Watch hub·govramp · stateramp · tx-ramp · ny-dfs-500

State & Local

GovRAMP, state cyber and privacy laws, municipal compliance, and the patchwork below the federal line.

Updated ·RSS ↗

States and municipalities are building their own cybersecurity regimes for vendors handling state and local data. GovRAMP (formerly StateRAMP) is the dominant cross-state framework; TX-RAMP, NY DFS Part 500, and CJIS run alongside it. This hub indexes those programs, tracks alignment (and divergence) with federal frameworks, and surfaces state-level enforcement and policy movement.

What changed in the last 30 days

  • vuln-advisory/standards

    CISA puts first PAN-OS GlobalProtect auth bypass on KEV

    CISA added CVE-2026-0257, an authentication bypass in PAN-OS GlobalProtect portal and gateway interfaces, to its Known Exploited Vulnerabilities catalog on June 22 based on evidence of active exploitation. The vulnerability affects PAN-OS 10.2, 11.1, and 11.2 across dozens of patch trains when GlobalProtect is configured with authentication override cookies enabled and a specific certificate configuration present. Palo Alto Networks reports limited exploit attempts in the wild. Prisma Access customers are on a managed upgrade schedule; self-managed PAN-OS instances require immediate patching.

  • ics-ot/trade-press

    Nobody tracked the cellular modems on water controllers

    In July, intruders compromised water and wastewater controllers across multiple states through an exposure no asset inventory caught: the devices were connected to public cellular networks, not the city LAN. The modems appeared on carrier invoices but nowhere on network scans. The former CIO of Waco, Texas, writing from direct experience, argues the core problem isn't technical. No single person owns accountability for the whole municipal network. Matching carrier invoices to actual devices costs nothing in tools or headcount and can start this fiscal year with money already in a budget request.

  • municipal/trade-press

    Minnesota extends cybersecurity baseline to local governments

    Minnesota CISO John Israel's office is expanding a statewide cybersecurity baseline program to local governments and critical infrastructure. The effort, built on a 2023 plan and backed by DHS grant funding, runs on three pillars: baseline assessments to help entities build a security program, enterprise-class tools offered at no or low cost through the state's buying power, and a team of cyber navigators who build ongoing relationships with local governments. Israel said the data shows that entities hit by ransomware and other attacks are the ones that haven't adopted the capabilities. The plan doesn't mandate use of state services, the goal is baseline controls, however sourced.

  • cisa/standards

    PowerShell RAT and Dual RMM Tools Target SLTT Governments

    CIS CTI identified an active phishing campaign targeting U.S. SLTT governments with a custom PowerShell WebSocket RAT and dual remote monitoring and management tools for persistence. The adversary chains a PowerShell backdoor with two separate RMM installations, betting that under-resourced government IT teams won't detect all three. The dual-RMM approach echoes CISA's 2023 advisory on malicious RMM use, but the deliberate redundancy signals an adversary who expects endpoint monitoring gaps and builds around them.

  • ics-ot/trade-press

    CRS maps three paths for water-sector cyber standards

    A new Congressional Research Service report catalogs the legislative options for water-sector cybersecurity after July 2026 attacks hit utilities in seven states. Three competing approaches are on the table: Capito's WRDA bill funds technical assistance under existing SDWA authorities; the Schiff-Klobuchar package directs EPA to set baseline cybersecurity standards through rulemaking; and the Trahan-Markey bill creates a wastewater cyber grant program. The CRS report flags unresolved questions on whether standards would apply uniformly to the roughly 170,000 U.S. water systems (many already struggling with existing SDWA requirements) and whether EPA or state regulators have the expertise to oversee them.

  • cisa/trade-press

    CISA grant program stares down Sept. 30 lapse, states told to triage

    The State and Local Cybersecurity Grant Program's authorization expires Sept. 30, 2026, and former state cyber officials are advising governments to adopt risk-based prioritization now rather than wait for reauthorization. The program, funded at $1 billion over four years by the 2021 infrastructure law, saw a short-term extension in January but faces an uncertain path forward in the Senate despite bipartisan House support. Former North Carolina CIO James Weaver called the sentiment among states "anxiety, the fact is there is no extension of it."

  • municipal/trade-press

    Suisun City 911 dispatch taken down in ransomware attack

    Suisun City, California, shut down its entire IT network Friday after ransomware hit critical systems including 911 routing, police dispatch, and city records. The city declared a state of emergency. The same week, Coweta, Oklahoma; Mitchell, South Dakota; Coryell County, Texas; and Washburn County, Wisconsin disclosed cyberattacks disrupting government services. Emergency calls in Suisun City are now routed through the county dispatch center, and the FBI is investigating.

Open questions

  • 01Which states are next to mandate a vendor authorization regime?
  • 02How aligned is GovRAMP's revised baseline with FedRAMP 20x?
  • 03How do state privacy laws and CJIS interact with federal CUI handling for cross-jurisdictional vendors?

Sources we watch

Earlier coverage