US Public Sector Cybersecurity: What Changed in 2025
Federal support for state and local cyber defense ended in 2025 while attacks rose. See what changed, and the controls that work without new budget.
Federal support for state and local cyber defense ended in 2025 while attacks rose. See what changed, and the controls that work without new budget.
US state and local government faces a harder year than most coverage admits. Federal support that many agencies leaned on ended in 2025. Meanwhile, attacks on schools and city services kept rising. Budgets will not close that gap. What does work is limiting what an attacker can reach, and building a workforce that reports fast enough to matter.
Table of Contents
ToggleTwo funding decisions reshaped the picture. Both land hardest on the smallest agencies.
CISA confirmed that its cooperative agreement with the Center for Internet Security ended on 30 September 2025. That deal funded the Multi-State Information Sharing and Analysis Center, known as MS-ISAC. For two decades, it gave threat data and free tools to state and local members. A $10 million cut had already landed in March 2025, roughly half its funding at the time. MS-ISAC has since moved toward a paid, tiered membership model.
The State and Local Cybersecurity Grant Program expired at the same time. In its final year, the grant rules also barred agencies from spending that money on MS-ISAC services, which closed the obvious workaround.
CISA says it will still offer grants, free tools, and regional staff under a new model. Even so, a small county that leaned on free threat data now faces a bill it did not plan for.
The pressure did not ease while the funding changed.
| Area | What the data shows |
|---|---|
| Human element | Involved in roughly 60% of breaches overall |
| Social engineering | Insider-targeted social engineering rose from 12% to 18% |
| Pretexting | Successful in more than 20% of reported incidents |
| K-12 incidents | 82% of US K-12 schools had a cyber incident in an 18-month span |
| Education ransomware | Attacks rose 23% year over year in the first half of 2025 |
| Ransom demands | Averaged $556,000 against education targets |
Verizon’s own analysis called insider-targeted social engineering common in the public sector. That detail matters most here. These are not technical breaks. They are people talked into something, which is why human error stays the dominant entry route.
The Center for Internet Security said much the same about schools. It urged districts to build a culture where staff act, rather than leaning on tools alone.
Discover how Threatcop protects your workforce from modern cyber threats.
A breached company loses money and reputation. A breached city loses services.
Dispatch, billing, payroll, benefits, and student records all sit on the same networks. When those stop, residents feel it at once, and they have nowhere else to go. That is why a ransom demand against a county carries weight a private firm rarely faces.
Staffing adds to it. Many agencies run with one or two people covering helpdesk and security at once, often across several departments. In that setting, one stolen password opens more doors than it would elsewhere, because network splits and monitoring are thinner.
Since spending is not the lever for most public sector teams, focus on controls that cost time rather than money.
None of these need a grant. They need someone to own them and a date in the calendar.
If staff are the main target, the workforce is where the rest of the budget should go.
That means practice, not an annual video. Staff need to meet a realistic lure in a safe setting, again and again. They also need reporting to be quick and blame-free. A clerk who fears a telling-off will wait before speaking up, and in a ransomware case that wait decides the outcome.
Threatcop Security Awareness Training (TSAT) is built for that work. It runs simulations across several attack types, including email, SMS, voice, and QR codes. So a program matches how agencies are really approached, rather than testing email alone. Its Employee Vulnerability Score turns a team average into a named list. That matters when a small team can only coach a few people well. It also measures average breach time, meaning how long from lure to compromise, and flags repeat offenders on its own.
Active Directory links keep groups current as roles change. The executive report then gives councils and boards a trend, not one month’s number. For agencies that must show evidence to auditors or insurers, the training records come out of the same system.
Then review quarterly, because the funding picture is still moving. Agencies weighing cost should also check what a program actually costs before assuming it is out of reach.
The funding that softened the blow for state and local government has thinned. The attacks have not. So the work shifts to what agencies control directly. Turn on phishing-resistant MFA, patch the devices facing the internet, and claim the free federal services that remain. Then put the rest into the workforce, because staff are now the main target and no tool takes that choice away from a person. Judge the program by how fast someone reports, not by how many finished a course. In an agency where one stolen password can stop emergency services, minutes decide whether this is an incident or a crisis.
Government agencies and schools hold Social Security numbers, health records, and student data, yet run with small teams and tight budgets. Attacks also stop services residents depend on, which raises the pressure to pay.
CISA’s deal with the Center for Internet Security ended on 30 September 2025, which removed federal funding. A $10 million cut had already hit it in March 2025. MS-ISAC has moved toward paid tiered membership.
Yes, though the shape changed. CISA says it still offers grants, free tools, performance frameworks, and regional staff. Agencies should check what is available directly, since these programs keep shifting.
A small government agency should start with phishing-resistant MFA, patching internet-facing devices, and a written reporting route. Then run a baseline phishing simulation to see where staff actually stand. These cost time rather than money.
Security awareness training helps at the entry point, where most cases begin. Stolen passwords and social engineering open the door before ransomware runs. So training that creates fast reporting cuts the time an attacker has to move.

Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Attackers research your staff before writing a single email. See what OSINT reveals, where it comes from, and how...
Modern phishing kits bypass MFA, hide from scanners, and ask victims to run commands. See what the tools now...
Gateways filter mail before delivery. API-based tools inspect it inside the mailbox. See how they differ, where each fails,...
Table of Contents
×