California Gov. Gavin Newsom released an updated statewide cybersecurity strategy on July 31 to help executive branch agencies address artificial intelligence (AI)-enabled attacks, modernize security tools, and protect essential public services.
Cal-Secure 2.0 replaces the state’s compliance-focused approach with a flexible, risk-based framework that agencies can adapt to their missions, systems, and threat profiles. The five-year roadmap covers the state services Californians use for benefits, healthcare, transportation, and public safety, according to the governor’s press release.
The strategy builds on the original Cal-Secure roadmap released in 2021.
“Californians expect their government to protect not only their personal information, but also the essential services they rely on every day. As cyber threats evolve, California is evolving with them. Our strategy helps ensure our state stays ahead of emerging risks while continuing to deliver secure, reliable public services,” Newsom said in the press release.
Cal-Secure 2.0 is organized around three components – people, process, and technology – and includes 10 priorities and 15 initiatives. The plan was developed through more than 10 working sessions, over 500 working hours, and participation from more than 12 state entities, according to the state.
The workforce component calls for role-based training, standardized cybersecurity career pathways, faster hiring and onboarding, and improved communication skills for security professionals. Training would cover technical and leadership skills as well as the secure use of AI and agentic tools.
The process component focuses on statewide coordination, automated security metrics and reporting, continuous audits, and clearer incident escalation procedures. It also calls for a fast-track procurement pathway for vetted AI-enabled defensive technologies and stronger collaboration with local governments, federal partners, academia, and private-sector organizations.
Technology initiatives include strengthening protections for critical infrastructure and operational technology, expanding statewide threat intelligence sharing, preparing state systems for post-quantum cryptography, and accelerating vulnerability and patch management.
“Cyber threats don’t stand still, and neither can we,” said Chris Given, the state’s chief information officer and director of the Department of Technology. “Cal-Secure 2.0 gives state agencies practical guidance and tools to strengthen security, adapt to new threats, and better protect the services Californians depend on.”
Agencies can use the accompanying Cal-Secure 2.0 toolkit to assess their current security maturity, establish target capabilities, and prioritize improvements based on their missions, risk tolerance, critical systems, and protected data.