California releases Cal-Secure 2.0 cybersecurity roadmap as AI threats accelerate

California releases Cal-Secure 2.0 cybersecurity roadmap as AI threats accelerate

California released Cal-Secure 2.0, a risk-based cybersecurity roadmap for state agencies facing AI-enabled threats.

Format News Brief
Read Time 3 min
Category Cyber Security
Updated Aug 03, 2026

California has released Cal-Secure 2.0, a new statewide cybersecurity roadmap meant to move its executive branch from a checklist-style security program toward a more flexible, risk-based model. Governor Gavin Newsom's office announced the update on July 31, describing it as the next phase of the state's effort to protect digital public services against faster-moving threats, including attacks assisted by artificial intelligence.

The plan matters because California runs some of the country's largest public-sector technology systems, touching benefits, health care, transportation, emergency response, licensing, taxes, and other everyday services. The governor's announcement says the updated strategy gives agencies practical guidance for identifying their biggest vulnerabilities, improving protections, and responding faster when incidents occur. It builds on California's first statewide cybersecurity strategy, launched in 2021.

What Changes In The Roadmap

The California Department of Technology describes Cal-Secure 2.0 as a multi-year roadmap for information security maturity across the executive branch. Instead of asking every department to follow the same compliance checklist, the new version is framed around risk management for agencies with different missions and systems. CDT says the strategy is organized around three pillars: people, process, and technology.

  • People: recruiting, training, and retaining cybersecurity workers across state government.
  • Process: improving coordination so agencies can share information and learn from incidents more quickly.
  • Technology: modernizing security tools while preparing for AI, post-quantum cryptography, and other emerging technologies.

The announcement also places AI-enabled cyberattacks at the center of the update. The governor's office says criminals are increasingly using AI to create convincing scams, exploit weaknesses, and target government and critical infrastructure systems. CDT's Cal-Secure page goes further, warning that AI-orchestrated attacks and sharply shorter exploit windows require a more adaptive defense strategy.

For state agencies, the practical effect is likely to be more emphasis on prioritization and shared standards. The governor's office says the roadmap lets agencies focus on the risks that matter most to their operations while still aligning around a statewide framework connected to national cybersecurity standards. That approach could help smaller or more specialized departments avoid treating cybersecurity as a paperwork exercise, while still giving central technology leaders a common way to measure maturity and coordinate response.

The release does not itself announce a specific breach, mandate, or new procurement. Its significance is strategic: California is updating the way one of the largest U.S. state governments organizes cyber defense at a moment when public agencies are being asked to secure aging systems, adopt AI tools responsibly, and maintain critical services under increasingly automated attack pressure.

Sources

Cover photo by Samon Yu on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...