Stuck in the Past: Aging Procurement Systems Are Opening the Door to Cyber Threats
Hackers Move Fast. State Procurement Doesn’t.
In March 2018, the city of Atlanta, Georgia was hit with a cyberattack. Using a strain of malware, two Iranian nationals carried out a ransom attack that infected 3,789 city computers. This malware encrypted files and locked the city out of its own system. Locked out, the city was unable to process financial transactions, police officers could not book inmates, and court computers failed to pull up cases. The attackers demanded a ransom of six bitcoin—roughly $354,000 at current market value — to end the disruption to government operations. Although the cyber attack was resolved through internal system restoration, the city of Atlanta spent $2.6 million on emergency response efforts.
The cyberattack in Atlanta was not an isolated incident. Rhode Island’s RIBridges system was breached by the Brain Cipher ransomware group in December 2024. The RIBridges program is the state’s centralized platform for administering benefits programs. Hackers had undetected access to the system for around five months, during which they breached 28 of the system’s environments and stole sensitive data belonging to 650,000 Rhode Island residents. Breached information included names, addresses, dates of birth, Social Security numbers, and banking details. Deloitte, the system’s maintainer, agreed to pay the state of Rhode Island $7 million to cover costs accrued from the incident. Although this settlement helped to cover the state’s losses, it did not erase the vulnerabilities 650,000 citizens now face.
Both of these cyber attacks highlight the vulnerability of state governments in an increasingly technological era. Cyberattacks do not just disrupt government operations and expose sensitive information; they cost taxpayers millions. Outdated systems that remain in use, combined with slow procurement processes that delay cybersecurity updates, increase the likelihood of these cyberattacks, as attackers have longer to exploit known vulnerabilities. Although many factors play a role in these cyber attacks, updated and efficient systems are the first line of defense in preventing such. With slow procurement processes, state governments are forced to rely on antiquated systems, and leave a door open for attackers to easily enter. With much of the United States’ critical infrastructure residing in states, vulnerable cybersecurity frameworks threaten national security. Although tools such as cyber maturity assessments, data protection clauses, risk-based tier analysis, and supply chain mapping are available to procurement teams, they are rarely deployed effectively.
When hackers don’t shy away from innovation, state governments cannot either. Understanding the challenges facing state government procurement is the first step toward building more sophisticated cybersecurity frameworks. Grasping cybersecurity’s far-reaching implications across entire states is equally critical.
States as the First Line of Defense
States are the first line of defense for America’s critical infrastructure, such as power grids, data centers, water systems, telecommunications networks, schools, hospitals, and more. Furthermore, state governments are the first to react to emergencies and natural disasters, which puts them on the front lines to defend citizens from international and domestic attacks. In a digital age, these attacks increasingly target digital rather than physical infrastructure. For example, instead of physically tampering with state level telecommunications, hackers can gain access from anywhere in the world. A telecommunications failure at the state level does not just silence personal connections; it cuts citizens off from emergency services at the exact moment they need them most.
As shown in the Georgia and Rhode Island cases, hackers repeatedly target state infrastructure because it is seen as less secure than comparable federal systems. This reputation is dangerously self-perpetuating , and states that fail to implement stronger cybersecurity frameworks are only reinforcing it. When hackers attack a state system, it should be understood not only as an attack on that particular state, but on the United States. The protection of our state cybernetworks is, simultaneously, the protection of our nation.
Defining Procurement
Procurement is the formal process state governments use to legally acquire essential goods and services. In 2025, the National Governors Association noted that one in every three dollars a state government spends goes to public procurement. As shown by this ratio, the procurement process serves as the key bridge between government agencies and private vendors. But how does standard procurement function?
First, states assess their need for a good or service. In this stage, government agencies analyze long-term objectives and budget constraints. Once needs are defined, the procurement lifecycle moves into a competitive bid process. Here, private companies bid on the open project. After this, a government evaluation committee assesses proposals and chooses a supplier based on cost, vendor compliance, and the supplier’s projected success. Next, contracts are awarded and executed by the private vendor. But the procurement process does not end there. Government agencies track procurement activities in real time to evaluate supplier performance, manage risks, and address issues before they escalate. The final stage consists of contract closeout and performance evaluation. This supports transparency efforts, and helps to ensure that tax dollars are spent efficiently.
Adopted across all 50 states, this standard government procurement process has been in effect since the 1980s. For a long time, the process was seen as the best way to handle formal relationships with private vendors. However, modern technology has pushed superannuated procurement to its breaking point.
Failures in State Procurement Systems
Currently, many states still run procurement on paper-era systems. A 2025 National Association of State Chief Information Officers (NASCIO) report found that physical signatures and manual workflows remain common, creating bottlenecks that slow the entire procurement process. Although digital alternatives exist, state procurement systems remain stuck in the past. This is especially cumbersome because vendor quotes typically expire within 30 days; shorter than the time it takes states to secure funding. By the time states have physical signatures for approved funding, the vendor quote has timed out and has to be resent.
Limited technical literacy also causes state procurement to falter. A 2023 New America report identified limited technical competency among state procurement officials as a critical vulnerability. Without the knowledge to evaluate complex systems or identify cybersecurity risks, many offices turn to vendors for technical guidance;often, these are the same vendors seeking to sell to those offices. This conflict of interest means system weaknesses often go unexamined. Even where IT departments exist, they are frequently cut out of final purchasing decisions.
Why do state governments lack technical literacy? SANS 2026Cybersecurity Readiness in Government Survey “points to ongoing concerns about preparedness, investment, and government agencies’ ability to sustain effective cyber defense strategies.” More than half of public sector cybersecurity respondents report difficulty recruiting and retaining qualified professionals, and only 22% feel capable of executing their cybersecurity strategy at scale.
From inadequate training for current employees to difficulty recruiting and retaining digital talent, states lack the personnel needed to build cybersecurity frameworks capable of protecting their systems. If government staff fail to understand how these frameworks function, how can they be expected to procure software that effectively prevents cyberattacks?
Security Implications of Procurement
Cybersecurity can no longer be treated as purely an IT concern, as it touches every function of state government.
Hackers are becoming exponentially more advanced. Phishing attacks, aided by AI, no longer arrive as obvious scams with poor grammar, but as plausible correspondence that can trick even security-minded employees who momentarily lower their guard.[1] One wrong click can give hackers access to an entire network, locking out personnel and exposing sensitive data. In addition, aging digital infrastructure left unrefreshed gives hackers more time to probe its weaknesses, leaving states increasingly vulnerable to breaches. In the near future, large language models are likely to introduce new attack capabilities that experts are only beginning to understand.
State Chief Information Security Officers (CISO) have raised alarms about vendors embedding AI into products faster than governance structures can keep up, often without adequate transparency to procurement teams. The result is AI deployed into operational environments before risk assessments can be applied. While AI offers significant benefits to state governments, it is equally important that robust cybersecurity measures accompany AI products to ensure the companies that supply them are not exposed to threats. For comparison, the federal government would not purchase a fighter jet and then leave it in a field unattended. They put fighter jets on secure military bases for their protection. In the same manner, states must understand that when they procure highly capable technology such as AI, they ought to also protect them properly.
Without new and improved cybersecurity technology, and technically literate personnel, states’ systems are vulnerable and exposed to threats.
Adversary Procurement Successes
While American states rely on outdated paper processes, adversaries like China are modernizing fast. A Hoover Institution report notes that China is expected to surpass the United States in total R&D spending in 2026. Beijing’s procurement policies shield domestic technologies from foreign competition, and provincial procurement structures consistently favor homegrown industries and strategic technological sectors. Technically literate personnel procure domestic technology that not only drives Chinese technical innovation faster, but protects it.
While American procurement comparatively succeeds in competition and transparency, as well as in adhering to a strong legal framework, inefficient procurement processes hinder states’ access to cutting-edge technology. In a world where every document and transaction is digital, clinging to outdated procurement processes is no longer just inefficient; it is a national security risk that leaves critical infrastructure vulnerable.
Bright Spots in a Broken System
On December 18, 2024, Governor Moore of Maryland signed an executive order which directed a comprehensive overhaul of the state’s procurement system. One main feature of this overhaul was an effort to streamline routine procurement. Before December 18, Maryland’s procurement timeline averaged 277 days. To solve this issue, the executive order directed the Office of State Procurement (OSP) to introduce a 120-day maximum procurement timeline. Governor Moore added that “this executive order will deliver significant improvements to our process flows and procurement infrastructure, which will benefit our state agencies, contractors doing business with the state, and Maryland taxpayers.”
In 2025, Maryland passed The Procurement Reform Act.This Act received bipartisan support, and represents the most significant overhaul of Maryland’s procurement processes in decades. First, the Act created a dedicated IT procurement team, putting technological expertise behind purchasing. In addition to this, the Act codified the 120-day procurement timeline put in place by Governor Moore. Finally, the Act states that contractors awarded procurements over $1 million must establish internships and registered apprenticeship programs. This helps to establish succession planning and workforce pipelines for the state of Maryland.
With each of these improvements, Maryland is taking meaningful steps to modernize its procurement system. This not only eliminates outdated and inefficient processes, but also strengthens the state’s ability to acquire the cybersecurity technology needed to protect Maryland citizens from ever-evolving threats.
Conclusion
Hackers are not waiting for state governments to catch up. While adversaries sharpen their procurement systems and accelerate their technological development, American states are still chasing physical signatures and watching vendor quotes expire. The Atlanta ransomware attack cost $2.6 million. The Rhode Island breach exposed 650,000 residents. These are not anomalies; they are warnings. But as Maryland has demonstrated, the path forward is clear. When states treat procurement not as paperwork but as the first line of defense, they do not just modernize a process; they strengthen the security of every citizen, every system, and the nation as a whole.
[1] A phishing attack is a form of social engineering where cybercriminals send deceptive messages—often masquerading as trusted organizations like banks or employers—to trick victims into revealing sensitive information, such as passwords or credit card numbers, or clicking malicious links that install malware.

Stay Informed
Sign up to receive updates about our fight for policies at the state level that restore liberty through transparency and accountability in American governance.