October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Trump’s Cyber-Readiness Shift Puts More Pressure on States and Local Governments

Executive Order 14239 signals a larger state and local preparedness role, but does not transfer cyber-defense authority. Reported cuts to coordination channels raise questions about funding, staffing, and practical support.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Executive Order 14239 did not formally hand cyber defense to governors, mayors, or local agencies. Signed March 18, 2025, it called for a larger state and local role in national preparedness and resilience, including readiness for cyberattacks. The practical concern is that this expectation arrived amid reported reductions to federal information-sharing and coordination support—without a dedicated cyber-readiness appropriation for local governments.

What Executive Order 14239 changed—and what it did not

The order, “Achieving Efficiency Through State and Local Preparedness,” was signed on March 18, 2025, and published by the White House the next day. It treats cyberattacks as one of several risks that communities should prepare for, within a broader national resilience policy.

Its central policy direction is to move from an all-hazards approach toward risk-informed planning and “beyond information sharing to action.” That can mean translating threat information into mitigation, exercises, procurement, and recovery plans. It does not mean information sharing is no longer needed, nor does the order itself create a new cyber incident-command system.

The order does not expressly transfer cyber-defense authority, repeal CISA’s statutory responsibilities, or prescribe a new state-by-state operating model. It says state and local governments should take a more active role while receiving federal support, subject to applicable law and available appropriations. Describing this as a shift of preparedness responsibility is an interpretation of the policy direction—not a literal legal transfer of cyber defense.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

The order’s deadlines and federal assignments

The order directed federal policy work on several timelines. The White House text establishes the deadlines; it does not, by itself, establish whether each deliverable was completed.

Assignment Deadline in the order What it calls for
National Resilience Strategy 90 days after the order Set out national resilience priorities, means, and methods.
National Critical Infrastructure Policy 180 days after the order Review existing policy; favor risk-informed planning over an all-hazards model and action informed by, but not limited to, information sharing.
National Continuity Policy 180 days after the order Modernize and streamline continuity capabilities and establish an enduring readiness posture.
Preparedness and response policies 240 days after the order Review federal policies and reformulate the process and metrics for federal responsibility.
National Risk Register 240 days after the order Identify and quantify natural and malign risks to national infrastructure, systems, and users, to inform intelligence priorities and public- and private-sector investment.
Federal “functions” framework Within one year The Secretary of Homeland Security is to propose changes intended to improve state and local communications with federal officials and clarify the federal role.

These assignments make implementation consequential. A policy document or risk register does not itself provide local monitoring staff, incident-response retainers, recovery capacity, or a reliable route to federal assistance.

Why the reported information-sharing reductions matter

In a March 2025 account, CSO reported reductions or changes affecting several coordination channels: a $10 million reduction affecting the Multi-State Information Sharing and Analysis Center (MS-ISAC), loss of federal support for the Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC), and elimination of the Critical Infrastructure Partnership Advisory Council (CIPAC). CSO also reported that CISA allocated $25 million to the Center for Internet Security (CIS), described as slightly more than 70% of the initially planned amount.

Those are distinct reported developments, not proof that all federal-state cyber information sharing ended. CSO reported that the CISA–CIS cooperative agreement remained in place. The figures and program status are time-sensitive and should be read as CSO’s reporting, not as confirmation of each program’s current fiscal-year position.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
SecuX PUFido® Drive Clife Key USB C Security Key with PUF Technology and Built in Flash Drive, FIDO2 U2F Certified Hardware Rooted Unclonable Security for Passwordless Login and 2FA Authentication (1)
  • Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
  • FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
  • Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
  • Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
  • Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.

What these channels provide beyond alerts

Information-sharing organizations can connect agencies, distribute indicators and guidance, support exercises, provide trusted contacts, and help turn scattered reports into a wider picture of an attack. Their value is partly operational: a small city may not have a security operations center, threat-hunting staff, malware analysts, or access to sensitive intelligence. A shared forum can lower the cost of establishing those relationships independently.

“Beyond information sharing to action” is not a choice between intelligence and mitigation. Intelligence that never changes a system is of limited use; mitigation without timely intelligence can leave defenders reacting blindly. A useful cycle is to receive credible indicators, prioritize protective steps, check whether those steps worked, and share relevant findings through appropriate channels.

Where a responsibility shift could land hardest

Local capacity varies widely. Large cities and some states have mature security teams; small and rural governments may have few dedicated staff and limited procurement leverage. The exposure is shaped by state support, shared services, regulation, vendor contracts, technology architecture, and mutual-aid arrangements—not simply by population size.

  • Small municipalities and rural counties: A single IT team may be responsible for security, daily support, and recovery.
  • Schools, hospitals, and utilities: Disruption can affect education, patient care, water, wastewater, power, or other essential services.
  • Election offices: They depend on reliable coordination and must protect both systems and public confidence.
  • Emergency communications and public safety: 911, dispatch, and response systems may rely on shared identity, network, or vendor infrastructure.
  • Transport, ports, and operational technology: A cyber incident can impair physical operations, not just administrative IT.
  • Governments dependent on a few vendors or aging systems: A provider outage, unsupported technology, or compromised management account can become a critical dependency.

A connected weakness can have effects beyond the jurisdiction where an intrusion begins. That makes common escalation paths and coordination useful even when local officials retain authority over their own response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Is this an unfunded mandate?

“Unfunded mandate” is an expert criticism, not a settled legal finding established by the order. The order makes implementation subject to applicable law and available appropriations; it does not create a dedicated cyber-readiness appropriation for states and municipalities. CSO quoted experts who warned that more risk-management responsibility could fall on governments without equivalent money, staffing, or technical capacity.

The practical funding question is whether jurisdictions can sustain the capabilities expected of them. A grant may help buy equipment, but recurring monitoring, alert triage, staff retention, patching, renewals, incident exercises, and restoration testing require ongoing resources. A tool without personnel to operate it can add cost without delivering meaningful coverage.

Statewide or regional shared services can make scarce expertise go further, and pooled purchasing may improve negotiating power. But a shared service needs clear rules for data ownership, escalation, response authority, service levels, and recovery priorities. Centralization can also concentrate risk if one identity system or management plane provides access across many jurisdictions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What state and local leaders can do

Immediate readiness checks

  • Confirm who can declare a cyber emergency and who has authority to isolate systems or disable accounts.
  • Maintain current contact lists for federal, state, regional, law-enforcement, sector, insurer, and vendor responders; verify which information-sharing or successor arrangements are actually available.
  • Prepare an out-of-band communications plan that does not depend on the identity or network systems most likely to be affected.
  • Inventory internet-facing assets, identity systems, privileged accounts, critical vendors, and operational-technology dependencies.
  • Set minimum logging and retention requirements, and confirm that key systems produce logs responders can access.
  • Keep isolated backups and test restoration, including the systems needed to restore identity and communications.
  • Review insurance and vendor contracts for notification deadlines, evidence preservation, cooperation, and incident-response obligations.
  • Run a ransomware and loss-of-communications tabletop exercise with IT, leadership, public information, legal, emergency management, and essential-service operators.

Build durable capacity

  • Assess a statewide or regional shared-security model where individual jurisdictions cannot support round-the-clock monitoring.
  • Pool procurement for endpoint, identity, vulnerability-management, backup, and incident-response services where doing so improves coverage or affordability.
  • Agree on a common severity scale and escalation matrix so neighboring agencies can coordinate without translating incompatible classifications during a crisis.
  • Establish mutual-aid agreements and pre-negotiate forensic and incident-response support before an emergency.
  • Map essential services and their dependencies, then tie investments to measurable recovery objectives rather than a raw count of IT assets.

During an incident

  1. Activate the established incident command and public-information roles; keep operational decisions and public communications coordinated.
  2. Contain affected systems while preserving evidence. Coordinate before wiping or rebuilding systems that may hold forensic information.
  3. Notify law enforcement, regulators, insurers, affected vendors, and relevant information-sharing bodies as required by applicable law, sector rules, and contracts.
  4. Keep a time-stamped record of decisions, affected systems, indicators, notifications, and restoration milestones.
  5. Restore critical services in a prioritized sequence and verify that the restored environment is safe before reconnecting it.

These steps are a practical framework, not a substitute for jurisdiction-specific legal, regulatory, insurance, or contractual requirements. Paying a ransom does not guarantee restoration or remove reporting obligations.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Thetis Pro FIDO2 Security Key Passkey with Complex Pin [PinPlex], Hardware Device Supports USB A, Type C &NFC, TOTP/HOTP Authenticator APP, PIV Certificates, FIDO 2.0 Two Factor Authentication 2FA MFA
  • Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
  • NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
  • FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
  • Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
  • Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.

How to judge a replacement coordination model

If federal or multistate channels shrink, states and localities need more than a new portal for alerts. A workable model must connect timely intelligence to people who can interpret it, act on it, and coordinate across organizations.

  • Coverage: Can the model include small jurisdictions and critical sectors, not only state agencies?
  • Operational usefulness: Does it provide trusted contacts, exercises, escalation, and actionable guidance as well as indicators?
  • Clear authority: Who can direct containment, and who owns decisions affecting local services?
  • Sustainable funding: Are ongoing staffing, monitoring, maintenance, and recovery covered, rather than only initial purchases?
  • Resilient design: Does centralization avoid creating a single point of failure or shared credentials with excessive reach?
  • Accountability: Are service levels and improvements measured by detection, response, and recovery outcomes?

A statewide security operations center can provide expertise and economies of scale, but local leaders still need clarity over priorities and response decisions. A hybrid arrangement—central monitoring and specialist support with local authority over service priorities—can balance scale with local knowledge, provided it has strong identity segmentation and agreed escalation rules.

What remains unresolved

The White House order sets deadlines but does not establish in its text whether the assigned strategies, policy reviews, and risk register were delivered. The March 2025 CSO account also cannot establish the final status of MS-ISAC, EI-ISAC, CIPAC, CISA staffing, or grant programs in later fiscal years. Those are implementation questions, not facts that can be inferred from the order’s language.

For state and local officials, the key accountability questions are whether the federal deliverables were completed, which agency owns follow-through, what appropriations support local cyber readiness, and what mechanisms now provide coordination, intelligence, exercises, and escalation. The gap to watch is whether operational expectations and dependable resources move together.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.