Skip to main content

The Public Sector Podcast: Q & A with Arizona Secretary of State's CISO Michael Moore

A CISO’s view from the front line of election security.

Author avatar
Heather Dailey 20 July 2026 · 3 min read
The Public Sector Podcast: Q & A with Arizona Secretary of State's CISO Michael Moore

Episode Overview

As AI becomes more embedded in government services, this episode makes the case that cybersecurity is no longer just a technical function — it’s a leadership and trust imperative. Public Sector's own Amanda Garcia sits down with Michael Moore, Chief Information Security Officer for the Arizona Secretary of State’s Office, to explore how agencies can innovate with AI while protecting systems, sensitive data, and public confidence — especially in high-stakes environments like elections.

Michael shares what the modern CISO role looks like in the election ecosystem, spanning not only cyber security, but also physical security, reputational risk, misinformation response, operational readiness, and legal complexity. Drawing on real-world experience — including responding to a significant nation-state-linked cyber incident — the conversation covers practical priorities (logging, IAM, patching legacy apps) and the emerging AI risk landscape: shadow AI, prompt injection, least-privilege for AI tools, data classification/tagging, and the critical need to keep humans in the loop.


Key Themes

  • Cybersecurity as a leadership issue in the age of AI
  • Election security: cyber + physical + reputational + misinformation threats
  • Responding to nation-state activity and strengthening resilience
  • Identity and access management as a foundational control
  • The “Who owns the risk?” question for AI in government
  • Shadow AI, training, and safe pathways for adoption
  • Data classification/tagging and least privilege for AI
  • Secure-by-design expectations for vendors and product security

What You’ll Learn

  • What a day in the life of an elections-focused CISO really involves
  • How security priorities shift in election years (and why availability matters most)
  • What improved logging/alerting/reporting changes after an incident
  • Why IAM can be the difference between containment and compromise
  • How AI can bypass controls if given too much authority (and why accountability stays human)
  • Why “prompting” is a skill that needs training — not a “dump the tools and go” approach
  • Why data tagging/classification is hard, expensive, and essential before scaling AI
  • How shared governance (security + IT + business + vendors) enables safer innovation

Key Takeaways

  • In government, cyber risk is increasingly a trust and mission continuity issue — not just an IT issue.
  • Election environments introduce a broader threat surface: physical threats, misinformation, and logistics all intersect.
  • After an incident, the basics matter: logging, alerting, reporting, and identity controls.
  • AI doesn’t “own” risk — organisations do, especially when delegating authority to automated systems.
  • Expect shadow AI if teams aren’t given clear, approved tools and guidance.
  • Treat AI like any powerful actor: enforce least privilege, and keep humans in the loop.
  • Secure-by-design isn’t optional: vendors must ship products that are secure by default (no unsafe defaults).
  • Good governance accelerates adoption by making lessons, training, and tooling reusable across agencies.

Why You Should Listen

If you’re a public sector leader, CISO, risk owner, IT leader, or vendor working with government, this episode offers a practical view of what it means to secure AI-enabled services — where the stakes include not just systems and data, but public trust and democratic continuity.



What’s Next: Join Michael Moore at This Year’s Event

Michael is speaking at the Government Innovation Arizona on October 1st, 2026 on a panel discussion:

Who Owns the Risk? Securing AI Systems Across Data, Models, and Operations

Michael along with other public sector leaders will clarify how you can define and operationalize shared responsibility so you can protect AI systems as they scale into real-world operations.

Don’t miss this critical conversation. Register here today (free and exclusive for public sector).

Published by

Heather Dailey Content Strategist, Public Sector Network