Note: this is not a comprehensive post about cybersecurity in NYC. However, I am writing it so I can refer others to it as a primer, and will be writing much more about it going forward. I expect the next few posts that I write on cybersecurity, like this one, to be more of a collection of ideas.
Table of Contents:
Who is in charge of cybersecurity for New York City? This is similar to answering “Who is in charge of physical security for New York City?” There is a simple answer, and then a full answer.
The simple, operational answer: New York City Cyber Command (NYC3). Just like the simple, operational answer for physical security is the New York Police Department (NYPD).
For the remainder of this post, I will be writing more about operational responsibility, rather than policy responsibility.
“Who is in charge of cybersecurity?” has a broad answer
But the full answer shows that security is a complicated team (and team-of-teams) sport, even if there are visible entities that do an important bulk of the work. In the case of physical security, the NYPD is not even the only police department operating in the city—it’s just the only one most directly under the control of the city. There are also Port Authority Police, MTA Police, State Police, the Department of Correction, the City Council’s sergeant-at-arms, the National Guard, federal agencies like the FBI, private security guards, every individual operating to protect themselves if necessary, and more. All of these entities have distinct roles, rights, and responsibilities, and they all work together in a complicated fashion. They also collectively respond to a wide diversity of threats, from physical fights all the way up to international counterterrorism.
Cybersecurity is not different from physical security in this respect. Not only is there NYC3, headed by the city’s chief information security officer (CISO) CJ Dixon, there is the NYS Division of Homeland Security and Emergency Services (DHSES); NYS Office of Information Technology Services (ITS); the State Police Intelligence Center (NYSIC); NYS Division of Military and Naval Affairs (DMNA); every utility like ConEd; city agencies; public authorities like the MTA; a panoply of federal and interstate entities like the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security (DHS) and the Multi-State Information Sharing and Analysis Center (MS-ISAC)1; every IT team in every private entity (especially large financial, healthcare, and technology companies); every individual operating to prevent themselves from getting phished, scammed, or hacked; and more. These are also collectively responding to a wide array of threats, from small scams to state-sponsored attacks on our critical infrastructure.
Cybersecurity required entities dedicated to coordination
The result of this complicated distribution of cybersecurity responsibilities and threats is a need for coordinating institutions, which New York City and State have been rapidly building the past few years. They are their own complicated list. For example: the Joint Security Operations Center (JSOC) that was created in 2022:
The Joint Security Operations Center (JSOC) brings together federal, state, city, and county governments, critical businesses and utilities, and state entities like Division of Homeland Security and Emergency Services, Office of Information Technology Services, New York State Police, MTA, Port Authority of New York and New Jersey, the New York Power Authority, among others.
Why do you want this coordination? So that the many entities responsible for cybersecurity can easily share information, telemetry, resources, and more. To use the policy term, New York State is working towards a “Whole-of-State Approach to Cybersecurity.” The idea here: all of these systems need to work together as an integrated whole, because they are otherwise too weak, lacking in information, or under-resourced to respond to the modern cyber threat landscape properly. If you want a deeper look at the coordinating nature of state cybersecurity policy, read this.
About New York City Cyber Command (NYC3)
Basic institutional history
Here is a basic institutional timeline of NYC3:
Pre-2017, prior to NYC3: cybersecurity, inasmuch as it is centrally handled, is handled by the Department of Information Technology and Telecommunications (DoITT), which was created in its modern form in 1994 by Local Law 28. But it was quite distributed, with entities like the NYPD carrying a lot of responsibility.
2017, created: NYC3 is established via mayoral executive order (de Blasio, EO #28), headed by the city’s chief information security officer (CISO). The CISO reports to the First Deputy Mayor, and NYC3 lives under the office of the mayor broadly. NYC3 is charged with working with DoITT to carry out its mission.
2020, put into the charter: Local Law 89 adds §20-j to the city charter, which hard-codes cyber command into the city government, rather than leaving it on the less-sure footing of an executive order, which could be rescinded by any mayor at any time.
2022, folded into OTI: DoITT is renamed the Office of Technology and Innovation (OTI) via mayoral executive order (Adams, EO #3). EO3 moved NYC3 within OTI2 as part of a larger consolidation of all city technology under OTI.
What does NYC3 do?
From §20-j of the city charter:
establish and regularly update cybersecurity policies and standards for city agencies;
regularly train appropriate city officers and employees on cybersecurity policies and standards;
review, at the request of the mayor, the budget priorities of all agencies for programs related to cybersecurity, and recommend to the mayor budget priorities among such programs;
at the direction of the deputy mayor for operations or another designee of the mayor, require any city agency to furnish data and information that is necessary to ensure the compliance of city agencies with cybersecurity policies and standards;
direct cybersecurity defense and response, in coordination with the department of emergency management as appropriate; and
perform such other responsibilities with respect to cybersecurity, including responsibilities delegated elsewhere by the charter, as the mayor shall direct.
Generally, NYC3 centralizes the task of cybersecurity across the city government in a way that it wasn’t before. While individual agencies throughout the city have their own tech teams, their cybersecurity standards are set by NYC3, and NYC3 assists with incident response.
For a longer overview of NYC3, look at: the bonds! The bonds!
For those who might not be aware, city bond official statements are one of the best places to look for overviews of city government (cc: Mark Levine); this is also true of any other bond-issuing entity, like the MTA. An official statement is an overview of city bond terms, as well as the risks and assets of the city. As a document, it says to investors: “We can pay back the bond you buy from us; here are the details to assure you of that, as well as uncertainties and risks that may cause problems.” It contains much more than people might think, including demographic information, housing stock information, and more.
City bond OSs have a section on cybersecurity going back to 2018. Over time, that section has changed as NYC3 has changed, and it mentions cyber incidents in the city when they occur. In my personal view, city general obligation bond official statements are the best summary overview of NYC3 that exists on any site or document facing the public.
I am going to reproduce the full 681-word cybersecurity overview from a recent general obligation bond official statement from September 2026 (see page 86). You can skip to the next section if you’d like, but I think this is cool, as are official statements in general:
The City relies on a large and complex technological environment to conduct its operations. As a recipient and provider of personal, private or sensitive information, the City and its agencies and offices face multiple cyber threats including, but not limited to, hacking, viruses, malware and other attacks on computers and other sensitive digital networks and systems. The City’s Office of Cyber Command (“Cyber Command”), which was created in 2017, is charged with setting information security policies and standards for the City, for directing the City’s citywide cyber defense and incident response, deploying defensive technical and administrative controls and providing guidance to the Mayor and City agencies on cyber defense.
In January 2022, Cyber Command became part of the City’s Office of Technology and Innovation (formerly the Department of Information Technology and Telecommunications). Cyber Command works with agencies to advance its cybersecurity capabilities in a number of areas. In 2023, Cyber Command established the NYC Vulnerability Disclosure Program to broaden the scope of the City’s efforts to identify and address vulnerabilities within its publicly accessible digital resources. By establishing guidelines, rules of engagement, and a secure channel for security researchers to send vulnerability submissions, the program complements existing citywide cybersecurity initiatives, facilitating timely remediation of identified risks.
Cyber Command has over 100 full-time employees and works with designated cybersecurity contacts at each City agency as part of the Citywide Cybersecurity Program. The Financial Plan reflects funding for Cyber Command of $105.5 million for fiscal year 2026 and $103.2 million for fiscal year 2027 and $102.7 million for each of fiscal years 2028 through 2030. Such funding does not account for cybersecurity funding at other City agencies. Cyber Command provides citywide cybersecurity services for all functions defined by the National Institute [sic] of Science & Technology Cybersecurity Framework.
In carrying out its functions, Cyber Command works with a range of City, State, and federal law enforcement agencies, including the New York City Police Department and the Federal Bureau of Investigation’s Joint Terrorism Task Force. In February 2022, the City and the State, along with the mayors of Albany, Buffalo, Rochester, Syracuse, and Yonkers, unveiled the Joint Security Operations Center. The center has enhanced coordination of cybersecurity efforts across the State, helping to foster collaboration among city, State, and federal entities. Cyber Command also regularly works with other states and municipalities throughout the country to share cybersecurity threat intelligence and best practices, as well as with non-governmental entities such as utilities, telecommunications providers and financial services companies for the purpose of enhancing collective cyber defenses. The City has developed standard cybersecurity policies and standards for third party vendors of the City to follow, and security provisions for contracts with vendors, which help ensure that the City is notified of cyber breaches and suspected cyber breaches of a vendor’s network environment. The City has also developed a Citywide Incident Response Policy, which requires City agencies to develop incident response plans in accordance with Cyber Command policies and standards.
While the City conducts periodic tests and reviews of its networks, no assurances can be given that such security and operational control measures will be successful in guarding against all cyber threats and attacks. New technical cyber vulnerabilities are discovered in the United States daily. In addition, cyber attacks have become more sophisticated and are increasingly capable of impacting municipal control systems and components. The techniques used to obtain unauthorized access to, or to disable or degrade, electronic networks, computers, systems and solutions are rapidly evolving and have become increasingly complex and sophisticated. As cybersecurity threats continue to evolve, the City may be required to expend significant additional resources to continue to modify and strengthen security measures, investigate and remediate any vulnerabilities, or invest in new technology designed to mitigate security risks. The results of any successful attack on the City’s computer and information technology systems could impact its operations and damage the City’s digital networks and systems, and the costs of remedying any such damage could be substantial. The City does not carry insurance against cyber attacks, consistent with the City’s general policy of self-insurance.
Colin Ahern: a brief profile of an important civil servant in New York cybersecurity
Note: his last name is pronounced uh-HURN (emphasis on the second syllable). People often go for AY-hurn, which is understandable, but not correct. My last name (Golliher) is often mispronounced as Goll-i-her, which is the phonetic reading, and makes sense, and yet it is pronounced GOL-yer (“gol” as in “golf,” “yer” as in how they sometimes say “your” where I grew up).
Mr. Ahern was appointed by Governor Hochul as the first New York State Director of Security and Intelligence earlier this year:
Governor Kathy Hochul today announced the appointment of Colin Ahern to serve as New York State’s first-ever Director of Security and Intelligence (DSI). In this role, Director Ahern, who previously served as New York State’s Chief Cyber Officer, will provide strategic direction and further unify the State’s security assets on national security and intelligence matters. The DSI will also coordinate statewide activities to better respond to global risks and seize opportunities for advancing the defense industrial base and technologies crucial to national security.
Mr. Ahern has had a long career in public cybersecurity that goes back to the founding of NYC3 itself. He has worked on these issues, both operationally and policy-wise, since he was in the U.S. Army.
You can find plenty of his talks and interviews online, but I will include a few ideas that regularly come up in them. They are both articulations of his own views, and descriptions of policies that he has overseen and implemented. You can find full quotes and sources in the footnotes.
Operational design: “Operationally relevant, technically feasible, politically sustainable, legal.”3
Do routine things routinely, and fall in love with the basics.4
Cyber threats are accelerating, and policymakers need to get a better idea of the severity of the threat.5
There are a lot of great civil servants working on cybersecurity for New York City and State. The point of this post isn’t to review them all, but to ground people in their thinking. Cybersecurity is done by people and technology. You can know the people, and you can assess New York’s cyber posture. You do not have to rely on vague generalities and high abstractions about “x risk.” I see too many people who are interested in AI/cybersecurity forget to learn the basics about the physical and managerial systems that provide those things, which is the key to shaping policy to respond to threats and embrace opportunities.
A sample list of docs to read that outline New York State’s “Whole-of-State” approach to cybersecurity
Much of what New York State has done to increase cybersecurity boils down to the basics: creating centralized, high-quality resources for governing units to access; integrating those units’ systems into a centralized view of state systems; using that centralization to identify and respond to threats better and more quickly; and supplying the money and talent necessary to do all of these things.
If you want to learn more about the state’s overall cyber strategy, start with these three documents:
New York State: Cybersecurity Strategy (August 2023).
E Pluribus Unum: New York’s Unified Cyber Defense Initiative (2026).
“State and Local Cybersecurity: Escalating Threats, Federal Partnership, and the Resilience of America’s Communities” U.S. House Committee on Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection, Testimony of: Mr. Colin Ahern, Director of Security and Intelligence, New York State (May 2026, see pp.11-27 of the linked PDF).
What’s next for my cybersecurity writing
In general, I think about cybersecurity like I think about other policy areas: it is best to be concrete, to know the systems and agents within a system, and to avoid speaking very generally if one cannot make those generalities specific. Due to rapidly increasing AI capabilities, it is too easy to panic, succumb to misdirection, and otherwise do anything other than craft policy that meets the moment. But we can craft policy that meets the moment, if we are concrete.
In addition to writing about New York’s cybersecurity policy, I will also be writing about how to evaluate it. How do we know if it’s working, and if we’re getting bang-for-buck? What would we expect to see if it weren’t working? And so forth. Despite still having a lot of work to do, New York City and State, as governments, seem much better prepared than most.
In his May 2026 testimony before the House (pp.18-19 in the linked PDF), Mr. Ahern offered this as evidence for New York State’s cybersecurity policy efficacy:
“The most consequential measure of the program's effect is the one local government leaders care about most. Ransomware incidents reported to the State have declined from 14 in 2023, the year the shared-services investment began, to zero through the first four months of 2026. This drop, despite increased reporting volume, is the strongest available evidence that investment in shared, state-level cyber defense generates significant returns.”
At the city level, I will be writing about what roles the mayor, city council, comptroller, and others have in both crafting good cybersecurity policy, and in shaping the public narrative productively. If you want to get in touch to discuss any of this, do not hesitate.
MS-ISAC used to be a free, subscription-based service for state and local governments (and other entities). That service was paid for by the federal government, but that funding was ended in September 2025. At that point, MS-ISAC moved to a paid subscription model, which was not without controversy; the idea is that it is a more sustainable funding model, and the counterpoint is that many smaller localities that can least afford cybersecurity tools are least able to afford it. See here.
“EO3 moved NYC3 within OTI” is a very bureaucratic sentence. Cybersecurity, like policy in general, is an alphabet and alpha-numeric soup.
“Lessons From the Front Lines: New York City Cyber Command,” (2017), from 13:38–17:31, emphasis added for the four principles of operational design:
I want to spend a few minutes on operational approach and operational design. I know this is a hacking conference, the difference between a great idea and a successful project is operational design. The operational design we use is called Hayden’s principle, named after General Mike Hayden, who was director of the CIA and the director of the NSA as well. And the purpose of this operational design is to minimize the impact of magical thinking…
The first things to avoid magical thinking is operational relevance: do the bad guys who care about me care about this? That is the first question we ask ourselves when we undergo major transformative efforts like New York City Cyber Command, like major technology roadmap journeys, and threat modeling. There has been a lot of great talks here about threat modeling…But having a codified practice surrounding threat modeling, making your assumptions explicit…obviously, all models are bad, but some models are useful, and a useful model that people can measure themselves against makes your threat models more reproducible, more data-driven, and more quantifiable. And when we talk about data as a problem, these need to be inputs to some model someplace ultimately. And when we talk about operational relevance, it’s not just the good guys doing behavioral things and machine learning things. The velocity, variety, and sophistication of attacks has really increased, so operational relevance needs to be taken at machine speed.
Technically feasible. Can we actually do this today, and if we can’t, what are the things we need to have tomorrow in terms of resources, people, time, and money—that delta, and how do we bridge the gap? There was a great talk earlier [on] policy and procurement and how relevant that is. We work very very hard…to safeguard the resources of our taxpayers, and that includes thinking a lot about the relationship between technical feasibility and our ability to procure things. For those of you in government or considering it, that is a very real concern.
Political sustainability. The reason we put this one near the bottom is because, for practitioners of some persuasion, this is both the most boring and the most important part of operational decision-making. By political sustainability, I don’t mean politics with a capital P, like elections [or] November. I mean politics with a small p, like fitting the culture of your organization, and meshing that with your operational design, and seeing executives as key stakeholders in your operational design. Executives aren’t people for you to manage. Executives are team members with valuable input to how you do operations, because this is the thing they do. If it’s not clear to you what your executive team does, what they do is have an extremely keen understanding of what is politically sustainable. If you don’t include them in designing your strategies, it’s unlikely that you’ll get their buy-in, and that this will succeed. And moving from a hero model to a team-of-teams approach.
Last and certainly not least, legal. The legal landscape in cyber evolves every day, and lawyers are force multipliers. What is legal today might not be legal tomorrow; legal risk is something to be managed by professionals. “I thought I read it on Wikipedia,” not a sufficient answer; “I checked with the general counsel,” sufficient answer.
He carries this framework throughout his career. He repeats it many places, but here’s a 2023 interview where he repeats it at the 15:16 mark.
18:51-19:28 in this 2023 interview:
And then the basics. Great organizations do routine things routinely, so if you want to do something extraordinary, it starts with the basics. So…all the usual stuff: multi-factor authentication; knowing your internet-facing threat surface and patching or triaging it appropriately; having a team of dedicated staff that can work problems; having the right relationships and contractual vehicles with your vendor partners, incident response teams, etc. There's no secret. There's only hard work.
2:10:06-2:10:19 in Congressional testimony from May 2026:
…underpinning all of this is falling in love with the basics every single day. [This] is a services business and these services are delivered by, with, and through technology.
Mr. Ahern provided lengthy testimony to a House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection in May 2026. The hearing was on “State and Local Cybersecurity: Escalating Threats, Federal Partnership, and the Resilience of America’s Communities.” The following quotes are from that hearing:
“The water is continuing to boil faster…we are seeing the collapse of deterrence.”
“We know bad things are going to happen, so having backups, cloud-based backups, business continuity planning, and other things are very important.
And with regard to legacy technology, these are systems that have been built over multiple decades by multiple vendors. And if something is old, it is harder to secure, it is harder to maintain. If something’s not reliable, it doesn’t matter if it’s secure, and then obviously if something isn’t secure, it doesn’t matter if it’s reliable. So when the technology debt we have, I think we’re going to be under a margin call, if you’ll excuse the finance metaphor, because this technology debt is going to come due with these AI threats and the ever-increasing scope of our adversaries.”
20:34-21:38 from a 2023 interview:
“I think, unfortunately, people don’t have a good enough imagination when it comes to how bad things could get. Among our policymakers, and, maybe I don’t want to say in particular the private sector..[It’s] magical thinking. We want to not be alarmist, but we want to be clear-eyed in our assessment of the trajectory of this space [and] our reliance on cyber…have a good imagination for how bad things could get, execute on timely, critical plans to assess how you’re going to know [when] you’re crossing into the danger zone…”




