Group Purchasing
Group Purchasing

SANS 2026 Cybersecurity Readiness in Government Report

The SANS 2026 Cybersecurity Readiness in Government Survey found that most U.S. government agencies now have formal cybersecurity strategies and governance frameworks in place, yet only 22% have reached optimized operational maturity, held back mainly by funding shortfalls, workforce shortages, and outdated technology.

Top Takeaways

22%

of agencies report optimized cybersecurity maturity

33%

of agencies say their program is fully funded

56%

struggle to recruit or retain qualified cyber talent

63%

cite insufficient budget as a top resource constraint

Survey Methodology and Respondent Profile

This analysis draws on the SANS 2026 Cybersecurity Readiness in Government Survey, which collected 417 responses from cybersecurity professionals working at U.S. federal (65%), state (19%), and local (13%) government agencies. This is the inaugural edition of the survey.

Participant Roles

Respondents held a range of roles, with security analysts or engineers in the largest single group (29%), alongside IT administrators, information system security managers, and cybersecurity program managers.

Vendor Neutrality

SANS Institute maintains editorial independence in survey design and analysis; sponsor participation is limited to underwriting the research and is disclosed separately.

More Key Findings from the Cybersecurity Readiness in Government Report 

  • 55% of agencies report a fully implemented cybersecurity strategy, though 18% are still developing one and 11% are revising theirs. 
  • 65% rate their program as “Established” or “Advanced,” but only 22% consider it truly “Optimized.” 
  • Just 33% of agencies say their cybersecurity program is fully funded, while 63% cite insufficient budget as a top resource constraint.
  • 56% of agencies struggle to recruit or retain qualified cybersecurity personnel, and 56% also point to competing organizational priorities as a barrier. 
  • Staff training and awareness (41%) and threat detection and response (40%) rank as the two most resource-constrained functions. 39% of agencies cite outdated technology or infrastructure as a cause of their resource constraints.

Related Webcast: Is the Public Sector Ready for the Next Cyber Threat?

SANS Senior Instructor Ryan Nicholson walks through the SANS 2026 Cybersecurity Readiness in Government Survey to unpack why most agencies have built strong governance frameworks but still fall short of optimized operations, and what it will take to close the gap in funding, workforce, and technology integration.

Stylized Microphone Orange Background

Meet the Author

Ryan Nicholson
Ryan Nicholson

Ryan Nicholson

Owner at Blue Mountain Cyber, LLC

Ryan Nicholson, SANS Senior Instructor and SEC502 and SEC541 author, brings DoD and cloud security experience to help practitioners detect threats, secure modern environments, and apply defensive strategies that work in real-world operations.

Read more about Ryan Nicholson

FAQs

Only 22% of government agencies rate their cybersecurity program as truly “Optimized,” even though 65% describe it as “Established” or “Advanced,” according to the SANS 2026 Cybersecurity Readiness in Government Survey.

No. Only 33% of government agencies report their cybersecurity program is fully funded, while 63% cite insufficient budget or funding allocations as a primary resource constraint.

Funding and workforce shortages are the leading barriers. 56% of agencies report difficulty recruiting or retaining qualified cybersecurity staff, and 56% also cite competing organizational priorities.

Staff training and awareness (41%) and threat detection and response (40%) rank as the most resource-constrained functions, ahead of incident response and recovery (32%).

Yes. 55% of agencies report a fully implemented cybersecurity strategy, while 18% are still developing one, 11% are revising theirs, and just 6% have no formal strategy at all.

Thank You To Our Sponsors

More Government Cybersecurity Research and Resources

SANS 2026 Cybersecurity Readiness in Government: Key Findings | SANS Institute