Summary

The Multi-State Information Sharing and Analysis Center (MS-ISAC), a cornerstone of US state and local government cybersecurity defense, has lost roughly 70% of its membership after the Department of Homeland Security terminated its federal funding agreement. The organization has dropped from 18,574 total members — including all 56 states and territories — to just 5,618 paying organizations after transitioning to a fee-based model on October 1, 2025.

The mass exodus includes dozens of states and over ten thousand local jurisdictions that can no longer afford cybersecurity services previously provided at no direct cost. The resulting gap leaves smaller and rural communities, along with their critical infrastructure — hospitals, courts, water systems, and emergency dispatch centers — significantly more vulnerable to ransomware and nation-state attacks.

In response, U.S. Senator Mark Warner introduced the “Guaranteeing Universal Access to Cybersecurity Act” in June 2026, proposing $50 million in annual funding starting FY2027 to restore and permanently support MS-ISAC operations. The bill would also direct CISA to conduct outreach to re-enroll former members. The legislation comes as local governments losing MS-ISAC access also face difficulty maintaining affordable cyber insurance, with insurers increasingly treating ISAC membership as a prerequisite for coverage.

Sources

Commentary

This is a self-inflicted wound to US defensive cybersecurity at exactly the wrong time. MS-ISAC was one of the few mechanisms that gave small municipalities access to real threat intelligence and incident response support — the kind of shared defense that makes sense when individual towns and counties can’t afford dedicated SOCs. Gutting it during a period of escalating ransomware attacks and state-sponsored intrusion campaigns is staggeringly short-sighted.

The downstream effects are predictable: more successful attacks on local government, more disrupted services, higher insurance premiums, and eventually more federal emergency spending to clean up the mess. Warner’s proposed $50 million annually is a fraction of what a few major ransomware incidents cost. Whether the bill passes is another story, but the math is straightforward — prevention is cheaper than recovery, and collective defense is cheaper than going it alone.

By Allan