
The State and Local Cybersecurity Grant Program (SLCGP) was created through the Bipartisan Infrastructure Law in 2021 to help state, local, tribal, and territorial governments strengthen cybersecurity defenses against a rapidly growing threat landscape. Funding for the program expired in September 2025 and since then Congress has been working to meet the funding needs of states to ensure not only the security of state systems and data, but that of the nation.
Funds from the first iteration of the SLCGP were largely used to address immediate security gaps with foundational cybersecurity controls including:
Multi-factor authentication
Endpoint protection
Vulnerability management
Cybersecurity awareness training
Incident response planning
These tools helped close vulnerabilities to ransomware and other cyber attacks. With these basic controls now in place, states are looking to further modernize how they use them and are hoping for federal support in funding the next evolution of their cyber strategy.
The Future of Funding
The House passed the PILLAR Act in November 2025 which would reauthorize the SLCGP program until 2033. It did not however specify a funding amount. In December 2025, the Senate introduced its SLCGP reauthorization bill which now sits in the U.S. Senate Committee on Homeland Security and Governmental Affairs.
This delay in funding is impacting state planning as cybersecurity modernization efforts require ongoing operational funding for staffing and tools, multi-year planning, and workforce development.
The Path Forward
Regardless of federal funding, states know they have to continue modernizing their approach to cyber security. The focus now is less on getting tools and more on building resilience using the technology now in place. Key initiatives include:
Shared Services – Since many local governments simply do not have the staffing, expertise, or budget necessary to independently manage sophisticated cybersecurity programs – particularly rural counties, school districts, and small municipalities – a shared services model can help them close vulnerability gaps. States are increasingly building centralized capabilities that local entities can leverage for managed detection and response services, shared identity and access management platforms, centralized threat intelligence sharing, among other services. States are also creating enterprise procurement vehicles for more efficient and cost-effective acquisition of technology.
Automation – Accelerating the shift to automated security operations addresses the staffing issues faced by states and localities. Automating rote, manual tasks allows for security teams that are stretched thin to focus on more strategic and immediate security tasks. Artificial Intelligence-enabled (AI) tools can help automate threat detection, prioritize vulnerabilities for remediation, and improve security analytics by analyzing large data sets. Funding is needed not only for the AI tools but also the engineering work to integrate them into security workflows.
Cyber threats facing state and local governments are not slowing down and with uncertain support from the federal level, states and localities are finding ways to continue forward momentum. To stay up to speed on their efforts, check out the following resources:
Next-Gen Cyber Operations: AI in Action Summit (July 30, 2026; Reston, VA) – This cybersecurity summit brings together government leaders, industry experts, and innovators to move beyond strategy and into real-world execution.
Vermont Digital Government Summit 2026 (August 4, 2026; South Burlington, VT) – This summit empowers public-sector leaders to explore cutting-edge technologies, modernize operations, and solve pressing challenges.
AI Assistants for Government Workflows (September 2, 2026; virtual) – This virtual workshop brings together government practitioners, technology experts, and industry subject matter experts to explore practical applications of AI assistants across federal operations.
Cybersecurity Summit 2026 (September 9-10, 2026; San Antonio, TX) – This event brings together chief information security officers and senior cybersecurity leaders from state, county and city governments to collaborate, share insights and shape strategic approaches to today’s most pressing cyber challenges.
For more details on state and local cybersecurity efforts, search for additional events and resources on GovEvents and GovWhitePapers.