State and Local Cybersecurity: Escalating Threats, Federal Partnership, and the Resilience of America’s Communities

Defense Posture and Global ThreatsHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection · 2026-05-21 · 119th Congress
The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection convened to examine the growing cyber threat landscape facing state and local governments, evaluate federal support programs including the State and Local Cybersecurity Grant Program (SLCGP), and hear from state officials about "whole-of-state" cybersecurity strategies. Begins at 0:12:09
Transcript
Highlights

Title

State and local cybersecurity grant program reauthorization and threat landscape

Purpose

The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection convened to examine the growing cyber threat landscape facing state and local governments, evaluate federal support programs including the State and Local Cybersecurity Grant Program (SLCGP), and hear from state officials about "whole-of-state" cybersecurity strategies. The hearing focused heavily on the September expiration of the SLCGP, cuts to CISA's workforce and the MS-ISAC, and how artificial intelligence is reshaping both offensive and defensive cybersecurity capabilities. Begins at0:12:09

Who spoke

Chairman Andy Ogles (R-TN)0:12:09: Opened by describing the mismatch between sophisticated nation-state threats and under-resourced local governments0:14:23, touted his Pillar Act to reauthorize the SLCGP before its September expiration0:16:41, and later pressed witnesses on rural community solutions and hypothetical hospital ransomware scenarios1:47:53.

Ranking Member Delia Ramirez (D-IL)0:17:31: Opened with condolences for victims of an attack at the Islamic Center of San Diego0:17:31, criticized the administration for gutting CISA's workforce to 1,100 and defunding the MS-ISAC/EI-ISAC0:19:36, and pressed witnesses on election security cuts and AI risk0:51:54.

Kristin Darby, CIO, State of Tennessee0:25:32: Testified Tennessee secured 89,684 endpoints and trained 21,000+ local employees through the grant program0:28:07, received about $21 million in federal funding but could use several times that0:29:15, and called for lower cost-share and a rapid-response funding mechanism0:30:17.

Colin Ahearn, Director of Security and Intelligence, State of New York0:30:47: Described New York's shared services protecting over 100,000 local computers and saving governments $19 million a year0:33:14, said CISA's elimination of MS-ISAC support left a pay-to-participate model with no new services1:16:12, and later detailed a $600,000 ransomware attack on the Town of Southold1:20:13.

Warren Sponholtz, CIO, State of Florida0:35:43: Explained Florida's state-funded local grant program, funded at $30M, $40M, and $15M over three cycles0:39:03, and urged flexible, low-match federal grant design for rural communities0:40:02.

Samir Jain, VP of Policy, Center for Democracy & Technology0:41:00: Noted the Canvas breach exposed data of over 275 million users0:42:39, said CISA has lost a third of its workforce and MS-ISAC funding was eliminated0:44:58, and warned smaller jurisdictions unable to pay for ISAC access are least able to afford other protections either1:16:42.

Rep. Carlos Gimenez (R-FL)0:57:31: Asked whether adversaries have a manpower/resource advantage, citing an FBI indictment of ~15 members of Chinese firm I-Soon0:58:12, and pressed all three states on whether they use paper ballots, learning Florida could not confirm and New York does1:02:13.

Rep. Herb Conaway (D-NJ), referred to as Ms. McBath1:02:53: Cited a Cranford, NJ schools data leak1:02:53 and CISA's loss of roughly 1,000 staff (a third of its workforce)1:04:13, asking witnesses to elaborate on CISA's regional role, prompting Ahearn's account of the 2022 Suffolk County cyberattack tiger team1:05:00.

Rep. Morgan Luttrell (R-TX)1:07:43: Raised the challenge of inconsistent state asks for federal help and asked whether states coordinate directly with each other1:08:38, prompting Darby to describe informal CISO information-sharing networks1:09:57.

Rep. Jennifer Wexton (D-VA)1:13:51: Cited cyberattacks against state/local governments up 50%, Iranian hackers targeting water utilities, and the Canvas breach1:14:49, and questioned Ahearn on the elimination of the Critical Infrastructure Partnership Advisory Council1:17:38.

Rep. Nick LaLota (R-FL)1:19:16: Questioned Ahearn on New York's cybersecurity budget (~$90 million) versus Governor Hochul's spending on migrant services (cited at $4.3 billion)1:22:18, repeatedly asking which was a higher priority for the governor1:24:26.

Chairman Ogles (second round)1:25:20: Asked about serving rural/small communities without "propping up" big cities, prompting Ahearn's example of $19 million saved and a 21% reduction in multi-factor token costs1:26:39.

Ranking Member Ramirez (second round)1:29:45: Contrasted federal spending on a White House ballroom ($1 billion) with SLCGP funding gaps1:30:14, and asked Jain about frontier AI risks to state/local governments1:31:07.

Rep. Watkinshaw (D-VA), name as transcribed1:34:18: Asked about CISA's FY2025 budget ($3 billion) versus the FY2027 request ($2 billion), a roughly one-third cut1:34:52, and asked witnesses how they measure cybersecurity success1:35:52.

Rep. Ro Khanna (D-CA) [2:11:17, second round at 2:13:37]: Asked about workforce development, describing his own work with community colleges2:11:17, and drew out Ahearn's account of New York's K-12 computer science curriculum and cyber clinics2:12:31.

Rep. Vince Fong (R-CA)2:00:28: Entered a letter from industry coalitions supporting SLCGP reauthorization into the record2:00:28 and asked how states are updating critical infrastructure cybersecurity for rural communities and military installations2:01:06.

Key moments

Chairman Ogles warned the State and Local Cybersecurity Grant Program, created in 2021 with $1 billion over four years, expires this September unless Congress acts, and touted his Pillar Act to reauthorize it0:16:110:16:41.

Darby testified Tennessee secured 89,684 endpoints and trained over 21,000 local government employees through the grant program, using roughly $21 million in federal funds0:28:070:29:15.

Ahearn said New York's shared services protect over 100,000 local computers, saving $19 million a year, and that average detection-to-remediation time is 37 minutes with shared services versus 2,880 minutes (two days) without0:33:141:38:23.

Ahearn testified there is no genuine replacement model for the defunded MS-ISAC — jurisdictions can now only "pay to participate," with no new services offered1:16:12.

Rep. LaLota pressed Ahearn on New York spending roughly $90 million on cybersecurity versus a cited $4.3 billion on migrant services, repeatedly asking which was a higher priority for Governor Hochul; Ahearn declined to rank them, calling the issues "not mutually exclusive"1:21:391:24:26.

Jain said the Canvas Learning Management Platform breach exposed sensitive information of over 275 million users0:42:39.

Rep. Gimenez's questioning revealed Florida could not confirm whether it uses paper ballots, while New York confirmed it does, prompting Gimenez to call for paper ballots nationwide1:02:131:02:23.

Rep. Watkinshaw cited CISA's FY2025 budget of $3 billion against a Trump administration FY2027 request of $2 billion, calling it roughly a one-third cut, versus Chairman Ogles' figure of $2.5 billion appropriated by the House1:34:522:10:37.

Sponholtz described testing "jailbroken AI" that provided detailed instructions for constructing weapons, illustrating the accelerating risk of AI-enabled attacks reaching unsophisticated actors1:57:521:58:41.

Ahearn disclosed a November 2025 ransomware attack on the Town of Southold, NY demanding about $600,000 in cryptocurrency, which the town refused to pay, instead spending roughly $500,000 to rebuild systems1:20:131:21:09.

Metadata

CommitteeHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection
Chamber / CongressHouse · 119th Congress
Date2026-05-21
TypeHearing
Witnesses
Ms. Kristin Darby — Chief Information Officer, State of Tennessee
Mr. Colin Ahern — Director of Security and Intelligence, State of New York
Mr. Warren Sponholtz — Chief Information Officer, State of Florida
Mr. Samir Jain — Vice President of Policy, Center for Democracy & Technology
Videoyoutube
Transcript306 caption blocks · 21,114 words · 2:22:23 runtime
EventCongress.gov 119254