
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
House Homeland Security Chairman Andrew Garbarino (R-NY) is urging lawmakers in the Senate to pass legislation before a Sept.
Summary
30 lapse to reauthorize a popular cybersecurity grant program for state and local governments, amid a heightened threat environment due to the war with Iran. “The suspected Iran-linked cyberattacks targeting municipal water systems across several states underscore the importance of ensuring state and local governments have access to the support they need to defend against rapidly evolving cyber threats, especially as AI supercharges vulnerability discovery,” Garbarino said in a statement to Inside Cybersecurity. The program was stood up under the 2021 infrastructure law, which provided the Cybersecurity and Infrastructure Security Agency and the Federal Emergency Management Agency $1 billion for state, local and tribal governments to be distributed over a four-year period.
The authorities for the program initially lapsed last October during the 2025 government shutdown but lawmakers approved short-term extensions, with the last one set to expire on Sept. 30. The cybersecurity community has largely focused on the authorization of the Cybersecurity Information Sharing Act of 2015, which provides critical liability and antitrust protections for the private sector to share threat information with the Department of Homeland Security and among industry players.
Lawmakers reached an agreement to extend CISA 2015, which was also set to lapse on Sept. 30, through a continuing resolution to keep the government open to Dec. 11 and to avoid another government shutdown.
A short-term extension of the grant program was not included in the continuing resolution. The House advanced in November 2025 a bill to reauthorize the grant program through fiscal 2033. The Protecting Information by Local Leaders for Agency Resilience Act was introduced by House Homeland Security cyber subcommittee Chairman Andy Ogles (R-TN).
Sen. Maggie Hassan (D-NH) introduced a bill last December to extend the grant program to the end of fiscal 2026. The bill has not gotten much traction in the Senate and it’s unclear whether the Senate Homeland Security Committee will consider the Ogles bill before the anticipated Sept.
30 lapse. Garbarino said, “The State and Local Cybersecurity Grant Program remains an essential tool to strengthen our nation’s cyber defenses, which is why House appropriators have included $50 million in the FY2027 DHS appropriations bill. The House has already passed the PILLAR Act which would reauthorize this program for seven years and now it is time for the Senate to do its job.” CISA can administer the remaining funds allocated to the state and local cybersecurity grant program in the event of an authorization lapse, according to a staffer for Republicans on the House Homeland Security Committee.
CISA and FEMA announced in August 2025 the availability of $103.8 million in grant funding for fiscal 2025, including $91.71 million for state and local governments and $21.1 million to go towards a tribal program. The staffer said, “However, reauthorizing the SLCGP is the only way to ensure stability for this program and that it continually receives the funding it requires,” the GOP committee aide said. House Homeland Security ranking member Bennie Thompson (D-MS) has also raised concerns over the Senate not taking up legislation to reauthorize the program ahead of the Sept.
30 deadline. Thompson said, “It is telling that the White House and Senate Republicans wasted the entire Congress without reauthorizing this critical program and are allowing it to lapse while cyber threats are on the rise and now, thanks to Donald Trump, Iran is also targeting our critical infrastructure.” “It shows that cybersecurity is not a priority for Congressional Republicans or this administration. Our communities deserve better,” Thompson said.
Increased fears over cyber attacks from Iran showcase the importance of supporting state and local governments. A series of coordinated cyber attacks against water utilities in July, which threat intelligence firms linked to Iran-affiliated threat actors, prompted lawmakers on the House and Senate Homeland Security committees to look to prioritize sustained funding for the grant program. The Operational Technology Cybersecurity Coalition called the attacks on the water sector a “wake up call” in a July 31 statement advocating for reauthorizing the grant program.
OTCC executive director Tatyana Bolton said in a Sept. 21 statement, “If the recent cyber attacks against water systems taught us anything, it is that all incidents are local. State and local governments and local critical infrastructure are the first line of defense against malicious cyber actors.” “And by not extending this grant program, Congress is leaving small towns to protect themselves from nation-state actors like China and Iran.
This cannot happen. This grant program is essential to secure the industrial control systems that underpin essential services such as water, energy, transportation, and public safety,” Bolton said. The National Association of State Chief Information Officers is also playing a major role in pushing lawmakers to reauthorize the program.
In an Aug. 31 letter to House and Senate leaders outlining their legislative priorities, NASCIO pushed for “long-term and appropriately funded reauthorization” of the program. On Sept.
21, Meredith Ward, NASCIO deputy executive director, said the grant program has been “tremendously helpful in expanding services that states can offer local government entities.” “Since the implementation of the grant, we have seen states use funds to deploy things like [Multi-Factor Authentication], [Endpoint Detection and Response] and training to local governments; expand offerings to cover critical infrastructure; and expand the whole-of-state cyber model.
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment — not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.