Skip to main content

California Gazette

Governor Newsom Launches Cal-Secure 2.0 to Defend California Against AI Enabled Cyberattacks

Newsom Launches Cal-Secure 2.0 Against AI Cyber Threats
Photo Credit: Unsplash.com

Governor Gavin Newsom announced on July 31 the release of Cal-Secure 2.0, an updated statewide cybersecurity strategy designed to protect California’s government systems from artificial intelligence-enabled cyberattacks and other emerging digital threats. The updated roadmap builds on California’s original cybersecurity strategy launched in 2021 and provides state agencies with practical tools and guidance to secure the infrastructure that residents depend on for benefits, healthcare, transportation, and public safety. Cal-Secure 2.0 arrives at a moment when AI is fundamentally reshaping the cyber threat landscape, with criminals using generative AI to craft convincing phishing scams, exploit security weaknesses, and probe government systems at speeds that traditional defense tools struggle to match.

  • Governor Newsom released Cal-Secure 2.0 on July 31, updating California’s statewide cybersecurity strategy to address AI-enabled threats
  • The plan focuses on three priorities: building a stronger cybersecurity workforce, improving coordination across state agencies, and modernizing security technology
  • Cal-Secure 2.0 gives agencies flexibility to prioritize their specific vulnerabilities while operating under a common statewide framework aligned with national cybersecurity standards
  • The strategy builds on Newsom’s executive orders in 2023 and 2026 on responsible AI adoption and procurement, which included privacy and civil liberties protections
  • California has also launched the DELETE Request and Opt-out Platform (DROP) allowing residents to block the sale of their personal data by data brokers
  • A 2026 NASCIO-Deloitte survey found that only 22% of state CISOs nationally reported cybersecurity budget increases of 6% or more, down from 40% in 2024

The Three Pillars of Cal-Secure 2.0

The updated strategy organizes California’s cybersecurity priorities around three pillars: building a stronger cybersecurity workforce, improving coordination across government agencies, and modernizing the technology infrastructure that underpins state operations. Each pillar addresses a specific dimension of the challenge that state governments face as cyber threats become more automated, more targeted, and more difficult to detect using conventional tools.

The workforce component reflects a recognition that cybersecurity depends as much on human capacity as it does on technology. Recruiting, training, and retaining skilled professionals across state agencies has been a persistent challenge for government employers competing against private-sector salaries in one of the world’s most concentrated technology labor markets. For California, where state agencies operate alongside the headquarters of the companies building the AI tools that are simultaneously creating new threats and new defenses, the talent competition is particularly acute.

The coordination pillar addresses the fragmentation that has historically characterized cybersecurity across large state governments. California operates dozens of agencies and departments, each with its own systems, data flows, and vulnerability profiles. Cal-Secure 2.0 establishes a framework for information sharing and joint response that allows agencies to learn from incidents and adapt collectively rather than defending in isolation. California State Chief Information Officer and Department of Technology Director Chris Given described the plan as giving agencies practical guidance to strengthen security, adapt to new threats, and protect the services residents depend on.

The technology modernization component targets legacy infrastructure and prepares agencies for emerging threats driven by AI. Unlike the 2021 strategy, Cal-Secure 2.0 gives agencies flexibility to prioritize the risks most relevant to their specific operations while maintaining alignment with a common statewide framework based on national cybersecurity standards. California State Information Security Officer Vitaliy Panych framed the approach as helping every state entity understand its biggest risks, strengthen its defenses, and respond quickly when threats emerge.

The AI Threat Landscape Driving the Update

The timing of Cal-Secure 2.0 is not incidental. The 2026 NASCIO-Deloitte Cybersecurity Study, released in June, found that state chief information security officers across the country reported cyber threats that are more numerous, more varied, and more sophisticated than at any previous point. The study quoted one state CISO describing the acceleration: with the rising adoption of AI and agentic AI, the speed at which attacks are occurring is increasing at a pace that traditional defense models were not designed to absorb.

The national data paints a challenging resource picture alongside the escalating threat environment. Only 22% of state CISOs reported budget increases of 6% or more in 2026, a sharp decline from 40% in 2024. More concerning, 16% of CISOs reported outright reductions to their cybersecurity budgets, compared with zero in 2024. The top three barriers state CISOs identified were legacy infrastructure, increasing sophistication of threats, and insufficient funding. California’s Cal-Secure 2.0 addresses all three, though the state’s implementation will ultimately depend on sustained budget commitments through future fiscal cycles.

The specific AI-enabled threats that Cal-Secure 2.0 targets include generative AI-powered phishing campaigns that produce highly convincing messages at scale, deepfake fraud targeting government employees and processes, autonomous malware capable of adapting to defense measures in real time, and AI-driven reconnaissance tools that probe systems for vulnerabilities faster than human analysts can respond. For a state government that manages personal data, benefits distribution, healthcare records, and critical infrastructure for nearly 40 million residents, the attack surface is enormous and the consequences of a breach extend far beyond data exposure.

California’s Broader Data Privacy and AI Governance Framework

Cal-Secure 2.0 does not exist in isolation. The cybersecurity strategy is layered on top of a series of policy actions that Governor Newsom has taken over the past three years to position California as the national leader in data privacy, AI governance, and digital security. In 2023, Newsom signed an executive order preparing California for AI advancement. In March 2026, he followed with a second executive order strengthening responsible AI adoption and procurement across state agencies, with explicit protections for privacy and civil liberties.

On the privacy side, Newsom signed legislation requiring web browsers to allow Californians to opt out of third-party data sales across all websites in a single action rather than site by site. The state also launched the DELETE Request and Opt-out Platform, known as DROP, the first tool of its kind nationally that enables residents to block the sale of their personal information by data brokers. Separately, the California Privacy Protection Agency’s 18-component cybersecurity framework has been described by compliance analysts as a de facto national standard, as organizations across the country adopt California’s requirements as baseline practices rather than managing separate compliance regimes for each state.

The legislative pipeline adds additional layers. AB 979, currently moving through the California legislature, would require the California Cybersecurity Integration Center to develop a California AI Cybersecurity Collaboration Playbook modeled on a federal framework published by the Joint Cyber Defense Collaborative in January 2025. The bill is designed to facilitate voluntary information sharing across California’s AI community, including providers, developers, and adopters, strengthening collective defenses against threats that cross organizational boundaries.

Implementation and the Road Ahead

The operational challenge for Cal-Secure 2.0 lies in translating a statewide strategy into agency-level action across a government that employs hundreds of thousands of workers and operates technology systems of widely varying age and complexity. The plan’s emphasis on flexibility, allowing agencies to focus on their specific risk profiles rather than mandating a uniform checklist, is a structural acknowledgment that a one-size-fits-all approach does not work in a state government as large and diverse as California’s.

The workforce pipeline remains a critical variable. California state government competes for cybersecurity talent against private-sector employers headquartered in the same metropolitan areas, many of whom offer compensation packages that public-sector salary structures cannot match. The plan’s focus on recruitment, training, and retention signals that the Newsom administration views human capital as a rate-limiting factor, not just a line item. Whether the state can attract and hold the cybersecurity professionals needed to execute Cal-Secure 2.0 will depend on the competitiveness of the positions created and the professional development pathways offered within state service.

The full Cal-Secure 2.0 strategy is published on the California Department of Technology’s website. For a state that hosts the headquarters of companies building the AI systems reshaping the global economy, the cybersecurity challenge is both a matter of government operations and a reflection of California’s unique position at the center of the technology ecosystem driving the threats it is now working to defend against.

FAQs

What Is Cal-Secure 2.0?

Cal-Secure 2.0 is California’s updated statewide cybersecurity strategy, announced by Governor Newsom on July 31, 2026. The plan provides state agencies with tools and guidance to defend against AI-enabled cyberattacks and other emerging digital threats. It focuses on three priorities: building a stronger cybersecurity workforce, improving coordination across agencies, and modernizing security technology. The strategy builds on California’s original cybersecurity roadmap launched in 2021.

Why Is California Updating Its Cybersecurity Strategy Now?

Cyberattacks targeting government systems are becoming more frequent and more sophisticated, driven in part by criminals using AI to craft convincing phishing scams, deploy autonomous malware, and probe for vulnerabilities at speeds that outpace traditional defenses. A 2026 NASCIO-Deloitte survey found that state cybersecurity officers across the country reported threats that are more numerous and varied than ever before, while cybersecurity budgets are shrinking relative to the growing risk.

How Does Cal-Secure 2.0 Relate to California’s Other Data Privacy Policies?

Cal-Secure 2.0 is part of a broader framework that includes executive orders on responsible AI adoption (2023 and 2026), legislation requiring browsers to support one-click opt-out of third-party data sales, and the DROP platform allowing residents to block data broker sales of their personal information. The California Privacy Protection Agency’s cybersecurity framework has become a de facto national standard that organizations across the country are adopting as baseline practice.

California Gazette

Capturing the Golden State's essence, one story at a time.