The National Association of State Chief Information Officers (NASCIO) urged Congress to reauthorize the expired State and Local Cybersecurity Grant Program (SLCGP), warning that its lapse undermines state and local cyber operations as other federal support declines. The four-year program expired in September 2025; the bipartisan PILLAR Act, which would have extended it through 2033, passed the House but stalled in the Senate. NASCIO and allied local-government organizations requested $300 million in one-year appropriations, with program rules directing 80% of funding to local-government services.
NASCIO cited partial defunding of the Center for Internet Security’s Multi-State Information Sharing and Analysis Center (MS-ISAC) as an additional strain on state and local defenses. The association also called for reauthorization of FirstNet before its statutory authority expires in February 2027, and urged lawmakers to preserve state authority over artificial-intelligence governance rather than broadly preempting state AI laws.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
The State and Local Cybersecurity Grant Program (SLCGP) expired after its original four-year term, leaving the state and local cybersecurity funding program without reauthorization.
NASCIO sent congressional leaders a letter urging reauthorization of SLCGP and FirstNet, while also calling on Congress not to broadly preempt state artificial-intelligence laws and regulations.
Federal support for state and local cybersecurity operations was reduced through partial defunding of the Multi-State Information Sharing and Analysis Center, which provided resources and monitoring to roughly 18,000 organizations and communities.
NASCIO, the National League of Cities, and other state and local associations requested that the Senate appropriate $300 million for a one-year continuation of SLCGP funding. The program requires states to direct 80% of funding to local-government services.
State cybersecurity leaders testified before Congress about the benefits their states had received from the SLCGP.
The House advanced the bipartisan PILLAR Act, which would reauthorize and fund the SLCGP through 2033. The measure did not advance in the Senate.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcestatescoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.