The Cybersecurity and Infrastructure Security Agency (CISA) has announced the planned conclusion of its cooperative agreement with the Center for Internet Security (CIS), a nonprofit organization that has provided cybersecurity services to state, local, tribal, and territorial (SLTT) governments. This transition, set to take effect on September 30, 2025, marks a significant shift in how CISA supports SLTT partners in defending against cyber threats. CISA stated that the move is part of a broader strategy to enhance accountability, maximize the impact of federal resources, and empower local entities to take a leading role in their own cybersecurity. The agency emphasized that, moving forward, SLTT governments will have access to grant funding, no-cost cybersecurity tools, and direct expertise from CISA to bolster their digital defenses. The State and Local Cybersecurity Grant Program (SLCGP) and the Tribal Cybersecurity Grant Program (TCGP) will continue to provide financial support, while services such as Cyber Hygiene scanning, phishing assessments, and vulnerability management will remain available at no cost. CISA also highlighted the availability of professional services, including vulnerability assessments and incident response coordination, as well as regular security operations center calls to keep SLTT partners informed of emerging threats. The end of the CIS agreement follows earlier funding cuts to the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC), which was also operated by CIS and played a key role in advising election officials on cyber threats. The rationale behind the funding shift is to streamline federal support and ensure that resources are used efficiently to strengthen the nation’s overall cyber resilience. However, some observers have questioned whether discontinuing funding for CIS, which has been instrumental in providing affordable cybersecurity services to local governments, will actually improve resiliency. CISA has not clarified whether the funds previously allocated to CIS will be redirected to other state and local cybersecurity initiatives. The transition is part of CISA’s new model to reinforce its position as the nation’s lead cyber defense agency, focusing on direct engagement and support for critical infrastructure and frontline partners. The Center for Internet Security has not yet responded to inquiries regarding the impact of the funding cut on its operations or on the services it provides to SLTT entities. The move underscores a broader trend in federal cybersecurity policy, emphasizing direct federal support and accountability over third-party partnerships. As the transition unfolds, SLTT governments are expected to rely more heavily on CISA’s in-house resources and expertise. The long-term effects of this policy change on the cybersecurity posture of local governments remain to be seen, particularly in light of increasing cyber threats targeting public sector entities. CISA’s commitment to providing ongoing support through grants, tools, and professional services is intended to mitigate any potential gaps left by the end of the CIS partnership. The agency has encouraged SLTT partners to engage with its new suite of resources and to participate in regular communications to stay abreast of evolving cyber risks. This development represents a significant evolution in the federal approach to supporting local government cybersecurity, with a focus on direct federal engagement and resource allocation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
FEMA issued a June 16 bulletin stating that recipients of the State and Local Cybersecurity Grant Program and Tribal Cybersecurity Grant Program may not use grant funds for membership fees that bundle cybersecurity or technical services. The guidance said recipients may still buy individual products or services from groups such as MS-ISAC if they follow federal procurement standards, and it also removed the requirement for some grant recipients to complete the Nationwide Cybersecurity Review.
Following the loss of federal support, CIS said it would transition MS-ISAC to a paid membership model. The change was intended to preserve threat intelligence, best-practice sharing, collaboration, and monitoring, blocking, and response services for members.
CISA announced it would not renew its cooperative agreement with the Center for Internet Security, ending the arrangement on September 30, 2025. The agreement had provided about $27 million annually to support CIS services for SLTT governments, including MS-ISAC.
Prior to the final termination decision, federal funding for the Multi-State Information Sharing and Analysis Center had already been reduced. The reductions prompted concern about the future of cross-state cyber threat information sharing for state, local, tribal, and territorial governments.
Before the MS-ISAC decision, the Department of Homeland Security terminated funding for the Elections Infrastructure ISAC, another Center for Internet Security program. The cut raised concerns about election security and information sharing related to election infrastructure.
CISA issued a public statement saying it would strengthen its commitment to state, local, tribal, and territorial governments and fill gaps in support. The announcement framed the agency's plan to continue providing services even as some federal support for CIS-run programs ended.
DHS, through CISA, ended a $10 million partnership with the Center for Internet Security that supported the Multi-State ISAC and Election Infrastructure ISAC. CISA said the move would eliminate redundancies and save about $10 million annually, while officials and experts warned it could weaken cyber and election information sharing.
Federal support for MS-ISAC threat intelligence and incident response services was cut, raising concerns about continued cybersecurity assistance for state, local, tribal, and territorial governments. The development preceded later DHS and CISA decisions to end broader CIS partnership funding.
Secretaries of state and election officials expressed concern that announced CISA staffing and program cuts, including ending EI-ISAC funding, would weaken election cybersecurity and resilience against foreign interference. They warned smaller and rural election offices would be hit hardest by the loss of federal support such as intelligence assistance, penetration testing, and Albert sensors.
11 references tracked. Mallory keeps watching after this page renders.
statescoop.com
Open sourcecybersecuritydive.com
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcecisa.gov
Open sourcenextgov.com
Open sourcestatescoop.com
Open sourcestatescoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.