
The democratization of technology is ordinarily c…
Loading summary
A
Hello, you're listening to State Scoops Priorities podcast. I'm Colin Wood, State Scoops Editor in Chief. For this week's episode, I interviewed Sarah Pawasik and Grace Mena, who work on the Public Interest CyberSecurity Initiative at UC Berkeley's center for long Term Cybersecurity. They had a lot to say about how frontier AI models are heaping an additional cybersecurity burden onto those organizations perhaps least equipped to handle those responsibilities. But first, here are the top stories this week. The nonprofit Earth Fire alliance this month launched three new satellites, which will soon be used by emergency managers to monitor for wildfires. They'll spend three months undergoing testing before entering service and providing far more frequent updates in fire prone regions. Arizona has launched two new locations for its Regional Security Operations center initiative, operated out of community colleges in the Phoenix area. They're hoped to provide additional cybersecurity services and bolster the state's cyber workforce pipeline. Pennsylvania's health department this week launched a new data dashboard to help the public stay apprised of measles cases. The state's health secretary said the dashboard boosts access to information and increases government transparency. The democratization of technology is ordinarily considered a good thing, but as AI models become more powerful, people working in cybersecurity in particular have raised concerns about what it is doing to the threat landscape. The availability of models that can find vulnerabilities in software and rapidly exploit them is troubling for even the most powerful governments. But for the little guy, the cities, towns and small public utilities, researchers at the center for Long Term Cybersecurity said it's an especially onerous threat and one that's too often going unspoken.
B
So I'm Sarah Balazik. I'm the program director of Public Interest CyberSecurity at the UC Berkeley center for Long Term Cybersecurity. And really what we're concerned about is that there's a big chunk missing from the conversation right now around cybersecurity and AI, and that is the that AI capabilities are exacerbating existing problems with the cybersecurity space. And the result of that is that a lot more threats and impacts are going to fall on the least resourced organizations in the US So we spend a lot of our time thinking about what services people rely on for daily life. You know, where do they get married, what do they rely on for food, school. So we spend a lot of our time focused mostly on the smallest organizations in the US So schools, cities, towns, nonprofits and small Utilities like electric co ops and wastewater facilities, they're technically not the focus, they don't make front page news, but they're really, really critical for people's just everyday life. And the way that AI is impacting those small organizations is very, very different than the conversation going on at the national level, which is mainly focused on export controls and US China relations. What we're really thinking about is how are everyday people gonna be using this and how is it gonna impact how their ability to go about their daily lives? So what we're most concerned about with AI, and specifically models like mythos and chatgpt 5.5 cyber is two things. The first is that AI is going to exacerbate existing inequities for those small organizations. So we can already see that these models are able to identify vulnerabilities at a much faster speed. And even though small organizations are already experiencing cyber attacks, we expect that this is going to mean they're going to face more and more and more attacks with the same amount of resources that they've always had. This is not a new problem, but we do expect that it's going to really exponentially increase the amount of load that they're expected to carry and the responsibility that they have to defend themselves against threat actors that are now armed with AI that will make it much faster, much easier for them to carry out attacks. This is not new, but what we're concerned about is that we're not talking about how that responsibility is going to fall primarily on these small organizations that maybe they don't have full time IT and cybersecurity staff, they probably don't have a very large cybersecurity budget, if they have one at all. And what that means is that the resilience of our communities is actually decreasing because we're not investing in what it's going to take to protect them in this new paradigm of huge, huge volumes of attacks all the time. The second way that we're concerned about AI impacting the safety and security of community organizations is that these community organizations themselves are being encouraged to use AI tools. Everybody has tried out ChatGPT and Claude, everybody's playing around with these new tools. But the introduction of any new piece of software or tool is going to extend the attack surface of a community organization. And again, we're talking about organizations that probably don't have full time IT and tech staff. And AI is a tool just like any other piece of software that needs to be maintained. It needs to be implemented with the proper controls. Someone needs to think about what sort of data is being put into it. And there's an aspect of third party risk there. So because everybody's trying out these new tools and we're still figuring out what new risks those AI tools introduce into an organization's security environment that is again increasing the risk without necessarily providing new resources for them. So those are the two things that we're most concerned about at the community level.
A
Right. And this question is for either one of you or both, but what is your interaction like with these organizations? Do you do surveys? Do you just reach out to them like on a one off basis and tell them that you're, you want to know about their, their cyber policies which they may or may not even have? How does that, how does that work?
C
Yeah, happy to take this one. My name is Grace Mena. I'm a Senior Fellow of Public Interest CyberSecurity at the UC Berkeley center of Cybersecurity. I work alongside Sarah on many of our projects and initiatives. CLTC engages with states, policymakers and leaders of different programs at the state level that are attempting to help bridge this gap that we're seeing a few different ways. The first is that we convene these folks all together in the same room through our regular convenings. This year we're holding three Cyber Civil Defense summits which are an opportunity to bring together state CIOs, CISOs, leaders at the city and local level for cyber, alongside community organizations and other volunteering programs that are helping to bridge this gap, to work alongside each other, share best practices and really build that connective tissue both between folks already in the states themselves and between states one to one, so that states are learning from each other and helping share best practices and lessons learned from the policies and programs that they're helping to spin up. So we are meeting three times this year. We had our first summit in Scottsdale, Arizona in May. We have our next one in New Jersey this coming August and then our third one will be in Louisiana in October. And these are all co hosted alongside either state government agencies like the Department of Homeland Security or the integration Cell Agency NJ kick in new JERs or the and Louisiana. Actually we're co hosting with the Louisiana State University as well as the State Guard Cyber Reserve Team which we're really excited about. So that's the first way CLTC engages and helps to spread these different programs. The second is we do research. We released a guidebook earlier this year that Colin so kindly actually covered in some reporting earlier this year that we engaged with state policymakers, state CISOs and then leaders of state cyber volunteering programs to better understand what programs each state have currently right now. And by programs I mean cyber defense programs. So states right now are really taking up the gauntlet for cyber defense for community organizations and they're trailing some really interesting models, all kind of in line with this whole of state cybersecurity model that we talk a lot about in this field, which is the idea that the status quo, that community organizations, state and local organizations should not be left to their own, there should not be left on their own to defend themselves against really well resourced actors like cybercriminal groups and nation state actors. And so they're trialing some really interesting programs. And so we learn about these programs through surveys that we put out. We do a ton of interviews with different policymakers and leaders to better understand these programs. And then we also just meet regularly with, with leaders of the cyber volunteering programs at the state and local level. Different states are trialing as a, as a possibility to help defend communities.
B
It adds just really quickly, Colin, to we help manage a number of human networks that operate nationwide that are doing hands on engagements with these community organizations. So one of those is the consortium of cybersecurity clinics where students will go out and do risk assessments in the community. The other is the Cyber Resilience Corps, which is a collection of state and nonprofit volunteering organizations. So we run these networks that go door to door basically in different communities offering free cyber cybersecurity services. And so we hear a lot from these folks in different areas of the country, what's actually happening on the ground, what sorts, and they help us separate the tough, you know, what tools actually work, what are actually people using AI for and what is not useful for them. And that informs our research and the sort of advocacy that we do.
A
Right, and I'm glad you brought up your report, Grace. That's where we were headed next, I'd hoped. So I think it would be helpful. I think most people have heard of a security operations center or a cyber corps or whatever else. I think it'd be helpful to, because they are, as you so thoroughly outlined in your report, there are important distinctions between all of them. Can you start by defining those to some extent?
C
Yeah, absolutely. So the title of my guidebook research paper that I released earlier, now it's come to me, it's Save Money, Build Talent and Defend Communities. And we really did a deep dive on these three programs that we kind of mapped out in this research report. And those are State Cyber Corps, which are volunteer based organizations that are run usually through a state agency that bring skilled volunteers to community organizations. And they can do both incident response and also proactive services. And so these are volunteers that already are skilled in cyber that are then being basically matched and in a reserve program should there be some sort of need for from community organizations or public entities to respond to an incident or create proactive services. So right now there's about 900 of these volunteers across these state cyber programs in the US There are six active ones in the states right now. They're in Louisiana, Maryland, Michigan, Ohio, Texas and Wisconsin. And interestingly enough, New Jersey, Oklahoma and the state of Washington are also in the process of standing up programs right now. But these programs, the state Cyber Corps in particular, are surge capacity that you cannot otherwise buy. So for example, a Wisconsin county lost its entire network and backups to ransomware. Wisconsin Cyber Response Team, which is that state reserve deployed on site, they preserved forensic data and rebuilt the core infrastructure with multi factor authentication, immutable backups. And then they stayed for the long haul doing assessments, exercises and a penetration test. So it's essentially incident response plus rest lasting resilience. The second type of program that states are running are university Cyber clinics, which Sarah mentioned earlier that at here at UC Berkeley cltc we help run the consortium of cybersecurity clinics, which is essentially the network of these programs across the country. These are university based cyber clinics that are bringing students, sometimes that have skills coming into them and sometimes that don't, and training them to go and be matched with community organizations. Usually the majority of them are nonprofits, but also can be public utilities, any other sort of community organization that's local to their area and provide proactive risk assessments and so helping through that face to face engagements with these organizations to help harden their defenses proactively. And then the third are RSOC programs which are known as Regional Security Operation Centers. They're essentially the idea built on the idea of soc. So a lot of states currently run soc, so security operations centers that monitor and essentially help mitigate any sort of threat that will come in. So these RSOC programs are essentially students staffed 247 monitoring locations. So students learn hands on experience on how to monitor different endpoints. Right now the state of Texas has really been a leader right now. One RSOC in Texas can monitor up to 22,000 devices at one time. There's one at Angelo State University which has 60 students a year. And now Texas has three. Our SOC programs serve over 65 counties across West Central and South Texas, which is a huge deal. And these programs, right, are not just really great pipelines for workforce development on the state and local level for building cyber talent, but they also save a ton of money for states. So we did a bunch of research earlier this year on how much money we projected these programs to be saving states. And a couple of quick stats for you. One RSOC program can generate between 1.1 and 2.6 million doll year and economic value for state Cyber Corps programs, that number can be even higher, mapped in our, in our research that it can be 747% return on investment for one program, which is a really staggering number. So for I believe most programs run on about a million dollar budget a year and they can produce up to 8,8 million dollars a year of economic value for states, which is incredible for a return on investment. And this is money that otherwise potentially would be utilized by states for responding to an incident or dealing with cyber insurers. And the process that goes with, goes with that. So it's a really, really interesting set of models that states are deploying. And these programs work best when they're all together. They each have different strengths and weaknesses. In the report, we liken these programs to being fire disaster prevention. So each of the programs kind of work great independently, but they are amplified when they are working in concert together. So we liken the RSOC programs to being essentially your smoke alarms. They're looking out for any sort of intrusion or thing that smells, smells like fire and then can notify folks when there's something going wrong. The university clinics are your maintenance crews. They're going in to these organizations proactively and fixing things that are potentially, potentially maybe not safe or that could open them up to risk before the fire breaks out. And then these state Cyber Corps programs are your volunteer fire department. So they're able to go in and respond to a fire if it breaks out and then also are able to conduct safety inspections ahead of time and afterwards to make sure that these community organizations are doing the most. But these programs are really incredible. Sarah, anything to add?
B
Yeah, just one quick point. I think Colin, the reason why we're so invested in volunteering programs and university based programs and these state led programs that are, are basically networks of people is that humans are still the best way to deliver cybersecurity defenses and solutions at scale. I think that there's a big argument that's being made right now that AI is going to make people obsolete. And cybersecurity is really an area where we don't see that happening in particular, we see that humans alongside cybersecurity tools and expertise and advice and toolkits make those tools more effective. For example, a study that we love by the Cyber Readiness Institute found that a water utility working with a human coach was three times more likely to complete a cyber resilience program than if they tried to do it by themselves. It's this resource issue that we're talking about. If an organization has no budget, has no in house expertise, you can throw all the tools and toolkits and free stuff at them that you want, but they're not going to be able to understand it, to chew on it, to ask someone questions, and end up actually internalizing it and using it in the long run. And we believe the same is true for AI. So we think really that investing in these human networks will make communities more resilient so that if any new tool comes out, AI, cybersecurity, what have you, they have somewhere to turn to ask questions, they have somewhere to get a risk assessment. We really think that these state led, university led human networks are going to be absolutely critical in an age where AI is finding bugs faster than anyone can patch them. You really need somewhere to turn, a friendly face to call that you trust that's going to be able to provide you advice.
A
Yeah. Do you think? We started off talking about these advanced AI models and I think the threat is fairly obvious to anyone just watching this space. As I see it, the what we're talking about is a threat that was always there, there was always the risk. We knew there's vulnerabilities out there. It was just a matter of someone finding them and then if they can exploit them before they get fixed, then that could potentially be a problem for you. As you guys see it. Is the issue of AI and cybersecurity one of simply amplifying the. That that challenge that I just described, or is there something sort of distinct about its character?
B
I think at this point it is exacerbating existing inequities within the cybersecurity space. And what I mean by that is that cybersecurity has always been a space that's very asymmetric in favor of attackers. It's much easier to break something than it is to defend it. And it appears that the benefits of AI right now are going to offensive security experts and threat actors before the defenses become widely available. This is not surprising, but it is concerning in that the impact of that is falling on the folks who don't have enough money. Who don't have enough resources to defend against those attacks. I think we're in a weird period where we're waiting for the defenses to scale just as quickly. I think there's a lot of opportunity for startups and for companies in the cybersecurity space to use AI to make their products better. In our realm, we are particularly hopeful that it will make them cheaper and that it will help folks basically automate the basics faster. We really still struggle with MFA vulnerability scanning and patching and identity access management. Like really just the basic cyber hygiene. If we could implement those across the board nationwide, we would be much more resilient to any sort of cyber attack that's occurring. And the fact that we're introducing more complexity and more attacks before we've gotten that baseline is what we're most concerned about. So yes, it is changing attacking and defense sort of in different ways, but because it is asymmetric at this point and we still haven't bulked up the defenses, we really see it driving a lot of the inequity that we're already seeing in the cybersecurity space.
C
And there's also a data governance piece of this too. So we're seeing community organizations, some of them are adopting these generative AI tools because they're understaffed.
B
Right.
C
And these tools are useful, but they're doing so without any sort of data governance policies or understanding what kind of data they're exposing to third party models. So, right. You've got both AI being weaponized by attackers and also creating ungoverned data exposure internally within these community organizations, which often are handling very sensitive data. So interestingly, there's a few clinics of these university cyber clinics that are starting to lead on this and are integrating AI risk guidance directly into their assessments to help bridge that education piece with the community organizations they serve, helping them understand that, you know, they're not only as vulnerable as they were before, if not more, to these basic things that Sarah just outlined. Right. You know, patching other sorts of problems that are, that are rife in under resourced organizations. But there's also this data governance piece they have to think so think about. So this is sort of the natural evolution of the clinic model that we're seeing. Right. The threat landscape is shifting. Clinics are also kind of shifting and thinking about how AI plays a role in this as well, because they're built on human expertise and not static tooling.
A
Yeah. And to and to Sarah's point about the cost, I think that's largely where the Whole of state idea came from. Right. That's why we're seeing that is the idea. Hopefully they won't have to worry about that so much. If, if states can really continue bolstering or you know, kind of shoring up those programs. Are there any other you, you guys have mentioned numerous ex of these different organizations, Are there any outstanding examples that you think exemplify their value?
C
The volume of the incidences that these programs are handling is quite staggering. I was speaking with a leader of one of these programs of the state Cyber Corps programs earlier this year and they were saying to me that the volume of calls for service that they had received earlier this year within a one month period was more than they had ever received over the years and years and years that it's been under operation. So the need for these services, the demand for these services is there. Community organizations are calling these programs and the programs are stepping up at staggering levels. Like I mentioned earlier, some of these programs are delivering, you know, 700% return on investments which is directly going out into these community organizations and helping harden these defenses. There's really an interesting pipeline that's happening now as well where students that are going through university clinic programs or RSOC programs are then really well equipped to then go on and join a state cyber corps. And so it's kind of creating this life cycle essentially of catching these talented students and talented cyber technicians and experts at every stage of the pipeline and also building this resilience and this talent pool locally rather than having to try to outsource it. So creating this resilience and local talent is really key for communities ability to respond to these incidents. Sarah, any other ones that come to mind really quickly?
B
Yeah, there's a couple from the university clinics that stand out to me. One of my favorites is these are not going to be examples that are like earth shaking, but they're a real proof of value at the community level. One of my favorites is that the cybersecurity clinic at Indiana University did an assessment for their local fire department and there was this great video of them in the fire truck talking to the firemen about cybersecurity. And it was just such a good example example of how useful it can be in spaces that probably don't have full time it and cybersecurity staff and the students had the best time. You know, they get to hang out at a fire truck, hang out at the fire station, learn how to apply the knowledge that they had in school to something that they felt was useful. Other things that stand out Are, you know, students getting to do assessments for nonprofits and then that nonprofit hires them out of school to be their full time IT and cybersecurity staff really exemplifies how working with maybe the lowest common denominator, like basically the most challenging environment you can find, you're the only staff person you have to handle. All the technology really trains students to be extremely capable cybersecurity experts in any situation. So like Grace was saying, you know, it trains good public servants, it helps the community. There's just a lot of, like, small stories of students making impact, getting jobs, changing their career. We had a student come through who was at pre med school and they did a clinic and they're still going to go be a doctor. And we're thrilled because they're going to be a doctor that understands password security and data security and hipaa. That is a huge win for us. Like, everybody needs some level of cybersecurity education.
A
Right? Right. It's like it's almost, I mean, I think we take it for granted just because it's so ubiquitous, but it's like there's a war on. You better know something about, I don't know, taking a weapon apart, you know.
C
Yeah, yeah, absolutely, absolutely. And it's, and it's getting more and more important as time goes on. There's a great story that the folks from Wisconsin were telling me from this year where earlier last year, one of their local school districts gave them a call out of the blue and said, hey, there's this funny screen in Russian popping up on one of our laptops. This is interesting. Like, no one from our, from our department or from the school, you know, said anything, can you, can you help us and tell us what's going on? And so they were able to deploy a few volunteers. And lo and behold, there was something that was from a Russian criminal group, some malware on. From a Russian, Russian criminal group on one of their laptops and devices. And the volunteering court was able to help mitigate that problem and prevent that malware from spreading in that school district. And this was a very small school district with very low resources. They didn't know who else to call, but they knew that they, this cyber volunteering corps at Wisconsin was there and was incredible. And they had incident responders and they were able to respond to that incident without shutting down a school district from having to deal with a malware incident. And then on top of that, also having school districts and other sorts of community organizations know and have the trust, they can just call Somebody if there's something funky going on is enormous. Right. Having that trust that, hey, something's not feeling right or looking right. I'm not sure that it's a full blown incident yet, but I want to check in before things get really bad. Can be the make or break between whether or not essential services continue or are disrupted.
A
Yeah. Now I think we've spent most, most of this interview talking about these different state run cyber organizations. Are there any other aspects of the, what you think, what you guys think is the solution or the challenge that we're looking at that doesn't involve that, that we ought to just give an honorable mention to here at the end?
B
Yeah, I would say that folks are really focused on what's going on at the federal level. And I mean, we're here talking to State Scoop like we're very invested in what's happening at the community level. And one of the biggest things that folks are missing is just how much policy making on cybersecurity and AI is happening at the state level. We released a report earlier this year that was a roundup of all the pieces of cybersecurity legislation in the US at the state level in 2025. And it was exceptional. I mean, there's such a wide range of technology policy issues that states are expected to legislate on. Congress has pulled way back on technology legislation, says a bit kneecapped with all the departures and the lack of funding. And states are stepping up to sort of fill that gap. So I would call attention to a lot of the really incredible legislation that's been going on at the state level. I'm based in New York, so one of the things I'm most excited about is Governor Hochul recently released some minimum standards for water and wastewater facilities. And they also provided, I think, several million dollars in implementation funding so that organizations could actually go out and try and get the resources that they need to implement those standards. I think we need a lot more of that. I think AI is still, again, a huge problem. But how are we going to solve it? We're going to solve it by securing community organizations. There's a huge role that states can play in that, not only by doing what Grace was mentioning around setting up community support programs so that folks know where to call and folks have resources no matter how much money they have, but also trying to encourage best practices through legislation and providing the resources that those organizations need to actually implement those recommendations.
A
Nice. Grace, anything to add there?
C
I think just to foot stomp what Sarah was saying, we're really seeing states step up and also local leaders as well, really taking an interest in helping protect their community organizations. We're seeing at our convenings that we've been holding that there is a path forward where cyber leaders at the regional level, from universities, nonprofits, state governments, they're all banding together to create those ecosystems of cyber support. And that the service over tools piece of the puzzle is really gaining some traction. Right? At the end of the day, AI is exacerbating the problems that already exist and humans are the ones that are actually bridging that gap. And so setting up programs and building trust in communities, human to face to face, on how to protect each other and protect the services that we all rely on day to day is really key. And I think that we're starting to see states take up that philosophy of that we're not going to solve this problem just by products and tools. They certainly help. But at the end of the day, it's humans that are helping to help essentially fix this problem and strengthen and defend their communities.
B
Yeah, I would add one more thing, Colin, which is a question that we get a lot about our work is isn't somebody doing this? Like you're really telling me that if a cyber attack hits a school, like there's no one they can call? And we're like, yeah, they call the local police department. There's, there's no infrastructure there to help them. And so when we're talking about whole of state cybersecurity, what we really mean is that any organization should be able to protect themselves and recover from a cybersecurity attack and stay online, especially the ones that everybody relies on every day. And so state CISOs in particular CISOs and CIOs are really stepping up. It used to be that their position was really to only protect state infrastructure, state agencies. And nowadays we see a lot of state CIOs and CISOs stepping up into this role of actually I'm responsible for protecting all of the organizations within my state. How do I extend state resources to help protect those organizations? So I think the role of the CIO and CISO is changing in state agencies and trying to expand that responsibility because really no one else is stepping up to protect these organizations and someone has to.
A
A big thank you to Sarah Pawasik and Grace Mena for sharing their expertise and insight with our our audience. That's it for this episode. The Priorities podcast is a production of Scoop News Group in Washington DC. Production work is done by Carlin Fisher. I'm Colin Wood. Thanks for listening.
Host: Colin Wood, StateScoop
Guests: Sarah Pawasik (Program Director, Public Interest Cybersecurity, UC Berkeley Center for Long-Term Cybersecurity), Grace Mena (Senior Fellow, Public Interest CyberSecurity, UC Berkeley Center for Long-Term Cybersecurity)
Date: July 15, 2026
This episode delves into the rapidly evolving threat landscape in cybersecurity due to advances in frontier AI models, particularly focusing on how these advances disproportionately burden small organizations like schools, towns, nonprofits, and utilities. The discussion highlights the unique challenges faced by these resource-constrained organizations, explores the gap between national cybersecurity priorities and local realities, and examines promising state-led approaches for defense and resilience.
"AI is going to exacerbate existing inequities for those small organizations... They're going to face more and more and more attacks with the same amount of resources that they've always had."
(Sarah Pawasik, 02:49)
"The introduction of any new piece of software or tool is going to extend the attack surface... and we're still figuring out what new risks those AI tools introduce."
(Sarah Pawasik, 04:54)
"We run these networks that go door to door basically... offering free cybersecurity services. We hear a lot from these folks in different areas of the country, what's actually happening on the ground."
(Sarah Pawasik, 08:53)
"These programs work best when they're all together... like fire disaster prevention: smoke alarms (RSOCs), maintenance crews (clinics), and volunteer fire departments (Cyber Corps)."
(Grace Mena, 14:25)
"Humans are still the best way to deliver cybersecurity defenses and solutions at scale... If an organization has no budget, has no in house expertise, you can throw all the tools... at them that you want, but they're not going to be able to understand it."
(Sarah Pawasik, 15:37)
The fundamental asymmetry of cybersecurity remains: attacking is inherently easier than defending. AI dramatically accelerates offensive capacity, but defenses—especially for under-resourced groups—are lagging.
"It appears that the benefits of AI right now are going to offensive security experts and threat actors before the defenses become widely available."
(Sarah Pawasik, 18:18)
Hopeful note: If defensive AI (e.g., automating basics like MFA and patching) becomes widely accessible and affordable through local programs and legislation, the tide can shift.
Many community organizations deploy AI tools without policies for data privacy or third-party risk, unwittingly exposing sensitive information.
"They're doing so without any sort of data governance policies or understanding what kind of data they're exposing to third party models."
(Grace Mena, 19:55)
Cybersecurity clinics are starting to embed AI risk management in their assessments, progressing beyond static tooling to education tailored to evolving threats.
"They didn’t know who else to call, but they knew this cyber volunteering corps was there... having that trust can be the make or break between whether or not essential services continue or are disrupted."
(Grace Mena, 24:47)
"There's such a wide range of technology policy issues that states are expected to legislate on... states are stepping up to sort of fill that gap."
(Sarah Pawasik, 26:48)
Local and state CIOs/CISOs recognize their role now extends beyond state networks—they’re working to protect every critical organization in their states, often for the first time.
"We really see it driving a lot of the inequity that we're already seeing... we haven't bulked up the defenses, so it is changing attacking and defense in different ways."
(Sarah Pawasik, 18:18)
Programs emphasizing service and trust—rather than just products—are making headway, fostering resilient ecosystems of cyber support rooted in local communities.
"Service over tools... At the end of the day, AI is exacerbating the problems that already exist, and humans are the ones that are actually bridging that gap."
(Grace Mena, 28:28)
This episode underscores the urgent and overlooked challenge facing the local fabric of American society: AI supercharges cyber threats just as small, critical organizations are being asked to do more with no additional resources. Effective defense will require a blend of policy innovation, investment in local human networks, and continued focus on service, trust, and education—not just technology or products. The guests highlight a nationwide momentum toward collaborative, human-centric solutions that both build talent and fill critical security gaps—redefining the frontline of cybersecurity in the age of AI.