© 2026 WHRO Public Media
5200 Hampton Boulevard, Norfolk VA 23508
757.889.9400 | info@whro.org
Play Live Radio
Next Up:
0:00
0:00
0:00 0:00
Available On Air Stations

How Virginia keeps tabs on cybersecurity threats as AI takes hold

The Virginia Information Technologies Agency adapts and evolves its cybersecurity measures based on the threat environment.
The Virginia Information Technologies Agency adapts and evolves its cybersecurity measures based on the threat environment.

Faced with more sophisticated cyber threats — and with artificial intelligence rapidly altering the landscape — a survey shows that information technology security officials in the US are losing confidence that they can protect people's data.

This raises a crucial question: Should Virginians be confident that their data is secure? Chief Information Officer Mike Watson believes so.

"I think Virginia is in a really good place there," Watson told VPM News in an interview.

Watson, who leads Virginia's Information Technologies Agency, said the state is cautious about boasting about its cybersecurity capabilities, is aware problems can arise because "there is always a way in," and that people make mistakes.

"Somebody's going to click the link the wrong way," he said. "An administrator is going to have a bad day and not catch that that website isn't an actual legit website."

VITA serves 65 state agencies and 55,000 executive branch employees, providing cybersecurity and overseeing Virginia's IT projects. It helps connect Virginians to government services and keeps public data systems secure.

Earlier this year, cyberattacks on school systems and universities in Virginia disrupted students' work and raised concerns. Virginia's attorney general's office was hit with a cyberattack last year that, according to reports, took state attorneys off the computer system.

A survey of state chief information security officers, published in the 2026 cybersecurity study from the National Association of State Chief Information Officers and Deloitte & Touche LLP, paints a stark picture of data privacy.

According to the survey, only 22% of security officers said they were either "extremely" or "very confident" in their data privacy protections, compared to 48% of survey respondents in 2022.

When an attack happens, Watson said VITA needs to ensure that it can address the immediate risks and stop it from getting worse. Watson added that VITA's tools and structure are designed to both anticipate failure and contain what's going wrong.

Watson said the agency adapts and evolves its cybersecurity measures based on the threat environment, which he said has two main considerations: what the business risk is and what are attackers after.

"But we aren't foolish enough to think that we are uncompromisable," Watson explained. "We've got different layers of protection to make sure that remains possible."

VITA needs to ensure IT systems are operational and prepared for major emergencies, Watson said, so protecting against ransomware attacks and other targeted efforts are prioritized.

Some information, such as financial data published online by the Department of Accounts, "are not necessarily valuable assets or intellectual property," Watson said.

"We take a different approach on where our areas of risk are, and make sure that we protect our environment in a way that we are worried about the assets that are important and meaningful to our business and our citizens," Watson told VPM News.

The reported increase in cyberattacks has been attributed to bad actors targeting softer targets, such as local hospitals and businesses, that might not have robust IT security measures.

AI has also changed the frequency of possible threats that governments need to deal with. Notably, some AI models recently hacked into other AI platforms and companies on their own.

Watson called it a "rougher period" for IT security, one where VITA and others will see additional challenges because of AI driving more complex compromises to computer systems.

"I think the tools don't necessarily open up a lot of new types of vulnerabilities as much as they end up increasing the number of vulnerabilities," Watson said.

One example Watson gave are attacks that require access to a device or system, which typically exploit an existing weakness.

"That was a lower risk, comparatively, than something that somebody could from the internet reach out and take over your system," he told VPM News. "It is now more likely that someone's going to be able to chain a couple different attacks together to exploit that sort of lower-risk scenario that we had before."

The potential for more frequent attacks makes VITA "a little more nervous," Watson said, but he added that it doesn't change its response.

Despite this, Watson said the good news is that these issues should be temporary, as the technology is used to also fix vulnerabilities and those abilities are eventually built into the models.

In hopes of bolstering VITA's cybersecurity infrastructure, Virginia reached a $285 million contract last year with General Dynamics to monitor and manage vulnerabilities and provide other security services.

"So basically we're transitioning from our existing footprint to our sort of next-gen footprint," Watson said about the project.

In the 2026 NASCIO survey, another concern for state IT security officers is getting the funding needed to protect against cyber threats. Its 2024 survey didn't have any officers reporting budget reductions, but that number jumped to 16% in 2026.

"Virginia has done, I think, a pretty decent job historically of investing in cybersecurity and making sure that we maintain it as one of our top priorities," Watson said when asked about state funding for the effort.

The state budget sets aside $14 million during both the current fiscal year and the 2028 fiscal, a total of $28 million, for IT security oversight. It was $25 million total in the previous two fiscal years. (Virginia's fiscal year runs July 1–June 30.)

For Watson, government is built on the public's trust that their government is providing consistent services that are protected from threats.

"That requires us to make sure that we are on our game on the cyber side to keep those types of malicious actors out, that are gonna do malicious things with their data," Watson said. "Whether it's steal it, whether it's leverage it in some way, whether it's try to trick our citizens."

Copyright 2026 VPM

Dean Mirshahi is a reporter for VPM News in Richmond, Va.