Revival of the State and Local Cybersecurity Grant Program: The PILLAR Act
The U.S. House of Representatives has taken a significant step towards bolstering cybersecurity at the state and local levels by voting to revive the State and Local Cybersecurity Grant Program (SLCGP). This revival comes through the newly proposed legislation known as the Protecting Information by Local Leaders for Agency Resilience (PILLAR) Act. The bill received strong bipartisan support and is poised for further consideration in the U.S. Senate, having been referred to the Committee on Homeland Security and Governmental Affairs.
Key Highlights of the PILLAR Act
One of the most pressing aspects of the PILLAR Act is its intent to reauthorize the SLCGP for an additional seven years, running until 2033. This move aims to provide stability to the program, which plays a crucial role in equipping local governments to defend against a range of cyber threats, from rogue hackers to well-resourced nation-state actors. It includes provisions to stabilize cost-sharing requirements and encourages the implementation of multifactor authentication, which is critical for enhancing cybersecurity postures.
Additionally, the PILLAR Act addresses new technological realities, including artificial intelligence, providing a forward-looking perspective on cybersecurity needs. Importantly, it seeks to ensure outreach to smaller and rural communities, thereby extending the benefits of cybersecurity funding to those who often face the toughest challenges.
The Legacy of the SLCGP
The SLCGP was initially established under the Infrastructure Investment and Jobs Act of 2021, providing a substantial $1 billion to enhance cybersecurity defenses across various state and local jurisdictions. Prior to its expiration in September 2023, the program successfully funded initiatives that strengthened protective measures for essential government services and critical infrastructure, shielding them from escalating cyber threats.
During its four years of operation, the SLCGP supported a diverse range of cybersecurity efforts. For instance, in New Jersey, Chief Information Security Officer (CISO) Michael Geraghty highlighted the program during a recent cyber summit, emphasizing its valuable contributions despite budgetary constraints. The initiative facilitated a state-wide approach, which included statewide volume licensing for cybersecurity tools and significant support for 153 municipalities, effectively blocking over 200 ransomware attacks.
Real-World Applications: How States Utilized SLCGP Grants
In practical terms, grants from the SLCGP made a significant difference across various states. New Jersey, as mentioned, focused on a holistic approach, providing local governments and agencies with essential tools and technologies at an accelerated pace. This has proven critical in their fight against active cyber threats.
Meanwhile, Washington State utilized its allocation for local jurisdictions to fund critical cyber practitioner training and policy development. Ralph Johnson, CISO of Washington, explained that the state also employed a pre-allocation strategy to ensure that promising proposals from the previous year were funded in subsequent rounds, demonstrating the demand and urgency for cybersecurity resources.
Advocacy for Renewal
The call for the renewal of the SLCGP has been persistent among state and local government leaders, who have recognized its role in mitigating “critical cybersecurity vulnerabilities.” The National Association of State Chief Information Officers (NASCIO) has been particularly vocal, providing testimony in Congress and emphasizing the program’s importance in enhancing local cybersecurity frameworks.
During a recent subcommittee hearing, Utah CIO Alan Fuller and Connecticut CIO Mark Raymond urged Congress to maintain the program, highlighting its integral role in addressing cybersecurity gaps in local communities. Their testimonies underscored a unified call for the federal government to solidify funding availability and ensure program continuity.
Moving Forward
As the PILLAR Act moves to the Senate, its future could significantly influence how state and local governments prepare for the evolving cybersecurity landscape. The focus on providing long-term stability is crucial for empowering these governments to allocate resources effectively and invest in sustainable cybersecurity solutions.
In essence, the revival of the SLCGP through the PILLAR Act represents an essential commitment to enhancing the cybersecurity resilience of local governments across the United States, ensuring they are better equipped to face an increasingly complex digital threat landscape.

