(The Center Square) - Gov. Gavin Newsom has announced an expansion of the state’s cybersecurity plan to protect state agencies from increasing cyber threats and artificial intelligence-enabled cyberattacks.
Cal-Secure 2.0 builds upon the original Cal-Secure roadmap that was launched in 2021.
“Californians expect their government to protect not only their personal information, but also the essential services they rely on every day,” Newsom said in a press release. “As cyber threats evolve, California is evolving with them. Our strategy helps ensure our state stays ahead of emerging risks while continuing to deliver secure, reliable public services.”
The updated strategy prioritizes training and recruiting to build a stronger cybersecurity workforce, improvements in coordination amongst government agencies so that information can be shared faster, and investment in stronger security tools.
According to Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance, the change from the original Cal-Secure to Cal-Secure 2.0 reflects a larger movement towards continuous risk management rather than “treating security as a one-time compliance exercise.”
“The biggest change is California's shift from a compliance-based approach to a continuous, risk-based model,” Steinhauer wrote in an email to The Center Square. “Instead of every agency following the same checklist, agencies will prioritize cybersecurity based on the systems they operate, the data they hold, and the risks they face.”
It is hard to identify one, or even a few places, where cyberattacks are most likely to occur, because they can occur anywhere, according to Bartlett Cleland, senior fellow of tech and innovation at the Pacific Research Institute
“Any place where there is valuable data, and frankly, these days almost all data is valuable for one group or another,” Cleland told The Center Square in an interview. “But the most valuable is always going to be any kind of person identifying information.”
Personal identifying information, financial information, health information, water sources, electricity systems, communication systems, and infrastructure are just a few of the areas prone to cyberattacks, according to Cleland.
At the government level, Cleland said that drivers license bureaus, tax entities, both the federal IRS and any state revenue department, Medicaid, and Medicare all face cybersecurity threats.
Cleland said that attackers focus on two objectives.
“The two biggest buckets are where you can get the most value and where you can cause the most damage,” Cleland said.
According to Steinhauer, California’s cybersecurity efforts are complementary to federal efforts led by the National Institute of Standards and Technology and the Cybersecurity and Infrastructure Security Agency.
Cleland said cybersecurity is, and needs to remain a federal initiative, and that he is wary of the idea of 50 separate state solutions for cybersecurity.
“What happens is you end up with what is a horrible idea for cybersecurity, which is 50 state solutions to a common problem of protecting information and infrastructure,” Cleland said. “People have been pushing for privacy legislation to be federal, and it's the exact same idea of privacy and cybersecurity.”
Cal-Secure 2.0 is not a spending program, according to the California Department of Technology. Cleland said that any money spent on Cal-Secure 2.0 initiatives would be better spent elsewhere.
“If federal standards already exist and we already have the market solving these problems, why do we need to throw Californians' money at the issue? It's already being done,” Cleland said. “It probably goes too far to say that this is a solution in search of a problem, but it doesn't go too far to say that this is probably taking the eye off the ball, and a waste of resources that could better be used elsewhere.”
The FBI reported more than 1 million internet crime complaints and losses totalling nearly $20.9 billion in 2025.
In his press release Gov. Newsom touted previous security advancements of unveiling privacy tools that allow Californians to block the sale of their data.
Cleland said that government agencies have to be 100% effective in combating cyber threats, so instead of expanding, they should be perfecting the securities they already use.
“It's kind of cliche, but the bad guys only have to be right once. In this case, the state government and the cyber defenses have to be right all the time, and that's not a small task,” Cleland said. “The state needs to nail what they're doing now, as opposed to adding more and more on that will inevitably just cause less and less attention to what they're already not accomplishing.”
The Center Square reached out to Gov. Newsom’s office but was redirected to the California Department of Technology. CDT did not respond by the time of publication.