-of-state cybersecurity.
Those last two items reframe everything above them. Third-party risk and whole-of-state cybersecurity are not a mandate to secure state agencies. They describe an obligation that runs across counties, cities, school districts, higher education, municipal utilities, public health entities, courts, and public safety organizations. Thousands of independent organizations, with independent budgets, at very different levels of maturity, none of which the state employs or directly controls.
Every security leader I speak with already accepts that premise. A ransomware event at a county records office affects the state services that depend on those records. A credential harvested from a school district gets reused against a state system when the same person holds accounts in both. One organization's incident is rarely contained to that organization.
Agreeing with that has never been the hard part. The arithmetic is.
The arithmetic problem no org chart solves
A large state agency may run a mature security function with dedicated analysts and detection engineering capability. A rural county in the same state may have one IT generalist handling cybersecurity alongside the help desk. Both sit in the same dependency chain. Both face the same adversaries. Only one has a realistic chance of seeing the threat coming.
What surprises leaders who have invested seriously here is that the shortage is not intelligence. Most states belong to national intelligence sharing centers, receive federal advisories, subscribe to commercial feeds, and trade notes with peers. That connectivity is real and it was hard won.
The gap opens after the intelligence arrives. An advisory could be published and distributed to several hundred organizations across the state. Several hundred people open the same document.ome fraction perform the same enrichment against the same indicators, reaching broadly the same conclusion at different times and with different quality. Then a validated indicator still has to be reviewed, approved, and entered into a block list or a detection rule by a person, in each organization, one at a time. Attacks execute in minutes. But the actioning takes days.
And the organizations most in need of the analysis are the ones least able to perform the proper analysis, so the conclusion they reach is frequently no conclusion at all.
Capacity, not coordination
None of that is an attitude problem or a governance problem. It is capacity, and capacity is the one constraint a state cannot resolve by hiring.
Which reframes what leaders are being asked to fund. The objective was never to bring six thousand organizations up to the standard of the state security operations center. That is not achievable on any realistic budget or timeline, and treating it as the goal is how whole-of-state strategies end up as documents rather than capabilities. The objective is to build one capable center and connect everyone to it, so a small municipality receives the benefit of enterprise-grade analysis without having to perform enterprise-grade analysis.
Whole-of-state security is the goal. Collective defense is the method. A shared threat intelligence capability is the mechanism that connects them.
Priority One: Artificial Intelligence Is Where That Capacity Comes From
The AI priority lists governance, policies, use cases, security, privacy, workforce skills, data quality, and ethical use. Read plainly, that is everything standing between enthusiasm and a first production deployment. Much of the conversation I expect this week is some version of the same question: what is a first AI use case that is genuinely defensible in front of a legislature, a privacy office, and an auditor?
The analysis burden described above has an unusually clean shape for exactly that purpose. The data involved is the state's own security telemetry and externally sourced threat data isnot citizen data. Outputs are reviewed by trained specialists rather than delivered to the public. The work being automated is repetitive analysis; most jurisdictions cannot staff at all, so no one is displaced. And results are measurable inside a single budget cycle.
The value of AI agents here is not autonomy. State leaders should be skeptical of anyone who frames it that way. The value is that an AI agent does in seconds what no analyst has the hours to do at all: read a single indicator against dozens of intelligence sources and years of prior reporting, correlate it, contextualize it with threat actor, campaign, malware, and technique context, score it for confidence and sector relevance, and show its reasoning. Correlate, score, explain, recommend.
That last part matters for the governance line. When confidence is scored and reasoning is inspectable, governance becomes a threshold rather than a policy statement. High confidence with a contained blast radius executes and is logged. Lower confidence, or a critical asset where being wrong is expensive, routes to a person with the reasoning attached, so the decision takes ninety seconds instead of ninety minutes. The alternative, which most programs run today, has exactly two settings: do nothing, or do everything.
Analysis is a fixed cost that becomes cheaper for the entire ecosystem the moment it is performed once, centrally, and distributed as a finished product rather than as raw material. AI is what makes performing it once fast enough to matter.
How Cyware Approaches It
Our work sits across both state top priorities rather than either one alone.
We bring intelligence from national sources, sector communities, commercial feeds, open sources, and client environments into a single system of record, then normalize, deduplicate, enrich, correlate, and score the data centrally using purpose-built AI agents before an analyst views the information. From there, the actionable intelligence is distributed in the form each recipient can actually use. A small jurisdiction may receive a prioritized, human-readable advisory with a clear recommended action. A larger agency receives machine-readable indicators delivered into a security tool it already owns. The analysis behind both is identical. Only the packaging differs, and that tiering is the difference between a program that serves sophisticated constituents and one that delivers genuine whole-of-state coverage.
This runs on a hub-and-spoke architecture over open standards such as STIX and TAXII, the structure already trusted by the majority of U.S. information sharing communities. Because the exchange is standards-based and connects through prebuilt integrations, participation is an add-on to an existing environment rather than a replacement of it. That matters more than it sounds. The most common objection to statewide programs is rarely philosophical. It is the reasonable observation that most jurisdictions cannot absorb a migration project.
Two things make it a defense rather than a distribution list. Intelligence moves in both directions, so a detection at one school district is validated, enriched, and pushed back out to every organization it could affect. And validated intelligence is enforced automatically at the endpoint, so a decision made once at the center produces protection everywhere it applies.
Collect from everywhere. Process in one place. Act everywhere it is relevant. If a proposed investment does not improve one of those three clauses, it is not a collective defense investment.
It is worth adding that this also answers the budget, modernization, and consolidation priorities further down the list. The comparison that matters is not shared infrastructure against zero. It is shared infrastructure against the current situation, in which dozens of jurisdictions independently buy feeds, portals, and point tools that overlap, do not interoperate, and are rarely fully used. Framed as a consolidation of existing distributed spend, the total cost to the ecosystem falls even as the state's line item rises.
The Questions I Plan to Ask in San Diego
When a weaponized vulnerability surfaces tomorrow, how long does it take for a confirmed indicator at the state level to reach every relevant constituent? Can you measure how much of your shared intelligence was actually enforced, rather than how much was distributed? Does your smallest county have a way to participate that does not require it to buy or operate anything?
The second question matters most. Enforcement rate is the single best indicator of collective defense maturity, and almost nobody tracks it. Success is not how many threats one agency blocks. It is how fast, and how completely, the whole state responds to a threat that any one of its members observed first.
Detect once, defend everywhere. Priority one is how a state can finally afford to.
If you are at NASCIO this week, I would genuinely enjoy the conversation. I am glad to walk through what this looks like for a state of your size and constituent mix, including how organizations at each maturity level connect and what onboarding actually involves. Email me directly at tom.stockmeyer@cyware.com, or request a walkthrough here and we will find time in San Diego or shortly after.
About the Author

Tom Stockmeyer
Managing Director, Government and Critical Infrastructure, Cyware