• 5 mins read
  • Published

California's Former CISO Reflects on Cybersecurity Challenges in Government

Nina Halbrook Business & Technology Writer Farmington Voice

Post by Nina Halbrook

California's Former CISO Reflects on Cybersecurity Challenges in Government Farmington Voice © farmingtonvoice.com
California's Former CISO Reflects on Cybersecurity Challenges in Government © farmingtonvoice.com

After two decades in California state agencies, Vitaliy Panych discusses the evolution of cybersecurity, the launch of Cal-Secure, and the growing risks facing public sector organizations as technology and AI reshape government operations.

After nearly 20 years working in California state government, Vitaliy Panych, the state's longest-serving chief information security officer, has transitioned to a new role as senior cybersecurity and risk advisor at World Wide Technology. Panych's tenure included overseeing cybersecurity for more than 140 executive branch agencies and helping to develop Cal-Secure, California's first multi-year cybersecurity roadmap.

Panych recently spoke with Route Fifty about the changing landscape of technology in government, the increasing complexity of cyber threats, and the importance of risk management across public sector organizations.

Building a Culture of Risk Awareness

Panych emphasized that technology is now deeply embedded in every aspect of state government, from delivering benefits to supporting public safety. While this integration brings efficiency, it also introduces new risks. His approach as CISO was to encourage all staff to become "risk practitioners," understanding both the benefits and vulnerabilities that come with adopting new technologies.

He worked closely with security teams across state agencies to help them measure, manage, and mitigate risk. The Cal-Secure roadmap, first released during his tenure, provided a unified framework for cybersecurity across California's vast network of agencies, cities, counties, school districts, and special districts. The roadmap's second version, released last month, now includes strategies for managing risks associated with artificial intelligence.

Responding to Evolving Cyber Threats

California's decentralized government structure means many organizations operate independently, making coordinated cybersecurity a challenge. To address this, Panych helped establish the California Cybersecurity Integration Center, which supports agencies not directly under state authority by coordinating incident response and sharing threat intelligence. The state's Security Operations Center monitors daily cyber activity, providing actionable information to help agencies respond to vulnerabilities and threats.

Over time, California's cybersecurity efforts have shifted from reactive to proactive, with continuous risk assessments and validation of security controls. Panych noted that cyber threats evolve rapidly, requiring constant testing and adaptation of defense mechanisms.

The Changing Role of the CISO

Panych described the CISO role as increasingly focused on program management and relationship-building, rather than just technical expertise. He compared it to a medical director who must understand both clinical details and organizational strategy. Modern CISOs must communicate risk in terms that resonate with agency leaders and legislators, ensuring that cybersecurity supports each organization's mission and public service goals.

Balancing Modernization and Security

As government agencies modernize their services and rely more on technology, Panych stressed the need to align cybersecurity with each department's mission. This includes managing not only technical risks but also workforce challenges, such as supporting legacy systems with shrinking staff. California has introduced services like a virtual CISO program to help agencies address workforce shortages and implement risk mitigation projects as needed.

Legal liability, public perception, and user experience are also part of the risk equation. Security controls must be designed to protect systems without hindering public access to essential services.

AI's Impact on Cybersecurity

Panych sees artificial intelligence as a long-term benefit for government operations, though it brings short-term challenges as standards and best practices evolve. AI is already improving efficiency in security operations, such as reducing alert triage times and identifying software vulnerabilities more quickly. However, threat actors are also using AI to craft more convincing phishing attacks, increasing the urgency for agencies to adopt real-time threat management practices.

For additional perspective on how governments are addressing data security and privacy, see this recent report on safeguarding government data sharing.

Lessons and Future Challenges

Reflecting on his time in state government, Panych advised agencies to focus on scalable security solutions and leverage automation to compensate for limited staffing. He highlighted the importance of partnerships with vendors and the broader public sector to improve efficiency and resilience.

Looking ahead, Panych warned that AI-driven cyberattacks are accelerating, requiring state and local governments to move beyond traditional monthly patch cycles and adopt continuous, real-time threat management. Basic practices like patch management, asset inventory, and exposure management must now be performed at a much faster pace to keep up with evolving threats.

California's approach to cybersecurity demonstrates the complexity of protecting public sector systems in an era of rapid technological change. As agencies across the country modernize, the lessons from California's experience offer valuable guidance for managing risk and safeguarding essential services.

Related Stories