State Governments Assume National Cybersecurity Roles

August 14, 2025 by
Frank Calviño

U.S. state governments began stepping into roles traditionally held by federal agencies in the area of cybersecurity enforcement.

State attorneys general from Kentucky, Nebraska, Arkansas, Illinois, and New York have launched lawsuits against the Chinese-linked e-commerce app Temu, accusing it of data harvesting, malware deployment, and unauthorized data transfers to China. These cases signal a significant shift in responsibility from federal bodies to state-level enforcement.

Why States Are Taking Action?

Under the current administration, federal agencies—including the Federal Trade Commission and the Consumer Protection Branch of the Department of Justice—have scaled back enforcement activities, especially in consumer protection and cybersecurity. This has opened a gap that state attorneys general are now working to fill through legal action under state unfair and deceptive practices statutes as well as privacy laws.

Executive Orders & Public Mandates

A March 2025 executive order calls for states and local governments to take on greater responsibility in resilience planning and cybercrime enforcement. State AG offices have cited this executive order as support for their investigations, including actions related to Temu.

Key Developments

  • Temu litigation: Kentucky, Nebraska, Arkansas, Illinois, and New York filed complaints in July 2025 under consumer protection and cybersecurity statutes, alleging spyware-like behavior by the Temu app and unauthorized publication of sensitive personal data.
  • New York cyber reporting law: Governor Hochul enacted legislation requiring local governments and public entities to report cyberattacks within 72 hours and ransom payments within 24 hours. Mandatory cybersecurity training is also required for all state employees.
  • Consortium forming: Eight state AGs (including those from California, Colorado, Connecticut, Delaware, Indiana, New Jersey, and Oregon) have formed the Consortium of Privacy Regulators to coordinate information sharing and enforcement efforts across jurisdictions.

Implications of State-Led Cyber Enforcement

Advantages

  • Local knowledge & agility: State AG offices can act rapidly and target local harm, tailoring enforcement to their populations.
  • Legal flexibility: State laws often grant AGs sweeping authority under unfair business practice statutes—not limited to federal laws alone—enabling creative enforcement theories.

Challenges

  • Resource limitations: Many states lack access to classified threat intelligence and nation-state cyber-forensics, raising concerns about their capacity to manage state-level cyber investigations effectively.
  • Coordination hurdles: Without strong coordination frameworks, state actions risk duplication, uneven enforcement, and jurisdictional overlap. Coalition efforts like the Consortium help mitigate this.

What This Means for Stakeholders

  • Consumers may benefit from more vigilant enforcement and quicker responses to digital threats, such as spyware or hacking.
  • Businesses should prepare for more rigorous scrutiny by state regulators, particularly in their privacy and cybersecurity practices.
  • Policy makers must consider aligning federal and state efforts to ensure consistent enforcement, shared intelligence, and adequate resources across jurisdictions.

Recent legal actions, new cyber reporting laws (such as those in New York), and multi-state collaboration represent a turning point: U.S. states are now assuming prominent cybersecurity roles. Whether they have sufficient resources or surveillance infrastructure remains in question—but the trend reflects a clear shift in the national enforcement landscape.

Shein falls into the red ahead of its Hong Kong IPO
Shein has reported a quarterly net loss as the fast-fashion e-commerce giant prepares for its long-awaited initial public offering in Hong Kong. The Singapore-headquartered retailer recorded a net loss of...
July 27, 2026
Notino reaches €1.76 billion as European cross-border growth accelerates
Czech beauty retailer Notino generated €1.76 billion in revenue during its latest financial year, reinforcing its position as one of Europe’s most successful cross-border e-commerce businesses. The Brno-based company closed...
July 24, 2026
Kord raises £6.4 million to unify onboarding, compliance and payments
UK fintech company Kord has raised £6.4 million in Series A funding to expand its platform for customer onboarding, regulatory compliance and payment processing. The round was led by Guinness...
July 21, 2026
Top crossmenu

By continuing to use the site, you agree to the use of cookies. more information

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.

Close