Federal grant termination forces many states and local governments to withdraw from cyber collaboration organization
The termination of U.S. federal funding for MS-ISAC has led two-thirds of states and thousands of local governments to withdraw from the cyber collaboration organization, raising concerns about security risks to critical infrastructure.

Federal funding for key cybersecurity resources for U.S. state and local governments expired on Wednesday, after the Trump administration decided to cancel the funding. The move signals significant security risks for tens of thousands of jurisdictions nationwide, which will lose a suite of critical cybersecurity services provided by the organization.
The Multi-State Information Sharing and Analysis Center (MS-ISAC), part of the Center for Internet Security (CIS), operated for 21 years under a cooperative agreement with the Department of Homeland Security (DHS). The agreement effectively subsidized services for state and local governments, making it a vital resource for jurisdictions that could not afford expensive contracts with top-tier cybersecurity vendors.
The Trump administration cut off this long-standing and widely praised partnership, first revoking some funding earlier this year, then allowing the rest to expire as the fiscal year ended at midnight. The administration called MS-ISAC's services duplicative, but the organization, its members, and independent experts widely disputed this claim, with some noting that the organization contributed the vast majority of the government's visibility into threats at the local level.
MS-ISAC is expected to retain enough paying members to continue providing services, but will overall lose two-thirds of states and thousands of local governments—organizations thaturgently need help,as they faceincreasingly aggressivethreats from nation-states and criminal hackers.
As local governments operating schools, hospitals, power facilities, and water systems lose critical cybersecurity support, the security of U.S. critical infrastructure could be compromised. In recent years, state and local governments have increasinglyfaced attacks from foreign governments and cybercriminals, and some intrusions havedisrupted essential services。
"By cutting MS-ISAC funding, Trump and Congress are helping our enemies more than they could ever help themselves," said Paul Rosenzweig, a former DHS official who, along with other cybersecurity experts, hastried to save the organization's funding. "State and local governments are on the front lines of cyber defense. Cutting funding that helps them fend off cyber intrusions is an act of self-harm."
Unexpected hostility
The midnight expiration of federal support was the culmination of months of trouble for MS-ISAC. At the start of the year, the organization had no reason to believe its$48.5 million annual funding agreement with DHSwas at risk. In February, the Trump administrationwithdrew about $1 million of it, effectively shutting down the MS-ISAC team dedicated to election security. In March, the administrationrevoked an additional $10 million, saying the work was duplicative and "no longer aligned with DHS priorities." In August, the government alsobarred recipients of the State and Local Cybersecurity Grant Program (SLCGP)from using funds for MS-ISAC membership fees.
The $10 million cut "had a very significant impact on MS-ISAC's ability to do its work," said Robert Beach, chief technology officer of Cocoa, Florida, and an MS-ISAC executive committee member. He said the cut affected member outreach, the organization's annual meeting, and some threat intelligence services. The administration's actions prompted CIS to step in with $1 million per month in emergency funding.
DHS's claim that MS-ISAC's services were duplicative "is clearly a mistake," said John Gilligan, CIS president and CEO. "There is no fact-based reason supporting their conclusion." The fact that local governments are now trying to buy MS-ISAC memberships with their own limited funds is "preliminary proof that the organization is not duplicative," he added.
Beach said that more than 90% of state and local threat intelligence distributed by the Cybersecurity and Infrastructure Security Agency (CISA) comes from MS-ISAC. He called the organization a "critical clearinghouse for cybersecurity capabilities and threat intelligence" for local governments. "I'm not sure CISA can take over this work, especially giventhe cuts their own organization has experienced。”
According to Gilligan, the administration's rejection of MS-ISAC's value stems from a hasty spending analysis by Elon Musk's Department of Government Efficiency that relied on artificial intelligence. He said he sent detailed rebuttals to CISA leadership but never received a response. "I think they're afraid to get in front of the train."
Gilligan said MS-ISAC continues conversations with Trump administration officials and congressional staffers seeking to understand the impact of the cuts. The organization's outside supporters are also communicating with policymakers. The National Association of Counties has been meeting with "different member offices on Capitol Hill to emphasize the importance of this funding," said Seamus Dowdall, the association's legislative director for telecommunications and technology.
As for CISA, Dowdall said: "They have told us they are developing new resources that may be offered to local jurisdictions."
CISA declined to comment on those new resources. But on Monday,the agency promotedits existing services—including vulnerability scanning, phishing assessments, coordination calls, and regional advisor support—and said ending MS-ISAC funding was part of a transition aimed at "strengthening accountability" and "shared national responsibility."
In practice, one CISA employee said the agency has "not offered anything new" in the short term to "make up for the loss of MS-ISAC's free services."
"We are pushing state and local government organizations to use SLCGP to offset the new costs until CISA rolls out some products," said the employee, who spoke on condition of anonymity.
Gilligan said CIS is "disappointed" by the administration's decision to abandon MS-ISAC, which he called "the most successful public-private partnership in this country."
MS-ISAC member exodus
To fill the gap left by the expiration of federal funding, MS-ISAC will beginraising membership fees. The lowest tier (for members with budgets under $25 million) will rise to $1,495 per year, an increase of $500. The other four tiers will increase by between $1,500 and $12,495.
States can choose a statewide membership covering all their local jurisdictions, or a cheaper membership covering only state-level agencies. Many local governments have told MS-ISAC they are waiting for their state's decision, but Beach said he encourages local leaders "not to wait for their state to join," because if the state eventually joins, MS-ISAC will refund the fees.
CIS also offers discounts and free memberships to severely financially constrained local governments.
Membership fees will coverMS-ISAC's core services, including threat analysis and information sharing; a security operations center (SOC) to assist with incident response; best practice documents; online collaboration forums; security maturity assessments; andintrusion detection sensorsandprotective DNStechnology products. The organization will continue to charge extra for non-core services, includingCrowdStrike endpoint detection and response softwareand vulnerability analysis services.
The new fees have already impacted MS-ISAC's membership base. Gilligan said about a third of states "are on their way to signing up," but "right now two-thirds say the fees are too high."
Meanwhile, about 2,000 local governments have signed up, but many others are balking at the already-high fee increase. "Before the federal cuts, we had nearly 19,000 members," Beach said. "We won't get back to that level." Still, he said there has been "significant uptake" at the local level.
"Moving in the wrong direction"
The Trump administration's cancellation of MS-ISAC funding will disproportionately hurt small, impoverished jurisdictions that were already facing both fiscal and cybersecurity challenges even before the government began cutting grants.
"The places that need our resources most—under-resourced local governments—are exactly the ones that will find it hardest to pay," Beach said. Many small jurisdictions cannot afford in-house cyber defense staff, he said, and now most of them may also have to forgo MS-ISAC's external help.
Dowdall said local governments rely on MS-ISAC for everything from threat intelligence and webinars to annual cybersecurity assessments and outsourced SOC functions. During the2024 CrowdStrike outage, the organization provided counties with "up-to-date information" on the incident's impact. According to Dowdall, county leaders who "have seen MS-ISAC's impact on the ground" are now filled with "a lot of uncertainty."
In recent years, MS-ISAC used federal funds to prioritize support for cash-strapped communities. With that resource gone, Gilligan said, "my biggest concern" is that these jurisdictions will not get the support they need.
"We used to have thousands of new organizations sign up every year," Gilligan said. Now, "we are actually moving in the wrong direction."
If MS-ISAC cannot continue to provide the same level of service, reduced membership could also hurt remaining members.
The organization believes its funding goals may not be met in early 2026, but will recover later in the year as states find funding to join.
But the value of the organization's most important service—the information-sharing platform—depends on the volume of information reported, and fewer members means fewer reports. Gilligan acknowledged there could be a slight decline in "the quality we are able to produce."
CISA said Monday it will still work with MS-ISAC on information sharing and guidance documents, though the nature of this adjusted partnership remains unclear.
Uncertain transition period
To avoid major disruption, MS-ISAC will not immediately abandon state and local members that cannot pay.
"We're not going to turn everything off on Wednesday," Gilligan said. "We will probably continue to provide essential services for about a month or two."
It remains unclear whether CISA or other agencies plan to increase support for state and local governments. But in the meantime, Beach said, critical infrastructure could soon be "more exposed than it is now."
MS-ISAC leaders say the organization will be hard to replace. "It's a trusted partner, and it always has been," Beach said, "and the federal government may not always be that popular."
MS-ISAC has become "a very effective facilitator of collaboration, communication, and threat sharing," Gilligan said, "which helps accelerate the nation's defense."
But with that collaboration now unavailable to many local leaders, they are anxiously discussing how to move forward.
"There's a lot of discussion about what the future will look like," Dowdall said.