<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="https://www.jain.com/assets/img/6adafce5-1.1"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>State and Local Government &#8211; Jain.com</title>
	<atom:link href="/tag/state-and-local-government/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Data centers, connectivity, and security — news and analysis</description>
	<lastBuildDate>Sun, 14 Jun 2026 16:00:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>/wp-content/uploads/2026/08/jain-com-icon-512-150x150.png</url>
	<title>State and Local Government &#8211; Jain.com</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>MS-ISAC Enters Uncertain Era After Funding Cut and Member Exodus</title>
		<link>/ms-isac-federal-funding-cut-member-exodus-uncertain-era/</link>
		
		<dc:creator><![CDATA[Deepak Jain]]></dc:creator>
		<pubDate>Sun, 14 Jun 2026 16:00:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[MS-ISAC]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[State and Local Government]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">/ms-isac-federal-funding-cut-member-exodus-uncertain-era/</guid>

					<description><![CDATA[MS-ISAC, the cyber threat-sharing hub for US state and local governments, has lost its federal funding and thousands of member organizations. We examine what the shift to fee-based membership means for critical-infrastructure defense, the collective-defense economics at stake, and who might fill the gap.]]></description>
										<content:encoded><![CDATA[<div class="jain-post-grid">
<div class="jain-post-main">
<p>The Multi-State Information Sharing and Analysis Center (MS-ISAC) — the primary cyber threat-sharing hub for US state, local, tribal, and territorial governments — has entered what Cybersecurity Dive describes as an uncertain new era after losing its federal funding and thousands of member organizations, according to a June 14, 2026 report.</p>
<p>The organization, operated by the nonprofit Center for Internet Security (CIS), spent roughly two decades as a free, federally supported service before its cooperative-agreement funding through the Cybersecurity and Infrastructure Security Agency (CISA) was cut in 2025, forcing a pivot to a fee-based membership model that many members have evidently declined to join.</p>
<h2>Executive Summary</h2>
<p>For most of its existence, MS-ISAC functioned as something close to a public utility for government cybersecurity: any state agency, county, city, school district, or tribal government could join at no cost and receive threat intelligence, incident-response support, and network monitoring, with the bill largely picked up by the federal government. That arrangement ended when federal support was withdrawn in 2025, and CIS moved the service to paid membership.</p>
<p>The reported result — thousands of member organizations gone — matters because an information-sharing organization&#8217;s value is a function of its network. Every member that drops out is both a blind spot in the collective picture and, potentially, a softer target. State and local governments run elections, water systems, 911 dispatch, courts, and schools; they are also among the most frequent victims of ransomware, precisely because so many of them lack the budget and staff for standalone security programs.</p>
<p>The open question as of mid-June 2026 is whether a smaller, self-funded MS-ISAC can sustain the same defensive footprint — and what happens to the organizations that used to depend on it and now, apparently, go without.</p>
<h2>From Public Good to Paid Service — and Why That Math Is Hard</h2>
<p>Shared threat intelligence has the economics of a public good: it is expensive to produce, nearly free to distribute, and most valuable when everyone participates. Federal funding solved the free-rider problem by simply paying for universal access. A fee-based model reintroduces it, and with a cruel twist known as adverse selection: the organizations most likely to drop out are the small, resource-poor ones — rural counties, small school districts, modest municipal utilities — which are exactly the entities least able to replace the service on their own and among the most attractive targets for ransomware crews.</p>
<p>None of this means CIS made the wrong call; a nonprofit cannot indefinitely underwrite a national service out of its own reserves once its primary funder exits. But the reported loss of thousands of members suggests the transition is playing out the way the economics would predict. The membership that remains will skew toward larger, better-funded governments, which changes what the shared data represents.</p>
<h2>The Collective-Defense Network Effect Runs in Reverse</h2>
<p>An ISAC — an Information Sharing and Analysis Center — works because one member&#8217;s incident becomes every member&#8217;s early warning. A phishing campaign spotted against one county clerk&#8217;s office can be blocked at ten thousand others within hours. That flywheel spins both ways: as membership shrinks, the sensor network shrinks, detection gets slower, and the value proposition for remaining members weakens, which can encourage further departures. Managed defensively, a smaller ISAC can still deliver real value to a committed core; managed poorly, shrinkage becomes self-reinforcing.</p>
<p>There is also a national-visibility cost that lands on the federal government itself. MS-ISAC historically served as the aggregation point through which federal agencies understood what was happening across tens of thousands of state and local networks. Fewer members means a dimmer picture — for everyone, including the agencies that cut the funding.</p>
<h2>Who Fills the Gap</h2>
<p>Three candidates stand out. First, states themselves: the &#8220;whole-of-state&#8221; model, in which a state CISO extends security services, monitoring, and grant money downward to counties, cities, and schools, has been gaining momentum for years and now has a stronger forcing function. Second, commercial vendors: managed detection and response (MDR) providers, threat-intelligence platforms, and security-focused hosting and connectivity providers will compete for budget that once didn&#8217;t need to exist, though public-sector procurement cycles and thin budgets make this a slow, uneven substitution. Third, CISA&#8217;s own free services — vulnerability scanning, advisories, regional advisors — which remain available but were never designed to replicate an ISAC&#8217;s peer-to-peer sharing fabric.</p>
<p>For infrastructure and security providers, this is a genuine market signal: the public-sector demand for outsourced security operations just grew, involuntarily. The risk is that the gap gets filled unevenly — well-funded jurisdictions buy their way to coverage while the long tail of small governments simply absorbs more risk.</p>
<h2>Background</h2>
<p>MS-ISAC was established in the early 2000s and grew, under the nonprofit Center for Internet Security, into the designated cyber threat-sharing and defense hub for US state, local, tribal, and territorial (SLTT) governments — a sector spanning tens of thousands of organizations, most of them too small to staff full security teams. Membership was free, underwritten by federal cooperative-agreement funding channeled through the Department of Homeland Security and later CISA, and the center became a fixture of national cyber defense, particularly as ransomware attacks on cities, counties, and school districts escalated through the 2020s.</p>
<p>That model unraveled in 2025 when federal funding was withdrawn amid broader cuts to CISA programs, pushing CIS to a fee-based membership structure. The June 2026 reporting marks a milestone in that transition: the organization survives, but with thousands fewer members and an open question about who now watches over the jurisdictions that left.</p>
<p>Source: <a href="https://news.google.com/rss/articles/CBMingFBVV95cUxNQjJMdUJCbk81Z256c1lHajBLaTNfTlpHSmE4TUQxYVh1SXZoT2pFcERmNlVKay0xTFhNS0RFTHItTy1BQUZaMTMwRDhadzAwZEN4MW1iNmpDZjdxRGdMUjMtZlB5amZxT3h5NUNKREFaZTVSNWh2X0ZhNnBzV080TlBZbC1zWDMzVUdEazB6WmNXeWI3X2FXb3VEcFRxdw?oc=5">MS-ISAC enters uncertain new era after losing federal funding and thousands of members</a> — Cybersecurity Dive report, June 14, 2026, on the threat-sharing center&#8217;s post-federal-funding transition.</p>
</div>
<aside class="jain-rail">
<section class="jain-gaps" aria-label="What the release does not say">
<p class="jain-gaps-kicker">⚠ What They Aren’t Saying</p>
<h2>What the Release Doesn&#8217;t Say</h2>
<ul>
<li>The report&#8217;s framing leaves the key quantities unspecified publicly: exactly how many members departed versus converted to paid tiers, what the membership fees are, and how far short the new revenue falls of the former federal support.</li>
<li>It is unclear which specific services have been reduced or preserved — 24/7 security operations center coverage, the Albert network-monitoring program, incident-response support, and advisories may not all be affected equally.</li>
<li>Nothing in the source indicates whether any replacement federal support, state-level subsidies, or philanthropic funding is under discussion, nor whether departed members have adopted alternatives or are now simply unprotected — the most consequential unknown for critical-infrastructure risk.</li>
</ul>
</section>
<section class="jain-faq">
<h2>Frequently Asked Questions</h2>
<h3>What is MS-ISAC?</h3>
<p>The Multi-State Information Sharing and Analysis Center is a US organization that shares cyber threat intelligence and provides security services to state, local, tribal, and territorial governments. It has long been designated as the key cyber-defense resource for that sector.</p>
<h3>Who operates MS-ISAC?</h3>
<p>The Center for Internet Security (CIS), a New York-based nonprofit also known for the CIS Benchmarks and CIS Critical Security Controls, operates MS-ISAC. For most of its history, CIS ran it under a cooperative agreement funded by the federal government.</p>
<h3>What happened to MS-ISAC&#x27;s federal funding?</h3>
<p>Federal support through CISA was withdrawn in 2025. CIS initially absorbed costs itself, then transitioned MS-ISAC to a fee-based membership model, ending the free access that state and local governments had relied on for years.</p>
<h3>Why did MS-ISAC lose thousands of members?</h3>
<p>According to the June 2026 Cybersecurity Dive report, the membership decline followed the loss of federal funding and the move to paid membership. Many state and local organizations, often operating on thin budgets, evidently chose not to pay for what had been free.</p>
<h3>What services did MS-ISAC provide to members?</h3>
<p>Its offerings have included cyber threat intelligence and advisories, incident-response assistance, security operations support, and network monitoring for government members — services many small jurisdictions could not afford to build in-house.</p>
<h3>Who is affected by the change?</h3>
<p>State agencies, counties, cities, school districts, tribal governments, and local utilities — the operators of elections, water systems, emergency dispatch, courts, and schools. Small, resource-poor jurisdictions are the most exposed, since they are least able to buy replacement services.</p>
<h3>Why does this matter for critical infrastructure?</h3>
<p>State and local governments operate a large share of US critical infrastructure and are frequent ransomware targets. A shrinking shared-defense network means slower warning, fewer sensors, and more jurisdictions defending themselves alone.</p>
<h3>What is an ISAC, in plain terms?</h3>
<p>An Information Sharing and Analysis Center is a clearinghouse where organizations in one sector pool information about cyberattacks so that one victim&#8217;s incident becomes everyone else&#8217;s early warning. Its value grows with the number of participants.</p>
<h3>What is CISA&#x27;s role in this story?</h3>
<p>The Cybersecurity and Infrastructure Security Agency was the federal channel that funded MS-ISAC. After the funding ended, CISA&#8217;s own free services — advisories, vulnerability scanning, regional advisors — remain available but do not replicate an ISAC&#8217;s peer-to-peer sharing network.</p>
<h3>Does a smaller MS-ISAC still have value?</h3>
<p>Yes, but less than before. Threat sharing has a network effect: fewer members means fewer sensors and slower detection for everyone remaining. A committed paying core can still benefit, but the collective picture is dimmer than when membership was near-universal.</p>
<h3>What is the whole-of-state cybersecurity model?</h3>
<p>It is an approach in which a state government extends security services — monitoring, incident response, grants, shared tooling — down to its counties, cities, and school districts. It is one of the most likely mechanisms to absorb roles MS-ISAC played.</p>
<h3>What alternatives do local governments have now?</h3>
<p>Options include paid MS-ISAC membership, state whole-of-state programs, CISA&#8217;s free services, and commercial providers of managed detection and response or threat intelligence. Each carries cost or capability trade-offs, and small jurisdictions may struggle to afford any of them.</p>
<h3>What does this mean for security and infrastructure vendors?</h3>
<p>It signals growing public-sector demand for outsourced security operations, monitoring, and threat intelligence. Vendors that can navigate government procurement and price for small jurisdictions have an opening; the risk is coverage concentrating in wealthier jurisdictions.</p>
<h3>What should municipal IT leaders do in response?</h3>
<p>Assess which MS-ISAC services they actually depended on, weigh paid membership against state programs and commercial options, register for CISA&#8217;s free offerings, and make the residual risk explicit to leadership rather than letting coverage lapse silently.</p>
<h3>What remains unknown as of June 2026?</h3>
<p>The precise membership numbers before and after the transition, current fee levels, which services were cut or kept, whether any replacement funding is coming, and — most importantly — whether departed members found alternatives or are now unprotected.</p>
</section>
</aside>
</div>
<p><script type="application/ld+json">{"@context": "https://schema.org", "@graph": [{"@type": "NewsArticle", "headline": "MS-ISAC Enters Uncertain Era After Funding Cut and Member Exodus", "description": "MS-ISAC, the cyber threat-sharing hub for US state and local governments, has lost its federal funding and thousands of member organizations. We examine what the shift to fee-based membership means for critical-infrastructure defense, the collective-defense economics at stake, and who might fill the gap.", "image": ["/wp-content/uploads/2026/08/ms-isac-federal-funding-cut-member-exodus.png"], "author": {"@type": "Organization", "name": "jain.com Editorial"}, "datePublished": "2026-08-23T04:56:19.169398+00:00"}, {"@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "What is MS-ISAC?", "acceptedAnswer": {"@type": "Answer", "text": "The Multi-State Information Sharing and Analysis Center is a US organization that shares cyber threat intelligence and provides security services to state, local, tribal, and territorial governments. It has long been designated as the key cyber-defense resource for that sector."}}, {"@type": "Question", "name": "Who operates MS-ISAC?", "acceptedAnswer": {"@type": "Answer", "text": "The Center for Internet Security (CIS), a New York-based nonprofit also known for the CIS Benchmarks and CIS Critical Security Controls, operates MS-ISAC. For most of its history, CIS ran it under a cooperative agreement funded by the federal government."}}, {"@type": "Question", "name": "What happened to MS-ISAC's federal funding?", "acceptedAnswer": {"@type": "Answer", "text": "Federal support through CISA was withdrawn in 2025. CIS initially absorbed costs itself, then transitioned MS-ISAC to a fee-based membership model, ending the free access that state and local governments had relied on for years."}}, {"@type": "Question", "name": "Why did MS-ISAC lose thousands of members?", "acceptedAnswer": {"@type": "Answer", "text": "According to the June 2026 Cybersecurity Dive report, the membership decline followed the loss of federal funding and the move to paid membership. Many state and local organizations, often operating on thin budgets, evidently chose not to pay for what had been free."}}, {"@type": "Question", "name": "What services did MS-ISAC provide to members?", "acceptedAnswer": {"@type": "Answer", "text": "Its offerings have included cyber threat intelligence and advisories, incident-response assistance, security operations support, and network monitoring for government members \u2014 services many small jurisdictions could not afford to build in-house."}}, {"@type": "Question", "name": "Who is affected by the change?", "acceptedAnswer": {"@type": "Answer", "text": "State agencies, counties, cities, school districts, tribal governments, and local utilities \u2014 the operators of elections, water systems, emergency dispatch, courts, and schools. Small, resource-poor jurisdictions are the most exposed, since they are least able to buy replacement services."}}, {"@type": "Question", "name": "Why does this matter for critical infrastructure?", "acceptedAnswer": {"@type": "Answer", "text": "State and local governments operate a large share of US critical infrastructure and are frequent ransomware targets. A shrinking shared-defense network means slower warning, fewer sensors, and more jurisdictions defending themselves alone."}}, {"@type": "Question", "name": "What is an ISAC, in plain terms?", "acceptedAnswer": {"@type": "Answer", "text": "An Information Sharing and Analysis Center is a clearinghouse where organizations in one sector pool information about cyberattacks so that one victim's incident becomes everyone else's early warning. Its value grows with the number of participants."}}, {"@type": "Question", "name": "What is CISA's role in this story?", "acceptedAnswer": {"@type": "Answer", "text": "The Cybersecurity and Infrastructure Security Agency was the federal channel that funded MS-ISAC. After the funding ended, CISA's own free services \u2014 advisories, vulnerability scanning, regional advisors \u2014 remain available but do not replicate an ISAC's peer-to-peer sharing network."}}, {"@type": "Question", "name": "Does a smaller MS-ISAC still have value?", "acceptedAnswer": {"@type": "Answer", "text": "Yes, but less than before. Threat sharing has a network effect: fewer members means fewer sensors and slower detection for everyone remaining. A committed paying core can still benefit, but the collective picture is dimmer than when membership was near-universal."}}, {"@type": "Question", "name": "What is the whole-of-state cybersecurity model?", "acceptedAnswer": {"@type": "Answer", "text": "It is an approach in which a state government extends security services \u2014 monitoring, incident response, grants, shared tooling \u2014 down to its counties, cities, and school districts. It is one of the most likely mechanisms to absorb roles MS-ISAC played."}}, {"@type": "Question", "name": "What alternatives do local governments have now?", "acceptedAnswer": {"@type": "Answer", "text": "Options include paid MS-ISAC membership, state whole-of-state programs, CISA's free services, and commercial providers of managed detection and response or threat intelligence. Each carries cost or capability trade-offs, and small jurisdictions may struggle to afford any of them."}}, {"@type": "Question", "name": "What does this mean for security and infrastructure vendors?", "acceptedAnswer": {"@type": "Answer", "text": "It signals growing public-sector demand for outsourced security operations, monitoring, and threat intelligence. Vendors that can navigate government procurement and price for small jurisdictions have an opening; the risk is coverage concentrating in wealthier jurisdictions."}}, {"@type": "Question", "name": "What should municipal IT leaders do in response?", "acceptedAnswer": {"@type": "Answer", "text": "Assess which MS-ISAC services they actually depended on, weigh paid membership against state programs and commercial options, register for CISA's free offerings, and make the residual risk explicit to leadership rather than letting coverage lapse silently."}}, {"@type": "Question", "name": "What remains unknown as of June 2026?", "acceptedAnswer": {"@type": "Answer", "text": "The precise membership numbers before and after the transition, current fee levels, which services were cut or kept, whether any replacement funding is coming, and \u2014 most importantly \u2014 whether departed members found alternatives or are now unprotected."}}]}]}</script></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
