September 3, 2026
Cybersecurity Is a Public Trust Issue, Not Just a Technical One
When I wrote a year-end reflection on FI$Cal’s work a while ago, I noted that cybersecurity is a top priority for the department. That has…

By Subbarao Mupparaju
1 min read
When I wrote a year-end reflection on FI$Cal's work a while ago, I noted that cybersecurity is a top priority for the department. That has not changed — if anything, it has become more central to everything we do. And the longer I work in public-sector technology, the more convinced I am that security is fundamentally a question of public trust, not merely a technical checklist.
The Financial Information System for California holds the data behind the State's budgeting, procurement, cash management and accounting. It is the State's official accounting book of record. A system of that consequence is only as valuable as it is trustworthy, and trustworthiness begins with security.
Private organisations secure their systems to protect their business. Government must secure its systems to protect the public's confidence in government itself. A breach of a state financial system is not only an operational failure; it is an erosion of the trust that allows public institutions to function. That reframing changes how you prioritise: security stops being the thing you bolt on at the end and becomes a first-order design consideration.
In more than three decades across the private and public technology sectors, I have seen that durable security rarely comes from any single tool or purchase. It comes from a few less glamorous commitments. Build it in, do not add it on: security designed into a system from the foundation is stronger and cheaper than security retrofitted under pressure later. Assume the long game: threats evolve continuously, and a posture that was adequate last year may not be adequate this year. And make it everyone's responsibility: the strongest technical controls are undermined by weak habits, and the best culture compensates for imperfect tools.
The people of California do not need to think about how their state's financial data is protected — and that is exactly the outcome we work toward. Invisible, dependable security is the goal. When it holds, no one notices. That quiet reliability is the real measure of success.
I will continue to share reflections here on cybersecurity, enterprise architecture, and technology leadership in government.
Subbarao Mupparaju is Director of the Financial Information System for California (FI$Cal). More at https://subbaraomupparaju.com