California is taking a significant step forward in protecting its residents and infrastructure from evolving digital threats. Governor Gavin Newsom has announced the release of Cal-Secure 2.0, the latest update to the California cybersecurity plan. This new phase of the state’s cybersecurity strategy is designed specifically to counter the growing risk of AI-powered cyberattacks, building on the foundation laid by the state’s first cybersecurity plan introduced in 2021.
What’s New in Cal-Secure 2.0 Compared to the 2021 Strategy?
The updated strategy introduces practical tools, guidance, and a sharper focus on emerging threats, giving agencies more flexibility to address their unique risks. While the 2021 plan set the initial framework, Cal-Secure 2.0 refines that approach by offering concrete resources rather than just broad recommendations. For anyone tracking the California cybersecurity plan, the shift from theory to actionable support is the clearest change.

Three Core Priorities of the Updated Plan
Cal-Secure 2.0 centers on three main priorities: workforce, coordination, and technology modernization. Under workforce, the strategy aims to help state agencies build and retain skilled cybersecurity teams—addressing a persistent shortage that can slow down even the best security postures. The coordination priority focuses on improving how agencies share threat intelligence and respond to incidents together, reducing silos that previously left gaps. Technology modernization pushes for replacing outdated systems with more secure, efficient alternatives, making it harder for attackers to exploit legacy vulnerabilities.
Flexibility in Risk Management
A key difference between Cal-Secure 2.0 vs 2021 strategy is the flexibility agencies now have. Instead of a one-size-fits-all mandate, each agency can prioritize its most critical risks. This means a smaller department can focus on basic state agency cybersecurity tools like multi-factor authentication and data encryption, while a larger agency might dedicate resources to advanced threat detection systems. The result is a more practical, scalable approach that respects the diverse operational realities across California’s government.
These cybersecurity priorities California emphasizes—workforce, coordination, and modernization—don’t just defend against today’s threats; they position the state to adapt as new challenges emerge. By providing clear tools and granting flexibility, Cal-Secure 2.0 turns the 2021 vision into a living, workable plan.
How Cal-Secure 2.0 Protects California Residents from AI-Powered Cyberattacks
As that living plan takes shape, one thing is clear: cybercriminals are not standing still. They are using AI to target government systems and critical infrastructure with increasing frequency and sophistication. The California cybersecurity plan meets this challenge head-on by focusing on the most pressing threat of the moment—attacks that leverage artificial intelligence to bypass traditional defenses.

Cal-Secure 2.0 includes specific measures to protect against AI cyberattacks California residents may face. These attacks can automate phishing attempts, mimic legitimate communications, or exploit vulnerabilities faster than ever before. The strategy recognizes that resident data protection must evolve alongside these tactics. It doesn’t just patch old holes; it builds smarter defenses that can detect and respond to AI-driven intrusions in real time.
The Role of the Delete Request and Opt-out Platform (DROP)
A key piece of this resident data protection puzzle is the Delete Request and Opt-out Platform (DROP). You might wonder how a data deletion tool relates to cybersecurity. The connection is direct: the less personal data stored in government systems, the smaller the target for attackers. DROP gives you a straightforward way to request removal of your information from state databases. This reduces the risk of data exposure and misuse, especially if a system is compromised by an AI-powered attack. By shrinking the surface area for potential breaches, DROP acts as a preventive cybersecurity measure that puts you in control.
Protecting Critical Infrastructure
Beyond individual data, Cal-Secure 2.0 hardens the systems that keep California running—power grids, water supplies, transportation networks, and emergency services. These are prime targets for attackers using AI to find weak points. The plan requires these agencies to adopt advanced threat detection tools that can spot abnormal patterns, such as an AI-generated command trying to mimic a legitimate operator. It also mandates regular drills and updates to ensure defenses stay ahead of evolving tactics. For you, this means greater confidence that the water you drink and the traffic lights you rely on are protected from AI-driven disruption. The DROP cybersecurity platform is just one part of a broader effort to make California’s infrastructure resilient against the next generation of cyber threats.
Workforce, Coordination, and Technology Modernization: The Three Pillars
Protecting critical infrastructure goes beyond any single platform, which is why the next phase of the California cybersecurity plan rests on three foundational priorities. Cal-Secure 2.0 is built around building a skilled workforce, improving coordination between agencies, and modernizing the technology those agencies rely on. The strategy provides state agencies with practical tools and guidance, so they can move from reacting to threats to staying ahead of them.

Recruiting and Training the Next Generation of Cyber Workers
One of the biggest hurdles California faces is simply finding enough qualified people to fill cybersecurity roles. The demand for skilled professionals far outpaces the supply, and state government competes with the private sector for the same talent. The updated plan tackles this head-on by investing in training programs and career pathways specifically designed for public sector work. If you are considering a career in tech, this emphasis on cybersecurity workforce California could mean more opportunities to get hands-on training and certifications without needing a traditional four-year degree. The goal is to build a pipeline of talent that can grow with the state’s needs.
Enhancing Coordination Across Agencies
Cybersecurity threats do not respect organizational boundaries, so neither can the response. A key piece of the plan is improving state agency coordination so that information about threats, vulnerabilities, and best practices moves quickly between departments. This also extends to federal partners, creating a more unified front against attacks that might target multiple levels of government at once. Better coordination means fewer silos and faster reactions when something goes wrong. For you as a resident, that translates into more reliable public services and a quicker recovery if a breach does occur.
The third pillar, technology modernization government, focuses on replacing outdated systems that are harder to defend. Older software and hardware often lack basic security features, making them easy targets. By modernizing these tools and providing clear guidance, the plan helps agencies adopt secure, up-to-date solutions without needing to be cybersecurity experts themselves.
Aligning with National Standards and California’s Executive Orders on AI
This modernization effort doesn’t stop at tool upgrades. The California cybersecurity plan also connects to larger frameworks, ensuring that state agencies aren’t working in a silo. By aligning with national cybersecurity standards, the strategy helps you—whether you’re a state employee or a resident—benefit from practices that are recognized across the country. While the specific standards aren’t detailed in the plan, this alignment means California is better positioned to meet federal cybersecurity alignment requirements, which can simplify compliance for agencies that also handle federal data. It’s a practical move that reduces duplication of effort and creates a more unified defense.
On a similar note, DeepSeek Pauses Second Fundraising Round explores this topic with concrete examples.

Which National Standards Are Referenced?
The strategy aligns with national cybersecurity standards California, but it doesn’t name individual frameworks. Instead, it focuses on creating a cohesive approach that matches what other states and federal bodies are doing. This consistency is valuable because it cuts down on confusion for agencies that must follow multiple sets of rules. For you, this means a more uniform level of protection across state services, regardless of which agency you’re interacting with. It’s about making sure that the same security principles apply everywhere, so you don’t have to worry about gaps in coverage.
Connecting the Executive Orders to Cybersecurity
California signed Executive Orders in 2023 and 2026 on responsible AI, and these directly tie into the AI risk management aspects of the cybersecurity plan. The executive orders emphasize using AI in a safe and ethical way, which aligns with the plan’s goal of securing AI systems. By building on these orders, the California cybersecurity plan ensures that as agencies adopt AI tools, they do so with cybersecurity front of mind. This creates a cohesive framework where technology innovation and security go hand in hand. For you, this means that the AI services you use from the state—like chatbots or data analysis tools—are more likely to be protected against threats, thanks to this forward-looking approach. It’s a clear example of how policy and security work together to keep your data safe.
Implementation Challenges: Funding, Timeline, and Measuring Success
Given those practical protections, you might wonder when you’ll actually see the effects of the California cybersecurity plan. While Cal-Secure 2.0 outlines ambitious goals, key questions remain about how it will be funded, when it will be rolled out, and how success will be measured. At this stage, the strategy is more of a vision than a detailed roadmap.
Where Will the Money Come From?
No specific funding or budget details have been announced for implementing Cal-Secure 2.0. This is a significant gap. Large-scale cybersecurity initiatives require substantial investment—for hiring skilled personnel, purchasing advanced tools, and training existing staff. Without clarity on California cybersecurity funding, it’s hard to know how quickly the state can move from planning to action. You’ll want to watch for any budget proposals in upcoming legislative sessions, as these will determine whether the plan has the financial backing it needs to succeed.
When Will the Plan Be Put Into Action?
Similarly, no timeline or milestones for the rollout of the strategy have been provided. A Cal-Secure 2.0 timeline would help both government agencies and the public understand what to expect and when. Without deadlines, there’s a risk that important initiatives could stall or lose priority. In practice, this means you may not see immediate changes to how the state handles cybersecurity, even if the long-term goals are clear.
How Will the State Measure Results?
Finally, there is no mention of how the strategy will be enforced or measured for success. Establishing clear cybersecurity success metrics is essential for accountability. Without them, it’s difficult to know what progress looks like—whether that’s reducing breach response times, increasing security audits, or improving public reporting. For a plan to be truly effective, you need a way to track whether it’s actually working. These unanswered questions make the California cybersecurity plan a promising start, but one that still needs concrete details to fulfill its potential for protecting your data.
Frequently Asked Questions
What exactly is new in Cal-Secure 2.0 compared to the 2021 strategy?
Cal-Secure 2.0 builds on the original plan with a stronger focus on AI-powered threats and stricter data protection standards. The updated strategy includes new requirements for state agencies to adopt advanced threat detection tools and conduct regular security audits. It also emphasizes collaboration with local governments and private sector partners to create a unified defense against cyberattacks.
How does California plan to recruit and train enough cybersecurity workers?
The state is launching targeted training programs and partnerships with community colleges and universities to expand the cybersecurity workforce. These initiatives offer certificates and hands-on workshops to prepare you for roles in both public agencies and private companies. The California cybersecurity plan also includes funding for scholarships and apprenticeships to attract new talent.
When will the different parts of Cal-Secure 2.0 be put into action?
Implementation is rolling out in phases, with some measures taking effect immediately and others scheduled over the next few years. State agencies must begin adopting new security tools within the first year, while broader infrastructure upgrades will follow as funding becomes available. You can expect the most critical protections for personal data to be active within the first six months.






