Cybersecurity

The threat environment has outpaced the regulatory frameworks, procurement systems, and organizational structures built to address it.

Cybersecurity is no longer just an IT issue. It is a national security concern, an economic risk, a public safety issue, and a growing source of regulatory and procurement pressure for companies, contractors, critical infrastructure operators, and government agencies.

That pressure is changing the terms of market access. Contractors, cloud providers, technology companies, and critical infrastructure operators are increasingly judged not only on whether security controls exist, but on whether those controls can satisfy procurement review, reporting obligations, and regulatory scrutiny. State-level requirements add another layer, with breach notification rules, cloud-security requirements, and vendor conditions evolving unevenly and not always aligning with federal direction. 

When these environments fail, the consequences are immediate and public: a ransomware attack on a water utility, a breach in a defense supply chain, or a local government incident that becomes a public crisis. IBM’s 2025 Cost of a Data Breach Report found that ransomware-related breaches averaged roughly $5.08 million — before accounting for lost public trust, regulatory exposure, operational disruption, and political fallout.

Vertex helps clients identify where cybersecurity policy, procurement, funding, and risk decisions are moving, what those decisions mean for their obligations and market access, and what needs to happen before compliance expectations, incident-response obligations, or public-sector scrutiny narrow the path forward.

North Carolina Spotlight

  • A record 2,349 data breaches were reported to the North Carolina Department of Justice in 2025, impacting more than 9 million North Carolinians.
  • Local governments remain among the most vulnerable — Winston-Salem and Thomasville both had municipal systems knocked offline by cyberattacks in 2025, while a July 2024 attack on the Town of Apex compromised data for roughly 22,000 residents 
  • North Carolina released a 2025–2030 Cybersecurity Strategic Plan and has moved to standardize cloud-security requirements for executive branch agencies, signaling a more formal statewide approach to cybersecurity governance, compliance, procurement, incident reporting, and vendor expectations.

Specialty Areas

  • Cybersecurity policy and legislative engagement — including federal, state, and local cybersecurity policy, regulatory affairs, oversight committee engagement, appropriations considerations, and emerging cyber legislation.
  • Artificial intelligence and cybersecurity governance — including threat detection policy, automated response frameworks, adversarial AI risk, model security, public-sector AI use policies, AI procurement conditions, data protection requirements, and state-level AI governance frameworks.
  • Cybersecurity frameworks, compliance, and public-sector governance — including CMMC, FedRAMP, FedRAMP 20x, FISMA, NIST Cybersecurity Framework, Zero Trust mandates, post-quantum cryptography requirements, GovRAMP, state IT security policy, and public-sector cybersecurity governance.
  • Cybersecurity funding, grants, and audit readiness — including the State and Local Cybersecurity Grant Program, federal appropriations, North Carolina cybersecurity funding, grant compliance, and audit readiness.
  • Cybersecurity procurement and market access — including federal procurement pathways such as GSA MAS, IDIQs, GWACs, and BPAs, NCDIT statewide IT term contracts, NC eProcurement positioning, cooperative purchasing options such as NASPO ValuePoint, vendor qualification, approved product list positioning, CJIS considerations, state IT procurement compliance, and small business set-aside strategy.
  • Critical infrastructure, ICS/OT security, and cyber coordination — including CISA frameworks, election security policy, sector-specific policy, ISAC and fusion center engagement, public-private information sharing, and coordination across critical infrastructure environments.
  • Cyber incident reporting and response — including CIRCIA compliance, public-sector reporting requirements, incident response coordination, agency notification protocols, and communications with regulators, law enforcement, and affected stakeholders.
  • Supply chain cybersecurity, secure software, and vendor risk — including Software Bill of Materials requirements, secure-by-design and secure development requirements, vulnerability disclosure, third-party risk management, foreign technology risk, and public-sector vendor accountability.
  • Data privacy, breach notification, and enforcement — including state attorney general oversight, sensitive data exposure, consumer notification obligations, and regulatory scrutiny following cyber incidents.
  • Cyber insurance, underwriting, and regulatory risk — including coverage availability, affordability trends, underwriting requirements, legislative and regulatory developments, and North Carolina Department of Insurance oversight.

Relevant Regulatory & Government Bodies

Federal

  • Cybersecurity and Infrastructure Security Agency (CISA)
  • Defense Information Systems Agency (DISA)
  • General Services Administration (GSA)
  • National Institute of Standards and Technology (NIST)
  • Office of Management and Budget (OMB) 
  • U.S. Department of Defense (DoD)
  • U.S. Department of Homeland Security (DHS)
  • U.S. Department of Justice (DOJ)
  • U.S. Senate & House Commerce and Homeland Security Committees

North Carolina

  • North Carolina Department of Administration (NCDOA)
  • North Carolina Department of Information Technology (NCDIT)
  • North Carolina Department of Insurance (NCDOI)
  • North Carolina Department of Justice (NCDOJ) 
  • North Carolina Department of Public Safety (NCDPS) 
  • North Carolina General Assembly (NCGA)
  • North Carolina Joint Cybersecurity Task Force
  • North Carolina National Guard (NCNG)