Cybersecurity is Local, Too: Assessing the State and Local Cybersecurity Grant Program

Environmental Permitting and Water InfrastructureHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection · 2025-04-01 · 119th Congress
The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held this hearing to examine the State and Local Cybersecurity Grant Program (SLCGP), which has allocated nearly $1 billion to state and local governments since 2021 and is set to expire in September 2025 unless reauthorized. Begins at 0:09:22
Transcript
Highlights

Title

Reauthorizing the State and Local Cybersecurity Grant Program

Purpose

The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held this hearing to examine the State and Local Cybersecurity Grant Program (SLCGP), which has allocated nearly $1 billion to state and local governments since 2021 and is set to expire in September 2025 unless reauthorized. Members and witnesses from Utah, Connecticut, Louisville, and the cybersecurity industry discussed the program's successes, funding structure, administrative burdens, and the risks of proposed cuts to FEMA and CISA. Begins at0:09:22

Who spoke

Chairman Andrew Garbarino (R-NY)0:09:22: Opened by noting nearly $1 billion allocated under the SLCGP over four years0:09:22 and Microsoft's estimate of 600 million daily cyberattacks against its customers0:09:52; later questioned witnesses on program successes, cyber plan requirements, and asked each witness for one proposed fix1:02:271:25:24.

Rep. Eric Swalwell (D-CA), Ranking Member0:13:02: Described a 2023 ransomware attack that shut down Hayward, California's networks for over two weeks and later exposed residents' Social Security and medical data0:13:280:13:56; criticized Trump administration plans to eliminate FEMA and cut CISA staff, and reports of paused grant distributions0:16:210:16:46; in his second round, asked all four witnesses for a real-time threat-landscape update1:12:48.

Robert Huber, Chief Security Officer, Tenable, Inc.0:19:35: Testified Tenable serves 44,000 customers and cited Vault Typhoon's 2023 attack on a Massachusetts utility0:20:010:20:31; said ransomware attacks doubled 2018–2024, causing over $1 billion in downtime0:20:31; recommended sustainable funding, NIST framework alignment, reduced administrative burden, and passage of the CyberPIVOTT Act0:23:290:23:54; later described ransomware-as-a-service letting criminals "buy access" without conducting attacks themselves1:13:46.

Alan Fuller, CIO, State of Utah0:24:48: Said Utah received about $13 million in federal funds plus $4 million in state matching funds, deploying endpoint security to over 26,000 devices and training 31,000 local employees across 140 entities0:26:290:27:22; described blocking seven major attacks in six months, including stopping ransomware at an airport before Christmas and at a 911 dispatch center0:27:470:28:18; later described a scam targeting Utah liquor stores' credit card readers1:15:10 and a 400-email AI-generated phishing campaign1:16:07.

Kevin Kramer, Councilman, Louisville Metro / First VP, National League of Cities0:29:19: Said Louisville's grant helped create the Kentucky Cyber Threat Intelligence Cooperative (KCTIC) for near-real-time threat sharing0:31:340:32:01; noted over 16,000 of the nation's 19,000 municipalities have populations under 10,0000:31:09; urged a direct federal funding track for larger cities bypassing state pass-through0:32:30; described a 2023 nation-state actor gaining network access via a provider's chat platform, costing about 100 hours to remediate1:16:59.

Mark Raymond, CIO, State of Connecticut0:34:47: Said Connecticut awarded close to $3 million in FY22 (over $2.1 million to localities) and expects over $7 million in FY23 (with $4.3 million to localities)0:36:40; reported only 27.7% of Connecticut municipalities assessed as low risk under NIST framework0:37:11; recommended standardizing match percentages and making shared services the default0:38:35; later warned FEMA/CISA cuts would diminish states' ability to defend municipalities1:01:06.

Rep. Morgan Luttrell (R-TX)0:40:28: Asked how local governments learn about the grant and whether all are reached0:40:28; pressed witnesses on return on investment0:43:21; in round two pressed Huber on whether nationwide protection is realistically achievable given limited local resources1:08:00.

Rep. Andy Ogles (R-TN)0:50:44: Citing his background as a former county executive, asked about cyber threat awareness among small, under-resourced rural infrastructure providers0:52:10 and how to prioritize needs assessments for rural communities0:53:31.

Rep. Gabe Amo (D-RI)0:56:55: Cited Rhode Island's use of SLCGP funds for training and infrastructure protection0:56:55; criticized reported delays and cuts under the Trump administration and noted Secretary Noem's stated plan to "eliminate FEMA" and shrink CISA0:58:07; noted Noem, as North Dakota governor, was the only governor to refuse state cybersecurity grants in 2022 and 20230:59:05; asked Fuller about reported delays or pauses1:00:02.

Key moments

Garbarino said $838 million has been allocated under SLCGP to date and the program expires in September 2025 absent reauthorization0:11:13.

Swalwell said a $250,000 SLCGP grant let a water utility expand real-time monitoring, addressing a long-standing sector resourcing gap0:14:24.

Huber testified ransomware attacks doubled between 2018 and 2024, causing over $1 billion in operational downtime for state and local governments0:20:31.

Fuller described Utah blocking a ransomware attack on a local airport just before Christmas and on a 911 dispatch center, crediting SLCGP-funded tools and no ransom paid or service interruption0:27:470:28:18.

Raymond reported only 27.7% of Connecticut municipalities were assessed as low cyber risk, with 51 grant awards made — 19 for incident planning/governance, 31 for MFA/ransomware protections0:37:110:38:07.

Amo stated Secretary Noem was the only governor in the country to refuse state cybersecurity grants in both 2022 and 2023, calling them "wasteful spending"0:58:370:59:05.

Kramer proposed letting larger cities like Louisville apply for grants directly rather than through a state pass-through, and urged routing rural funding through municipal leagues0:32:301:22:45.

Fuller said Utah applications for the grant were double what could be funded in the first year, indicating high unmet demand0:43:21.

Huber noted that after a major vulnerability is disclosed, most organizations take weeks to patch and fix only about half within two weeks, underscoring persistent exposure1:11:34.

Asked for one fix each, witnesses proposed: harmonized standards focused on security not compliance (Huber), continuity/longer-term funding (Fuller), direct funding access for larger municipalities (Kramer), and ongoing sustainable funding with recurring risk assessments (Raymond)1:25:24.

Metadata

CommitteeHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection
Chamber / CongressHouse · 119th Congress
Date2025-04-01
TypeHearing
Witnesses
The Honorable Kevin Kramer — First Vice President, National League of Cities
Mr. Alan Fuller — Chief Information Officer, State of Utah
Mr. Robert Huber — Chief Security Officer, Tenable, Inc.
Mr. Mark Raymond — Chief Information Officer, State of Connecticut
Videoyoutube
Transcript175 caption blocks · 13,298 words · 1:27:19 runtime
EventCongress.gov 117904