Growing Adoption of GovRAMP Across All State, Local Government, & Education Sectors
September 20, 2022
Note: Our Authorized and Progressing Lists are now unified under the Program Participants List.
Shared risk management is the practice of government agencies, technology providers, and other stakeholders working together to identify, manage, and reduce cybersecurity risk through collaboration, transparency, and standardized security practices.
As governments increasingly rely on cloud technologies, AI-enabled tools, and third-party service providers, protecting sensitive systems and citizen data can no longer be accomplished in isolation. Success depends on trusted partnerships, common security expectations, and a commitment to continuous improvement across the entire public sector ecosystem.
That theme was at the center of GovRAMP's panel discussion at GovForward's 8th Annual Carahsoft Summit on FedRAMP on July 23 in Washington, D.C. Moderated by Leah McGrath, Executive Director of GovRAMP, the discussion brought together leaders from state government, industry, and GovRAMP's Program Management Office (PMO) to explore how organizations can strengthen cybersecurity through collaboration, transparency, and shared responsibility.
Cybersecurity has become increasingly interconnected. Government agencies depend on service providers and technology vendors to deliver mission-critical services, while providers depend on clear security expectations and trusted frameworks to demonstrate their commitment to protecting government data.
Shared risk management recognizes that every organization has a role to play. When governments, technology providers, and cybersecurity practitioners collaborate around common standards and continuous communication, they create a stronger, more resilient security ecosystem.
That collaborative model has long been central to GovRAMP's mission.
The panel featured leaders representing state government, industry, and GovRAMP's cybersecurity community:
Leah McGrath – Executive Director, GovRAMP (Moderator)
Shawnzia Thomas – State Chief Information Officer, State of Georgia
Charles Rote – State Chief Information Security Officer, State of Maine
Drenan Dudley – Head of State, Local, and Territorial Government Partnerships and Senior Advisor for Global Policy, Zscaler
Noah Brown – Executive Advisor to the GovRAMP PMO, RAMPQuest
David Resler – Chief Operating Officer and Chief Technology Officer, GovRAMP
"Cybersecurity is no longer the responsibility of a single organization—it requires shared ownership, trusted partnerships, and a commitment to protecting the public together."
- Shawnzia Thomas, State Chief Information Officer, State of Georgia
One message remained consistent throughout the discussion: cybersecurity cannot be owned by a single agency, department, or technology provider.
Every stakeholder contributes to reducing cyber risk—from federal agencies establishing policy, to state and local governments implementing security controls, to cloud providers securing their platforms and technology partners maintaining transparency throughout the software lifecycle.
Rather than viewing compliance as a one-time exercise, panelists emphasized the importance of building ongoing partnerships that strengthen security over time.
This philosophy aligns closely with GovRAMP's approach. By providing a standardized security framework, centralized program management, and continuous monitoring, GovRAMP helps government agencies and service providers work from a common foundation of trust.
Ultimately, shared risk management is about moving beyond individual responsibility toward collective resilience.
Artificial intelligence was one of the most discussed topics during the panel—and for good reason.
According to Deloitte's CIO survey, the National Association of State Chief Information Officers (NASPO) reported more than half of U.S. state CIOs report their employees are already using generative AI tools in their daily work, demonstrating how quickly AI is becoming part of government operations. As adoption accelerates, agencies must ensure innovation is supported by thoughtful governance, security, and transparency.
The discussion focused on several emerging considerations, including:
Protecting sensitive citizen data used within AI systems
Understanding which AI capabilities are embedded within commercial software
Strengthening identity and access management for AI-enabled applications
Increasing transparency when vendors introduce new AI functionality
Preparing for faster and more sophisticated cyberattacks enabled by AI
Panelists also highlighted Georgia's Horizons Innovation Lab, where agencies can safely evaluate AI use cases in a controlled environment before broader deployment.
The conversation reinforced an important message: adopting AI responsibly requires organizations to develop governance and security practices alongside innovation, not after implementation.
Governments increasingly depend on cloud providers and technology vendors to deliver essential services, making third-party risk one of today's most pressing cybersecurity challenges.
According to Verizon's 2026 Data Breach Investigations Report, third-party supply chain breaches increased 60% year over year and now account for 48% of analyzed breaches. Those findings underscore the growing importance of continuous monitoring, vendor transparency, and proactive risk management.
Panelists emphasized the need for organizations to understand how vendors protect sensitive information, communicate product changes, and disclose when AI-powered capabilities are introduced into existing platforms.
One observation particularly resonated with attendees: citizens often cannot choose whether governments collect their personal information. That reality creates an even greater responsibility for governments and their technology partners to safeguard that data through strong security practices and shared accountability.
Another major discussion centered on FedRAMP 20x and the future of cybersecurity framework harmonization.
While panelists welcomed increased automation and emerging concepts like Key Security Indicators (KSIs), they also recognized that state governments continue to operate within regulatory environments shaped by NIST standards and federal requirements from organizations such as the IRS, FBI, SSA, and CJIS.
Reducing duplicative compliance requirements while maintaining rigorous security standards remains a shared priority across government and industry.
For service providers, greater harmonization means spending less time preparing duplicate documentation for multiple frameworks. For government agencies, it creates greater consistency when evaluating security and selecting trusted technology partners.
GovRAMP continues to advance these conversations by working with stakeholders across the public sector to encourage alignment, improve efficiency, and strengthen trust throughout the cybersecurity ecosystem.
GovRAMP continues to advance cybersecurity framework harmonization through research, policy development, and collaboration across government and industry. Explore these related resources to learn more:
Framework Harmonization in Action: Advancing Alignment Across the Government Technology Ecosystem
GovRAMP Releases Policy Path Forward to Advance Cybersecurity Framework Harmonization
Although emerging technologies dominated much of the discussion, panelists agreed that many successful cyberattacks continue to exploit familiar weaknesses.
Phishing, social engineering, poor identity management, and unpatched systems remain among the most common attack vectors affecting public sector organizations today.
As cybersecurity continues evolving, organizations should embrace innovation while remaining disciplined in the foundational practices that have always protected government systems: maintaining visibility, reducing vulnerabilities, managing identities, and continuously monitoring risk.
Strong fundamentals remain the cornerstone of every successful cybersecurity program.
The conversations that began in Washington will continue this November at the 2026 GovRAMP Cyber Summit, taking place November 15–17 in San Antonio, Texas.
Recently recognized by Carahsoft as one of the Top 10 FedRAMP Events for Government in 2026, the Summit will bring together government leaders, service providers, assessors, policymakers, and cybersecurity professionals to continue discussions on AI governance, framework harmonization, continuous monitoring, shared risk management, and the future of public sector cybersecurity.
Public sector professionals attend at no cost, creating an opportunity for government leaders to engage directly with peers, exchange ideas, and learn from experts who are helping shape the future of secure cloud adoption.
Whether you're navigating emerging AI challenges, modernizing your cybersecurity program, or preparing for the future of government cloud security, the GovRAMP Cyber Summit offers a unique opportunity to continue these important conversations.
We look forward to seeing you in San Antonio.