Digital transformation in government can creates an apparent security paradox. The more digital a government becomes -- more online services, more data collected and shared, the more systems interconnected -- the larger the potential attack surface for increasingly sophisticated threats. At the same time, the more security-locked a system becomes, the harder it may be to use. And systems hard to use do not draw user traffic, which defeats the purpose of transformation. In cybersecurity, treating security and usability as opposites can cripple programs that survive other challenges.
Why Government Systems Have High Value
Public sector organizations manage sensitive data that would be attractive to any adversary, including citizen identity records, financial information, health data, immigration records, critical infrastructure control systems. Such can be personally sensitive, and also strategically valuable.
At the same time, government’s expanding digital footprint – powered by cloud adoption, IoT integration, and AI-powered services -- multiplies the points of vulnerability. Each new system, platform, or integration is a potential entry point.
When citizen data is compromised, public trust erodes -- and that erosion can set back digital transformation programs far more than any technical failure.
“Cybersecurity is absolutely critical. We have to approach cyber to both protect our informational advantage but not to the point of disadvantaging ourselves by making it too hard to find the right information or cut people off from critical data.”
-- Air Force Research Lab official, interviewed for the study
The Open-Source Challenge
One security challenge specific to the digital transformation era deserves particular attention. Modern software development relies heavily on open-source components -- the research cites estimates that 80-90% of contemporary code incorporates open-source libraries. This enables developers to build on proven, peer-reviewed code rather than reinventing solutions from scratch.
But open-source dependency can creates supply-chain vulnerability. When a vulnerability emerges in a widely used library, every system built on it has potential exposure. As one official noted: “People don’t always update to the most recent version.” The gap between a vulnerability’s discovery and an organization’s response opens a window of risk exposure that adversaries can exploit.
This challenge requires proactive governance: tracking dependencies, monitoring vulnerability databases, and building update protocols into operational routines rather than treating them as exceptional events.
From Perimeter Security to Embedded Security
Traditional government cybersecurity was perimeter-based: keep bad actors out while securing internally. That model made sense when government systems were relatively closed.
Digital transformation upends those assumptions. Cloud systems, APIs, remote access, and citizen-facing digital services all mean that a perimeter no longer exists in any meaningful sense.
Many observers advocate for a move to layered, embedded security architectures. These include frameworks like zero-trust (which treats every access request as potentially hostile, regardless of origin), multi-factor authentication, end-to-end encryption, and AI-powered threat detection.
Crucially, these approaches embed security into the architecture of systems rather than applying it as an external layer. Security should constitute a first-order design factor -- considered at the same level as functionality, scalability, and accessibility -- not a bolt-on feature added after building the system: “baked in, not bolted on.”
The Human Dimension
Technical architecture is necessary but not sufficient. Human error remains a leading cause of security breaches -- not because government employees are careless, but because security protocols are complex, opaque, or friction-heavy, and thus can be bypassed by people trying to do their jobs effectively.
This creates an imperative: design security systems for usability, not just protection; avoid multi-factor authentication that take users too long. Clear, memorable security protocols have far greater impact than comprehensive ones that nobody follows.
Investment in cybersecurity workforce skills should not be separated from investment in transformation – rather, these be integrated.
Key Takeaways
- Security and accessibility are not opposites -- treating them as a trade-off reflects a design failure, not an inherent constraint.
- Open-source dependency can create supply-chain vulnerabilities that require proactive governance, not just reactive patching.
- Perimeter-based security has become insufficient in a cloud, API-driven, remote-access world -- zero-trust and layered architectures can provide a path forward.
- Security should be baked into system design from the beginning, not added after deployment.
- Human factors, including usability and workforce literacy, should be addressed alongside technical architecture in maintaining security.