MS-ISAC enters uncertain new period after losing federal funding and thousands of members
After losing federal funding, MS-ISAC's membership dropped from 18,574 to 5,618, a loss of about 70%. Although CIS maintains operations through subsidies and automation, experts worry that local governments' cybersecurity protections will face greater risks, especially against the backdrop of escalating threats from state-sponsored cyberattacks.

MS-ISAC enters uncertain new era after losing federal funding and thousands of members
The information-sharing organization vital to state and local governments has cut staff and is pinning its hopes on a surge in membership.
Eight months after losing federal funding, the Multi-State Information Sharing and Analysis Center (MS-ISAC) has seen its membership dwindle significantly: dozens of states and more than ten thousand local jurisdictions have dropped out because they cannot afford its critical cybersecurity services, even as the cyberattack threats they face have grown in both number and danger.
MS-ISAC, operated by the nonprofit Center for Internet Security (CIS), says it is working to recruit new members through measures such as discounted fees, and stresses that it can still collect enough data from existing members to provide high-quality cyber threat intelligence to the community. However, the loss of members could leave thousands of small jurisdictions and their critical infrastructure more vulnerable to state-sponsored disruption and ransomware attacks—local impacts that could resonate nationwide as China and Iran use cyberattacks as a foreign policy tool in their conflicts with the United States.
"Community security is national security," said Sarah Powazek, director of the Public Interest Cybersecurity Program at the University of California, Berkeley's Long-Term Cybersecurity Center. "I cannot overstate the local instability caused by critical services being forced offline by cyberattacks—schools closing, water supplies stopping, public life grinding to a halt."
Experts point to MS-ISAC's predicament as a stark example of how the Trump administration's abandonment of traditional federal responsibilities is weakening U.S. cybersecurity.
"Just as the threat environment is accelerating at an unusual pace," said Samir Jain, vice president of policy at the Center for Democracy and Technology, during a recent House hearing, "the federal government is pulling back dramatically."
Membership drops by more than half
For more than two decades, federal subsidies allowed MS-ISAC to offer free membership to state and local governments. But after the Department of Homeland Security (DHS) abruptly cut this funding in 2025, the organization had to start charging membership fees. With cities and counties unable to afford the new fees, and some states having already passed their budgets for the year, MS-ISAC's membership rolls plummeted.
According to CIS data, as of mid-June 2026, a total of 21 states, two territories, and about 2,700 local jurisdictions (including cities, counties, school districts, library systems, hospitals, and police departments) are members of MS-ISAC. Another 15 states have paid membership fees covering all their local entities, adding 2,895 organizations. The current total stands at 5,618 organizations. On the day MS-ISAC lost its federal funding, its total membership was 18,574, including all 56 states and territories. Since then, its membership has declined by about 70%.
Connecticut managed to scrape together funds to cover the unexpected new MS-ISAC fees, but John McKay, a spokesperson for the state's Department of Administrative Services, said, "We're not sure we can continue to afford it." Virginia is finalizing a new membership agreement, but Jennifer Guild, a spokesperson for the state's IT agency, said the loss of federal funding forced it to "scale back the agreement."
Washington state was forced to drop out of MS-ISAC due to a budget deficit, leaving nearly 500 local entities without a "shared operational picture," said Vickie Sheehan, communications director for the state's technology agency.
Meanwhile, Kentucky decided to leave MS-ISAC after reviewing its cybersecurity program, concluding that membership "does not provide an effective return on investment," said Kinsey Woodson, communications director for the state's finance department. Colorado and Michigan have also said they have left the organization.
In an interview with Cybersecurity Dive, CIS President and CEO John Gilligan said MS-ISAC's ability to retain nearly half of its state members is a "huge success" in his view. "Given the short notice, the lack of funding planning, and the severe financial pressures facing state and local jurisdictions generally, our situation is not far from what we expected."
CIS continues to subsidize MS-ISAC fees for some of America's smallest local jurisdictions. The organization has 1,592 "Tier 1" jurisdictions (with annual operating budgets below $25 million), of which 254 receive subsidies in the form of free membership or discounted rates.
Thousands of other local jurisdictions have yet to cancel or begin paying for membership. "Last month, we started moving them off," Gilligan said, beginning with those that use MS-ISAC services less frequently.
Growing risks to state and local infrastructure
MS-ISAC's services form a critical protective barrier for many U.S. states and cities. Losing these protections could significantly weaken their cyber defenses, leading to more disruptions at local hospitals, courts, water systems, and emergency dispatch centers, and increasing the risk of regional or national cyber crises.
Many local governments are already struggling to fund essential services such as water supply, trash collection, and emergency services. Every new expense can upset this delicate balance. "It definitely presents challenges that people would rather not have to face," said John Matelski, chief information officer and managing director at the National Association of Counties.
Even larger counties may struggle to afford MS-ISAC fees. "They may have more money, but they also have more on their plate," Matelski said. "It's really not a big versus small distinction; it's a problem that affects everyone."
Organizations that leave MS-ISAC lose access to a vast network of cyber threat data that is crucial for maintaining situational awareness amid growing threats. The organization issues ransomware attack alerts, shares indicators of compromise from intrusions, and recommends defensive measures.
"Without services like this," Matelski said, "we would all be more vulnerable."
Local governments that lose MS-ISAC services and intelligence will also struggle to maintain affordable cyber insurance or receive payouts after incidents, as insurers consider factors such as ISAC membership and third-party incident response support.
The Cybersecurity and Infrastructure Security Agency (CISA) may be able to fill some of the gap left by the loss of MS-ISAC services, but over the past 16 months, the Trump administration has significantly downsized CISA and restructured its partner programs, leaving many state and local officials uncertain about how much they can rely on the agency. (CISA "regularly communicates with our state and local partners and provides them with timely intelligence, expertise, no-cost tools, and resources," Christine Serrano Glassner, the agency's chief external affairs officer, told Cybersecurity Dive.)
Some lawmakers want action. Senator Mark Warner of Virginia, vice chairman of the Senate Intelligence Committee, has drafted a bill that would require the government to restore funding for MS-ISAC. "Cuts to critical infrastructure protection have led to information silos, depriving communities across the country of the ability to collaborate in protecting critical infrastructure," Warner wrote in a letter to Homeland Security Secretary Markwayne Mullin.
Funding loss transforms MS-ISAC
The disappearance of federal subsidies has triggered multiple changes at MS-ISAC.
Facing a tighter budget, the Center for Internet Security reduced ISAC staff and began looking for ways to automate more tasks. The onboarding process now includes self-guided tours through a portal instead of human-hosted welcome meetings. "We are placing more emphasis on automation," Gilligan said, "because we don't have as many people to conduct outreach activities."
Meanwhile, MS-ISAC says it is still receiving a large volume of threat intelligence from members and continues to publish reports and guidance based on that data. The organization collects telemetry from about 400,000 endpoint security devices, thousands of protective DNS users, and nearly 1,100 intrusion detection sensors, although all three data sources have declined slightly as state and local governments have canceled memberships.
"The quality of intelligence we obtain is as good as it has been in the past," Gilligan said. "In fact, we have increased the depth of analysis and the breadth of report types, providing more services to the state and local community."
Still, the loss of federal subsidies has increased pressure on CIS, which subsidized MS-ISAC by about $1 million per month in 2025. Gilligan said the nonprofit still provides "some subsidy" to the ISAC, but he declined to say how long that can last. "We expect to see more stability by the end of this year."
To demonstrate its value to current and potential members, MS-ISAC is emphasizing its focus on the full spectrum of physical and cyber threats facing state and local governments; educating broader local leaders beyond IT and security offices; and promoting "statewide" models that encourage states to extend membership to often-overlooked entities such as court systems and legislatures.
"It definitely presents challenges that people would rather not have to face."

John Matelski
Chief Information Officer and Managing Director, National Association of Counties
Critical summer
The summer of 2026 will be a critical test of MS-ISAC's ability to demonstrate its value. When many states' annual budgets take effect on July 1, CIS hopes to see membership fees included in those budgets.
Meanwhile, at the local level, IT and cybersecurity leaders are scrambling to find funding for MS-ISAC membership or alternatives. "People are still worried about how to maintain a minimum baseline of cyber capability?" Matelski said.
At the same time, questions remain about the long-term viability of CIS subsidies for cash-strapped jurisdictions. Experts say that if these discounts end, the cybersecurity plight of local governments will deteriorate sharply.
As foreign adversaries continue to probe weaknesses in U.S. networks, some state leaders say the federal government's attempt to distance itself from MS-ISAC is only making things worse.
"No state can handle cyber defense alone," said Colin Ahern, New York State's director of security and intelligence. "These moves will reduce visibility, diminish information sharing, and threaten operational collaboration at a time when we can least afford to lose it."