State and local governments are driven by a shared mission to provide responsive, equitable, and accessible services. However, achieving this goal is often hindered by legacy technical debt, disconnected data, and heavy administrative burdens that slow down mission delivery.
This systemic fragmentation creates costly operational bottlenecks across the public sector, including:
Legacy data silos: Crucial caseworker information frequently resides in isolated repositories managed by separate departments.
Manual bottlenecks: Agency personnel spend a significant amount of time managing routine data entry and manual documentation.
Stakeholder and end-user friction: Users are often required to submit identical verification documents multiple times across different platforms because legacy systems cannot interoperate.
Today, agents can help break down silos, automate routine and manual tasks, and enable agency employees to focus on high value public services, and the deeply human work they were called to do.
AI is the number one priority for state CIOs
Across the public sector, AI has rapidly evolved from an experiment to a core part of the strategy. Reflecting on this shift, the National Association of State Chief Information Officers (NASCIO) State CIO top 10 annual report recently ranked AI as the number one priority for state CIOs for the first time. This reprioritization matters deeply for the future of state and local governance: as state agencies face mounting administrative backlogs, aging infrastructure, and shifting public expectations, CIOs recognize that intelligent automation is the central mechanism to increase staff capacity, streamline caseworker workflows, and deliver more responsive, equitable services to local residents.
As agencies move from AI pilots and experiments to full-scale adoption, the central question for many agencies becomes: How do we leverage AI to bridge the gap between existing legacy investments and modern service delivery?
Leveraging AI for mission impact
Google provides an integrated AI stack designed to remove the friction of manual systems integration, with a focus on speed, scale, and cost-efficiency. Let’s take a closer look at some public sector organizations who are partnering with Google Public Sector and putting AI to work:
Utah Department of Transportation (UDOT): Faced the monumental task of identifying and mapping more than 52,000 property parcels. Originally estimated to take 33.5 years of manual labor to complete, UDOT built a unified data platform on BigQuery, completing the entire project in less than one year and freeing engineers to focus on roadway safety.
City of Hartford: Set a national benchmark for inclusive governance by using AI to provide real-time, two-way translation in 80 languages across all public city meetings, expanding participation while achieving $1.3 million in structural cost savings.
City of Chattanooga: Centralized municipal crash and incident data using Google Cloud's AI and analytics tools, enabling city planners and public safety teams to identify high-risk corridors, optimize traffic signal timing, and prioritize infrastructure investments to make streets safer for residents.
Indiana Department of Transportation (INDOT): INDOT deployed Google Cloud’s AI and document analysis models to automate compliance auditing across dense procurement contract repositories and scale smart road infrastructure. Meeting tight 30-day compliance mandates without pulling licensed engineers from active field projects, the solution saved 360 hours of senior engineering labor while automating roadway asset detection to ensure safer, well-maintained highways for residents statewide.
City of Los Angeles: Facing the massive operational demand of hosting global events—including the 2026 World Cup, 2027 Super Bowl, and 2028 Olympic and Paralympic Games—the city is embedding Gemini directly into daily workflows across 45 departments and 27,500 employees. Serving as a force multiplier for municipal staff, the platform automates complex administrative tasks to amplify workforce capacity, accelerating service delivery and expanding multilingual support for over 15 million expected visitors and four million residents speaking more than 224 languages.
Maryland State: The state partnered with Google Public Sector to empower its 40,000-strong workforce using Gemini and Gemini Notebook within a secure, privacy-first cloud foundation. By lowering cognitive load and automating repetitive administrative tasks, agency teams built and deployed a clean water management application in just five weeks-saving thousands of staff hours and accelerating environmental oversight to deliver more responsive, sustainable public services to Maryland residents statewide.
Accelerate your AI journey with Google Public Sector
The agentic era is all about augmenting human capacity and empowering leaders and builders who make public service possible. Organizations across the public sector are leveraging Google Cloud’s integrated AI stack to redefine how they serve their stakeholders, empower their workforce, and advance their mission. At Google Public Sector, we are excited to partner with pioneering organizations as we build a more resilient, responsive, and connected government, together.
Join us at our Google Public Sector Summit on October 20 to hear from public sector leaders who are leveraging AI to re-imagine service delivery in the agentic era.
The Canadian government’s security guidance for cloud environments outlines a standardized set of security controls to protect data and workloads in the cloud. The security guidance, known as the Security Control Profile for Cloud-based GC Services, also outlines security controls and profiles from a different publication, the IT Security Risk Management: A Lifecycle Approach (ITSG-33).
The ITSG-33 publication has made Protected B Medium Integrity Medium Availability (PBMM) a key compliance measure for the Canadian government and crown corporations.
As part of our commitment to serving the Canadian government with the security capabilities and controls they need, we’ve developed a set of open-source recommendations that map Google Cloud capabilities and security settings to Canadian Protected B regulatory requirements to help our customers place their sensitive data in the cloud. With the Google Cloud landing zones, we’re helping to ensure Canada has the easy-to-administrate, cost-effective, and more secure cloud environment needed for your biggest projects.
Cloud environments built for Canada
Google Cloud’s Protected B landing zones are a set of codified recommendations focused on establishing Google Cloud projects, Identity Access Management (IAM), networking, naming schemes, and security settings in line with regulatory requirements and best practices. Using these as a baseline, Canadian public sector customers are better positioned to quickly meet their compliance requirements.
Google Cloud has published a Terraform-based Infrastructure-as-Code (IaC) template on Github to ensure the foundational settings, policies, and folder structures are correctly configured in alignment with the Annex 4A - Profile 1 (PBMM and ITSG-33).
Codified, built-in security
Landing zones enable a secure environment that is quick to deploy, easy to administer, and provides cost savings for organizations. To make our templates easily understandable, we’ve selected the open-source infrastructure-agnostic IaC tooling provided by HashiCorp’s Terraform. Terraform gives organizations the flexibility to adopt a DevSecOps methodology within their infrastructure. It also provides a security foundation by allowing the IaC to be modified, versioned, change controlled, and automatically provisioned.
The template and instructions on how to use landing zones can be found on GitHub.
Included security controls
There are effectively three different types of security controls described in ITSG-33 documentation:
Technical security controls implemented using technology, such as firewalls.
Operational security controls implemented using human processes, such as manual procedures.
Management security controls focused on the management of IT security and IT security risks.
Within the landing zone template, we’ve focused on controls that can be represented via code. Addressed controls fall into these primary families:
Access Control (AC)
Audit and Accountability (AU)
Configuration Management (CM)
Contingency Planning (CP)
Identification and Authentication (IA)
Risk Assessment (RA)
System and Services Acquisition (SA)
System and Communications Protection (SC)
System and Information Integrity (SI)
How it works
The landing zone deployment phases
To deploy the landing zone, a user with Organizational Administrator privileges will need access to a shell terminal with the Google Cloud (gcloud) CLI, JSON Query (jq) and Terraform installed (which can be done in Google Cloud’s integrated terminal, Cloud Shell). As part of the initial bootstrap script, a single project will be created. This Google Cloud project will be used to set up the landing zone core infrastructure, network infrastructure, automated pipeline, code repository, logging and bunkering aggregation capabilities, and security policies via infrastructure as code automation. After deployment completes, workloads can be deployed in alignment with IT and regulatory policies. This can include leveraging the Cloud Build & Cloud Source Repo (CICD) pipeline established as part of the landing zone bootstrapping.
Several Terraform modules are used to establish the required controls for meeting PBMM requirements:
Landing Zone Modules
The landing zone can be applied with either a Google Cloud organizational node (default and illustrated below), or with a folder as the root node of the landing zone.
Organizational Structure
How to deploy it
Have a shell environment with the required prerequisites installed (Cloud Shell can be used for this)
Update the relevant .auto.tfvars files as indicated in the README.MD file within the repo
From bash, run the bootstrap.sh script from the environments/bootstrap/ directory. The script will prompt for the domain and user that will be deploying the bootstrap resources.
Committed to serving Canada
Our landing zone template extends upon our existing 30-day Guardrails created to meet Canadian Centre for Cyber Security requirements, allowing organizations to have a compliant landing area for production workloads quickly. Visit the Terraform-based Infrastructure-as-Code (IaC) template on GitHub for more detailed deployment instructions and to learn more about meeting CCCS requirements.
Welcome to the second Cloud CISO Perspectives for August 2026. Today, Chris Sistrunk and Stephanie Kiel detail the critical issues facing the water sector, and actionable steps that OT operators can take to secure their infrastructure.
As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.
aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7f06802cc310>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>
Tips on securing the water sector in the AI era
By Chris Sistrunk, Practice Leader, OT, Mandiant Consulting, and Stephanie Kiel, Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud
Chris Sistrunk, Practice Leader, OT, Mandiant Consulting
Google Cloud’s threat intelligence teams have observed that threat actors are becoming bolder when targeting critical infrastructure amid geopolitical conflicts. Recently, we’ve seen increased targeting of water utilities' internet-connected programmable logic controllers in the U.S.
Stephanie Kiel, Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud
Historically, cyber incidents haven’t usually disrupted operations, in part because water utility operators have long had manual override capabilities and established water-quality checks that kick in before water reaches consumers. Pumps and pipes fail routinely for reasons that have nothing to do with cyber threats.
However, they do require our urgent attention and a commitment to stronger security hygiene. Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era.
We recommend a threat-informed, risk-managed response. The current state of water sector security is indicative that additional action should be strongly considered in light of the unique operational resilience that keeps these systems safe.
Actions water and wastewater utilities should consider
For resource-constrained utilities, the most effective defense is to focus on cybersecurity fundamentals. By prioritizing these fundamental practices, you can significantly harden your systems and transform your organization into a far more challenging and resilient target, causing even well-resourced threat actors to look elsewhere.
Inventory assets and assess exposure: Identify if your control systems are insecurely exposed to the internet, which often allows for the successful exploitation of vulnerabilities.
Basic security hygiene: Replace default credentials with strong passwords, and rigorously harden exposed access points, including firewalls.
Backups: Make sure that critical systems, including control systems, are safeguarded following the proven 3-2-1 backup rule (keep three copies of your data on two types of storage, with at least one copy stored off-site). Ensure critical spare equipment is on-hand to minimize downtime from cyberattacks.
Segmentation: Use network segmentation and multifactor authentication to ensure that remote access, when necessary, is strictly controlled. You should use read-only access where full control isn't required.
Emergency planning: Integrate cyber-incident planning into your existing all-hazards incident command system, including FEMA NIMS and Incident Command System for Industrial Control Systems, the same response structures you already use for physical pipe breaks, boil water alerts, and natural disasters.
Secure third-party and vendor access: As many water utilities do not manage their own IT or OT and rely on third-party system integrators, you should audit the remote connections used by the system integrators and maintenance contractors. You should ensure third-party vendors are held to rigorous access controls (such as MFA standards) and logging requirements.
These recommendations echo guidance from the American Water Works Association, the National Rural Water Association, the Water-ISAC, the Environmental Protection Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI.
Recommendations for IT and OT leaders: Bridging the governance gap
IT and OT leaders must work together to build a unified governance framework and should focus on making cyber-physical systems more resilient over the long term, a collective effort that spans government agencies, private sector organizations, and individuals. The goal is to build a future where these systems are secure, adaptable, and capable of recovering quickly from disruptions.
Although PLCs almost always sit outside standard software development practices, a robust approach to the software your organization uses can significantly enhance your overall security posture, such as those outlined in NIST’s Secure Software Development Framework (SSDF). They’re also good examples of leading indicators that can help you gauge your resilience, and to help you get started we’ve published a guide to evaluate leading indicators.
Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era.
As technology evolves, it is critical to modernize security, transitioning from a reactive, manual model to an AI-augmented approach that keeps human expertise central to decision-making. This approach offers an unique opportunity to be a force multiplier for lean security teams.
To stay ahead of today’s threats, organizations must move beyond simple compliance checklists and adopt a more agile, threat-informed strategy that makes compliance a natural outcome of good security, rather than the primary goal.
The Mandiant Operational Technology (OT) Theory of 99 has become more relevant in the AI era. Although the funnel of opportunity has been significantly compressed, in intrusions that go deep enough to impact OT:
99% of compromised systems will be computer workstations and servers
99% of malware will be designed for computer workstations and servers
99% of forensics will be performed on computer workstations and servers
99% of detection opportunities will be for activity connected to computer workstations and servers
99% of intrusion dwell time happens in commercial, off-the-shelf computer equipment before any Purdue level 0-1 devices are impacted
As a result, there is often a significant overlap across tactics, techniques, and procedures used by threat actors who target IT and OT networks. However, the Theory of 99 underscores a significant defender's advantage in the AI era. By using advanced AI capabilities to secure the 99% of intermediary infrastructure, organizations can proactively neutralize threats and ensure robust protection for the critical 1% of physical operational processes.
AI for cyber defense
As we have shared before, AI capabilities offer the opportunity to shift the balance in network security in the favor of defenders. The defender’s advantage becomes even more important as malicious actors increasingly use AI capabilities across the attack lifecycle.
In the current threat environment, automating defenses can serve as a force multiplier for human security teams, enhancing decision-making and productivity to ensure critical exposures are addressed before they can be exploited. With careful planning, critical infrastructure providers can protect their physical assets while building a more resilient, threat-informed defense.
To effectively realize AI advantages for defense, you should integrate AI tools into systems in a structured, intentional way. It’s crucial that operators understand the unique vulnerabilities that AI introduces to physical processes, evaluate specific business uses that can benefit from security automation, and establish clear frameworks to continuously test and monitor. As part of our approach, we’ve developed the Secure AI Framework to help you achieve secure integration and deployment of AI capabilities, regardless of sector.
Most importantly, human oversight must remain central — meaning that AI should support decision-making, and safety practices need to be embedded directly into incident response plans.
What’s next for water security
Protecting water systems from malicious cyber threats is not just a technical challenge; it is a fundamental public safety imperative. Given that access to clean, reliable water is an essential service, we anticipate that federal, state, and local governments will increasingly shift from policy debate to decisive action to ensure the continuity of this critical public infrastructure in the face of cyber threats.
Google is committed to helping you protect your cloud and hybrid cloud OT environments. To learn more about Google guidance on securing critical infrastructure, please visit our CISO Insights Hub.
Here are the latest updates, products, services, and resources from our security teams so far this month:
Empowering autonomous agents with advanced security governance: To be useful and secure, AI agents need access — and also guardrails. In our new State of AI infrastructure report, 79% of tech leaders cite security, governance, or operations as their most significant challenge to scaling inference. Read more.
The state of cloud risk 2026: Most security findings aren’t real attacker opportunities: Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise. Read more.
Introducing Google Cloud Fault Injection Testing in preview: When databases fail and network paths falter, you still need your mission-critical cloud services to stay online. Fault Injection Testing (FIT) can help you automate failure testing to ensure predictable behavior during disruptions. Read more.
How Wiz built AI-powered data discovery: Inside the multi-agent pipeline and feedback loops that turned a bucket scanner into a context engine. Read more.
Democratizing FinOps with Wiz: How the Wiz Cloud Cost automates cost allocation to power developer-led cost optimization and connect cost to business value. Read more.
Defend against agent risks with layered protections in Google Workspace Studio: Studio incorporates layered defenses to mitigate risks from threat actors and robust observability tools to help organizations adopt agents safely. Built on Google’s secure-by-design architecture, Studio combines native threat defenses with deep ecosystem visibility to secure multi-step agentic workflows. Read more.
Please visit the Google Cloud blog for more security stories published this month.
aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7f06802cc3d0>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>
Threat Intelligence news
Distinct clusters target individuals of interest to Russia: Google Threat Intelligence Group (GTIG) is tracking three suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace, governments, and think tanks across Europe and in the U.S. Read more.
Inside 90 days of attacks on AI infrastructure: Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft. Read more.
Version Control DFIR: A cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps: A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services. Read more.
Rust supply chain attack on arrayref: Significant overlap with DPRK campaigns: Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios. Read more.
Please visit the Google Cloud blog for more threat intelligence stories published this month.
Now hear this: Podcasts from Google Cloud
Cloud Security Podcast: Patching browsers with AI, agents, Rust, and your tabs: Jasika Bawa and Doug Turner of Chrome Security explore how Google Chrome now uses AI agents to autonomously identify and patch security vulnerabilities at an unprecedented scale, significantly accelerating the browser's update cadence. Listen here.
Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Near Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.
To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.
The National Oceanic and Atmospheric Administration (NOAA) is embarking on a transformative journey to redefine how we understand and predict patterns in the Earth’s atmosphere that affect the weather we face every day. Today, we are proud to announce that Google Cloud was selected as the primary provider of high-performance computing (HPC) infrastructure for the Weather and Climate Operational Supercomputing System (WCOSS).
This program represents a pivotal shift for NOAA as it transitions from a more traditional, on-premises computing agency to cloud-first infrastructure—a major milestone as one of the first operational Numerical Weather Prediction (NWP) centers globally to move to the public cloud. By modernizing WCOSS on Google Cloud, NOAA is positioning the United States to lead global weather modeling through scale, speed, and reliability.
Google Cloud H4D VMs, powered by fifth-generation AMD EPYC™ processors, are serving as the primary computing backbone for NOAA on Google Cloud. Purpose-built for demanding, compute-intensive workloads like numerical weather prediction, H4D VMs provide the compute power and low-latency networking required to execute massive, tightly-coupled simulations.
To put this in perspective, if traditional computers are like a fleet of individual delivery vans navigating city traffic, H4D VMs operate like a synchronized convoy on a dedicated, multi-lane superhighway—sharing information instantly so they can work together as a single, massive engine. For the NOAA workforce, the move to cloud HPC provides a more streamlined, flexible environment, enabling meteorologists and researchers to quickly adapt future modeling innovations.
A foundation built on long-term collaboration
The partnership announced today is more than just a technological upgrade; it is the latest milestone in a long-term collaboration between NOAA and Google Cloud. For years, our teams have worked together to streamline and share petabytes of environmental data, track real-time wildfires, and advance marine conservation efforts. This work was anchored by the agency’s visionary leadership, which also drove a full transition to Google Workspace as its collaboration suite of choice in 2011.
The success of these early efforts paved the way for broader innovation. For example, NOAA Fisheries pioneered the development of a cloud compute accelerator pilot, giving scientists more flexible computing power they need, when they need it. NOAA also used Google DeepMind and Google Research’s WeatherNext model to predict Hurricane Melissa’s Category 5 landfall five days in advance, saving lives with early warnings and evacuations. These early pilot projects laid the groundwork for NOAA Fisheries to explore agentic AI applications powered by Gemini for Government.
As we look ahead, this collaboration is a testament to what is possible when government and industry align on a shared vision. By combining Google Cloud’s HPC capabilities with NOAA’s unparalleled scientific expertise, we can help improve forecast accuracy, positively impact public safety, and ensure that the United States remains at the forefront of global weather modeling for years to come.
Ready to see how cloud technology is transforming the public sector? Join us at the Google Public Sector Summit 2026 to hear more about how agencies like NOAA are advancing their missions.
Scientists today face challenges of extraordinary scale and complexity. From shaping and simulating the intricate dynamics of fusion plasma, to exploring the vast search space of new materials, to making sense of the exabytes of data pouring out of the world's most advanced experimental facilities. The demands on modern research are unprecedented. Frontier AI can help address these challenges, while accelerating groundbreaking scientific discoveries.
In December, we shared our commitment to the White House's Genesis Mission — the national effort to harness AI and double the pace of American scientific discovery within a decade. Since then, Google DeepMind (GDM) announced an early access program that provides AI for science tools to all 17 Department of Energy (DOE) National Laboratories, and Google Public Sector shared how Gemini for Government could serve as an AI backbone for the DOE.
Today, at the DOE Genesis Mission Summit 2026, we are expanding this by committing $40 million of AI tokens and cloud credits for researchers in support of the Genesis Mission.
Frontier AI tools for scientific discovery
Under this expanded commitment, we will first provide DOE’s Genesis Mission awardees in-kind access to GDM’s frontier AI for science portfolio, including:
AlphaEvolve — a Gemini-powered coding and discovery agent, for designing advanced algorithms.
AlphaFold 3 — a model for predicting the structure and interactions of proteins and other biomolecules.
AlphaGenome — a tool for understanding how variation in DNA, including the non-coding genome, shapes biology and disease.
WeatherNext — a state-of-the-art family of AI weather forecasting models for mapping weather conditions.
AlphaEarth Foundations — a foundational AI model for mapping and understanding our planet in unprecedented detail.
Second, we will provide Gemini for Government seats and tokens for one year to tens of thousands of users across the DOE National Laboratories’ operations, research, and management teams. This secure platform supports the full breadth of work from the research bench to the administration of specialized user facilities serving the entire scientific community, providing a single secure foundation that the DOE mission can depend on.
AI for science tools in action across the laboratory ecosystem
While we have a lot of work still to do, the practical impact of the Genesis Mission is already coming to life across the laboratory ecosystem.
At Pacific Northwest National Laboratory (PNNL), senior scientist Dr. Henry Kvinge is using AlphaEvolve to map out massive mathematical systems that are far too complex for humans to explore by hand. The AI uncovers hidden connections automatically, fast-tracking discoveries that would normally take researchers years to find.
“Modern math relies on abstraction, but combinatorics offers concrete models that make complex geometry and algebra easier to grasp. We’ve found that systems like AlphaEvolve are perfect for this search,” said Dr. Kvinge. “By leveraging the broad mathematical knowledge of LLMs, we can automate the exploration of countless angles. We’re still experimenting, but the discoveries are already shaping our future research.”
At the National Laboratory of the Rockies (NLR), researchers are utilizing Gemini to fundamentally change how they interact with physical laboratory hardware. Dr. Steven R. Spurgeon, a senior materials data scientist at NLR, leads a pioneering program in autonomous materials discovery.
"Our collaboration has allowed us to build an autonomous experimentation capability," said Dr. Spurgeon. "By deploying Gemini in our instruments, we cut microscope calibration time from over 90 minutes to about 13 minutes (eight times faster) and reduced the manual steps needed to focus an image from as many as 50 down to two. That's time and attention we've given back to the science itself, enabling genuinely autonomous workflows that observe, reason, and decide in real time. This has helped us explore parts of the material design space we simply could not have reached through manual operation alone."
Driving American innovation
The Genesis Mission represents an opportunity to transform research and science across America. By providing access to advanced AI tools, we aim to help scientists accelerate breakthroughs across critical energy, security, and scientific challenges. To learn more about how these AI capabilities can support your research initiatives, join us at the upcoming Google Public Sector Summit in October.
In 2026, the public sector is no longer defending a traditional perimeter. Instead, they are defending a complex web of interconnected trust relationships against adversaries that now operate at machine speed. We recently published the 2026 Public Sector Threat Landscape: M-Trends and Beyond report, which distills more than 500,000 hours of frontline incident investigations conducted by Mandiant in 2025, specifically tailored to the mission-critical needs of public sector leaders.
Key findings from the report and what they mean for the public sector
The most alarming trend in this year’s M-Trends data is the 22-second hand-off: the median time between an initial access broker establishing a foothold and the hand-off to a ransomware operator. This extreme compression of the attack cycle renders traditional, human-speed triage obsolete. When an infection on a municipal workstation can move to an encrypted network before a human analyst can even open a ticket, the strategic mandate for resilience must pivot toward machine-speed defense.
Additionally, the report uncovered several emerging "boundaries of trust" that adversaries are systematically exploiting:
The persistence paradox: State-sponsored espionage actors are pursuing multi-year persistence, with some remaining undetected for over five years. This "persistence paradox" directly challenges standard 90-day telemetry retention policies, often leaving agencies unable to quantify the full impact of a breach.
The virtualization stack: Attackers are moving "down the stack" to target the virtualization management plane. Techniques like "snapshot mounting" allow attackers to bypass guest-level security tools, creating snapshots of domain controllers to steal databases offline.
The SaaS domino effect: At the state and local levels, the reliance on third-party cloud tools has turned integrations into threat vectors. Exploiting non-human identities (NHIs) like service accounts and OAuth tokens allows a single compromise to trigger a chain reaction across an entire agency network.
The vishing surge: Voice phishing (vishing) has surged to 11% of global infections. These highly effective social engineering attacks target government help desks to reset passwords or enroll unauthorized devices. This proves that the ‘human element’—the administrative trust placed in help desk staff and IT administrators—is now a primary vector for establishing initial access.
A mandate for continuous verification
Looking ahead, resilience in the public sector will require more than a compliance checklist; it demands a cultural pivot to continuous verification—a security doctrine where trust is never assumed and must be constantly re-validated. Success is no longer just defined by the absence of a breach, but also by an agency’s ability to remain operational while under active attack. At Google, we provide the technical architecture to make continuous verification a reality through three core capabilities.
Identity as the new perimeter: Through Chrome Enterprise Premium, we replace traditional VPNs with context-aware access. We verify the user’s identity and the security posture of their device for every single application request, ensuring that access is only granted under the right conditions.
Agentic defense: We enable agencies to ingest and analyze massive telemetry datasets in real-time using Google Security Operations, which includes threat-centric case management, interactive, context-rich alert graphing, and automatic stitching together of entities. This allows for the "Machine-Speed" detection required to spot an adversary within the 22-second hand-off window, turning manual triage into automated, continuous monitoring. To stay ahead of these rapid shifts, this operational stack is directly infused with Google Threat Intelligence, exposing global actor infrastructure and matching internal telemetry with Mandiant’s frontline incident insights in real time.
At Google Cloud Next ‘26, we announced three new AI-powered autonomous agents within Google Security Operations: a Threat Hunting agent to proactively unearth hidden attack patterns, a Detection Engineering agent to automatically close telemetry coverage gaps, and a Third-Party Context agent to seamlessly enrich analyst workflows.
Hardened infrastructure: By moving "down the stack" with Security Command Center and leveraging our strategic partnership with Wiz, we offer deep visibility into the virtualization and cloud layers. This allows agencies to continuously verify the integrity of their hypervisors and cloud configurations, automatically detecting unauthorized "Snapshot Mounting" or configuration drifts that adversaries exploit for persistence. By hardening the administrative fabric—including identity and virtualization—and modernizing log retention to close the visibility gap, government leaders can move from a state of reactive triage to a future of context-aware resilience.
Google security in action
Google’s security technology comes to life across the public sector, where agencies are successfully shifting from manual triage to agentic defense, and accelerating their security transformation. The Pasco Sheriff’s Office transformed its security and operations, unifying siloed tools with Google Security Operations to boost efficiency, improve community safety, and champion secure AI for law enforcement. Meanwhile, the State of Connecticut moved from a fragmented operating model to a unified, proactive security posture using Google Security Operations to reduce forensic investigation times from months to mere hours and create a secure-by-design digital infrastructure for the future of public service.