Updating California’s roadmap for protecting the state government from sophisticated cyber threats, Governor Gavin Newsom has announced the release of an updated strategy, known as Cal-Secure 2.0, to protect the state against new online threats, including AI-enabled cyberattacks.
Building on California‘s first statewide cybersecurity strategy launched in 2021, Cal-Secure 2.0 gives state agencies practical tools and guidance to strengthen the systems Californians rely on every day – from benefits and healthcare to transportation and public safety. The plan also prepares the state for new threats driven by AI and other rapidly evolving technologies.
“Californians expect their government to protect not only their personal information, but also the essential services they rely on every day. As cyber threats evolve, California is evolving with them. Our strategy helps ensure our state stays ahead of emerging risks while continuing to deliver secure, reliable public services”, Governor Gavin Newsom.
Cyberattacks are becoming more frequent and more sophisticated. Criminals are increasingly using AI to create convincing scams, exploit security weaknesses, and target government and critical infrastructure systems.
This updated strategy gives state agencies a clear roadmap to identify their biggest cybersecurity vulnerabilities, strengthen protections, and respond faster when threats emerge.
The strategy focuses on three priorities:
-
Building a stronger cybersecurity workforce by recruiting, training, and retaining skilled professionals across state government.
-
Improving coordination across government so agencies can share information, respond faster, and learn from one another.
-
Modernizing technology by investing in stronger security tools and preparing for emerging technologies, including artificial intelligence.
“Cyber threats don’t stand still, and neither can we,” said California State Chief Information Officer and California Department of Technology Director Chris Given. “Cal-Secure 2.0 gives state agencies practical guidance and tools to strengthen security, adapt to new threats, and better protect the services Californians depend on.”
Thus gives agencies flexibility to focus on the risks that matter most to their operations while following a common statewide framework aligned with national cybersecurity standards.
“Our goal is simple: help every state entity understand its biggest risks, strengthen its defences, and respond quickly when threats arise,” said California State Information Security Officer Vitaliy Panych. “This roadmap gives agencies the flexibility to improve over time while working together under a common statewide strategy for both the state and our partners in critical sectors.”
Modernising state-level cybersecurity and digital public infrastructure will be central to conversations at Identity Week America 2026 (September 2–3, 2026). Attendees focused on public sector security strategies can attend key sessions in the Digital Public Infrastructure and AI & Cybersecurity Threats tracks. Highlighting these state-level implementations, Ajay Gupta (Chief Digital Transformation Officer, California DMV) will join the panel “Integrating Digital Identity into DPI”, alongside public sector leaders such as Marie Eichholtzer (Senior Digital Development Specialist, The World Bank) and Robert Reynolds (CIO, Orange County) discussing resilience against AI-backed cyber attacks. Get your ticket here.













