Skip to main content

Cybersecurity statistics / Performance Metrics

49% of state CISOs name implementing effectiveness metrics as a top cybersecurity initiative, up from 25% in 2024 and 15% in 2022.

PublisherDeloitte
Report2026 NASCIO-Deloitte Cybersecurity Study
Published27 April 2026
TopicsPerformance Metrics, Public Sector, US

Published by Deloitte in 2026 NASCIO-Deloitte Cybersecurity Study, 27 April 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

43% of Public Sector organizations experience access revocation failures.
FIDO Alliance & HID, 20/06/2026
20% of Public Sector credential revocations are performed manually, which is more than double the manual revocation rate in the IT/Technology sector.
FIDO Alliance & HID, 20/06/2026
16% of state CISOs report their budgets have been cut, up from none in 2024.
Deloitte, 27/05/2026
63% of CISOs describe themselves as not very confident in the ability of local government and public higher education to secure public data, up from 35% in 2022.
Deloitte, 27/05/2026
Roughly one-fifth of CISOs indicate their states are moving toward a "whole-of-state" approach to cybersecurity.
Deloitte, 27/05/2026
Only 26% of state CISOs are extremely or very confident that their state's information assets are protected from cyber threats, down from 48% in 2022.
Deloitte, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.