Maine CISO Details Edge-Focused State Cybersecurity Strategy

Maine’s chief information security officer outlined the state’s whole-of-state cybersecurity work at a NASCIO conference. The plan emphasizes protecting users at the edge, including local governments and schools, through phishing training and tokenized multifactor authentication. Maine has relied on federal grant funding, and officials view education as a durable investment once grants expire.
Maine’s top information security official, Charlie Rote, described the state’s approach during a NASCIO gathering in San Diego. The strategy prioritizes users in smaller governments, schools and similar organizations that might lack expensive security tools, treating them as an initial protective layer for broader networks.
Maine has used federal State and Local Cybersecurity Grant Program money for two main efforts: phishing simulations and training, plus token-based multifactor authentication. Rote said tokenized MFA disrupts many common attack paths, while education remains valuable after grants end because acquired knowledge does not carry recurring costs.
Maine’s edge-focused efforts could strengthen defenses for local agencies, schools and residents who depend on their digital services. If phishing training and token-based authentication reduce successful intrusions, smaller municipalities and districts may become less attractive targets. That may help protect sensitive data and keep public services available. Yet because the work has relied on federal grants, its long-term reach could depend on whether knowledge and practices persist after funding ends.