CISA Cuts $10 Million in Cybersecurity Funding for States and Elections
The Cybersecurity and Infrastructure Security Agency (CISA) has terminated around $10 million in funding for vital cybersecurity initiatives at the Center for Internet Security. This withdrawal affects election security and broader cyber support for state, local, and tribal governments, raising concerns about continuity of services in threat intelligence and incident response.
Key Signals
- CISA cuts $10M funding for cybersecurity initiatives related to elections
- Jurisdictions may face gaps in cyber threat intelligence services
- Center for Internet Security sees funding elimination affecting incident response capabilities
"Election officials were reporting malicious cyberattacks and sharing important details in real time, which she said allowed Maine to preemptively block those attempting to target her state’s networks."
The Cybersecurity and Infrastructure Security Agency (CISA) has made a significant decision to discontinue approximately $10 million in annual funding allotted to the Center for Internet Security (CIS). This funding has historically supported two key initiatives: the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC) and the Multi-State Information Sharing and Analysis Center (MS-ISAC). These programs were instrumental in facilitating information sharing and collaborative incident response strategies during cyber threats, especially concerning election security.
The implications of this funding cut extend far beyond the loss of financial support; it raises critical questions regarding the sustainability of cybersecurity measures implemented across states. Jurisdictions that have depended on these initiatives for the threat-information sharing and incident response capabilities may now face challenges in ensuring these essential services continue. Without immediate alternatives or new mechanisms to replace this funding, many election offices and government entities could experience delays or service gaps, potentially compromising their readiness against cyber threats.
The withdrawal of these funds particularly impacts jurisdictions that were leveraging the real-time sharing capabilities they provided. For instance, Shenna Bellows, the Maine Secretary of State, remarked, "Election officials were reporting malicious cyberattacks and sharing important details in real time," which she noted had enabled her state to preemptively block attempts from adversaries targeting their networks. This level of proactive engagement may soon be at risk, underscoring the urgency for affected jurisdictions to seek out new information-sharing and cooperative frameworks to fill this gap.
Concerning the fiscal implications, the lack of a clearly defined replacement procurement or successor provider is troubling. The termination of this funding initiative not only eliminates existing resources but also leaves open questions about the continuity of ongoing projects that are crucial for state-level cybersecurity frameworks. The absence of any forthcoming solicitation or new contracts indicates a potential void in potential partnerships that were previously facilitated through these funding avenues.
Moreover, while there may be a silver lining for cybersecurity vendors looking to fill this gap, the signal does not confirm any immediate procurement opportunity. The decision by CISA does, however, highlight an impending demand for substitute capabilities and solutions that could arise as jurisdictions reassess their cybersecurity postures. Vendors interested in this realm should focus on constructing innovative strategies to address these emerging challenges in order to engage with state and local governments proactively.
In summary, the cessation of this funding provides an important moment for both state and local governments and the cybersecurity industry as a whole. There is now an urgent need for stakeholders to mobilize, assess requirements for continuity in cybersecurity measures, and consider collaborative approaches to mitigate vulnerabilities moving forward. Increased awareness and action from vendors could significantly alter the landscape of cybersecurity support for elections and beyond as jurisdictions navigate these new challenges.
Agencies
- U.S. Cybersecurity and Infrastructure Security Agency
- U.S. Department of Homeland Security
- National Association of Secretaries of State
- National Association of State Election Directors
Vendors
- Center for Internet Security
Sources
- Pentagon confirms data breach with over 3 million people affectedreddit-cybersecurity · Sep 30