California updates statewide cybersecurity strategy for AI-era threats

Published On: August 5, 2026

Cal-Secure 2.0, an updated statewide cybersecurity strategy intended to help California agencies address increasingly sophisticated cyberattacks, including threats enabled by artificial intelligence, has been published by the California Department of Technology, Governor Newsom announced on Friday (7/31/26).

First released in 2021, the strategy provides state agencies with guidance for identifying cybersecurity vulnerabilities, strengthening defenses, and responding more quickly when incidents occur.

The updated version focuses on three priorities: expanding the state government cybersecurity workforce, improving coordination and information sharing among agencies, and modernizing security technology. The plan also directs agencies to prepare for emerging technologies, including AI.

Newsom said the update is intended to protect residents’ personal information and maintain the reliability of essential government services as cyber threats evolve.

“Californians expect their government to protect not only their personal information, but also the essential services they rely on every day,” Newsom said. “As cyber threats evolve, California is evolving with them.”

State officials said criminals are increasingly using AI to develop convincing scams, exploit security weaknesses and target government and critical infrastructure systems. The updated roadmap is designed to help agencies assess which risks are most significant to their operations and prioritize security improvements accordingly.

California Department of Technology Director and state Chief Information Officer Chris Given said the strategy gives agencies practical guidance for adapting to new threats.

“Cyber threats don’t stand still, and neither can we,” Given said. “Cal-Secure 2.0 gives state agencies practical guidance and tools to strengthen security, adapt to new threats, and better protect the services Californians depend on.”

The updated plan gives agencies more flexibility to focus on risks specific to their systems and responsibilities. Agencies will continue to operate under a common statewide framework aligned with national cybersecurity standards.

State Chief Information Security Officer Vitaliy Panych said the framework is intended to support improvements over time while maintaining a coordinated statewide approach.

“Our goal is simple: help every state entity understand its biggest risks, strengthen its defenses, and respond quickly when threats arise,” Panych said.

About the Author: Staff

Contact us, share tips and news: info@techca.org. Contributors to this site include writers, analysts and researchers who occasionally use AI tools to perform routine tasks, such as summarizing event transcripts and analyzing documents for grammar and spelling. Human editors are always in charge of articles posted here.