irs program accomplishments · form 990 part iii · fy2025
What they reported doing
- #1 primary $13.46MTHE MS-ISAC PROGRAM PROVIDES A COMMON MECHANISM FOR RAISING THE LEVEL OF CYBERSECURITY READINESS AND RESPONSE IN EACH STATE AND WITH LOCAL GOVERNMENTS AND U.S. TRIBES AND TERRITORIES WITH THE GOAL OF IMPROVING THE OVERALL CYBERSECURITY POSTURE OF U.S. STATE, LOCAL, TRIBAL, AND TERRITORIAL (SLTT) GOVERNMENT ENTITIES. THE MS-ISAC PROGRAM COLLABORATES AND SHARES INFORMATION WITH ITS SLTT GOVERNMENT MEMBERS, PRIVATE SECTOR AND FEDERAL GOVERNMENT PARTNERS. THE MS-ISAC PROGRAM LEVERAGES TRUSTED RELATIONSHIPS WITH GOVERNMENT AND PRIVATE SECTOR ENTITIES TO GENERATE COORDINATED AND ACTIONABLE INTELLIGENCE PRODUCTS TO IMPROVE THE SECURITY POSTURE OF ALL PARTNERS. THE MS-ISAC ALSO PRODUCES EDUCATIONAL MATERIALS, MANAGES WORKGROUPS MADE UP OF SLTT MEMBERS, AND OPERATES IMPORTANT NATIONAL CYBER SECURITY PROGRAMS. THE DEPARTMENT OF HOMELAND SECURITY (DHS) DISCONTINUED FUNDING FOR THIS PROGRAM ON SEPTEMBER 29, 2025, AT WHICH TIME A FEE-BASED MEMBERSHIP MODEL WAS IMPLEMENTED, WHERE SLTT MEMBER ORGANIZATIONS PAY A YEARLY MEMBERSHIP FEE TO RECEIVE MS-ISAC BENEFITS AND SERVICES.
- #2 $31.94MTHE CIS SERVICES PROGRAM OFFERS SERVICES TO ALL STATE, LOCAL, TERRITORIAL, AND TRIBAL ENTITIES AND PUBLIC AUTHORITIES TO IMPROVE THEIR OVERALL CYBER AND ELECTION SECURITY. THESE SERVICES INCLUDE SCANNING, SECURITY ASSESSMENTS, PHISHING EXERCISES, AND OTHER CYBER SECURITY RELATED SERVICES.
named programs · 6 · from sources
What they call their work
CIS Benchmarks
Over 100 configuration guidelines for securely setting up IT systems and software across more than 25 vendor product families.
CIS Controls
A prioritized set of actions to defend against known cyber attacks, developed and refined by global cybersecurity experts.
CIS CyberMarket
Leverages collective purchasing power to provide SLTT organizations with vetted, cost-effective cybersecurity solutions from trusted vendors.
CIS SecureSuite
Membership program providing access to tools, resources, and services to implement CIS Benchmarks and Controls.
EI-ISAC
Supports election infrastructure security through collaboration, information sharing, and threat prevention for state, local, tribal, and territorial election offices.
MS-ISAC
Provides real-time threat intelligence, 24x7x365 support, and member-exclusive tools to improve cybersecurity readiness for state, local, tribal, and territorial government entities.
activities · 2 groups
What they do
-
Privacy-Preserving Cybersecurity & Data Collaboration 11 activities
- Deliver managed cybersecurity detection and response servicesProvides 24x7x365 monitoring and management of endpoint and network security through CIS Managed Detection and Response (MDR), including real-time threat protection, automated malware analysis, remote incident analysis, and centralized visibility across multiple organizations.
- Develop and maintain CIS Controls and BenchmarksCreates and updates globally recognized best practices for securing IT systems, including the CIS Controls and over 100 configuration guidelines (CIS Benchmarks) across more than 25 vendor product families.
- Lead global cybersecurity community collaborationEngages a global community of IT professionals to collaboratively evolve cybersecurity standards, share knowledge, and develop products and services that defend against emerging threats.
- Offer vulnerability assessment and penetration testing servicesConducts network and web application penetration tests and vulnerability assessments to identify security weaknesses and enable remediation, improving organizational security posture.
- Operate EI-ISAC for election infrastructure securityImproves the cybersecurity posture of state, local, tribal, and territorial election offices through collaboration, information sharing, and coordinated threat intelligence with federal partners and private sector entities.
- Operate Malicious Code Analysis Platform (MCAP)Provides a web-based sandbox environment using Cisco Secure Malware Analytics that allows U.S. SLTT members of MS-ISAC to analyze suspicious files and URLs, identify malware, and generate threat intelligence.
- Operate Multi-State Information Sharing and Analysis Center (MS-ISAC)Provides cyber threat prevention, protection, response, and recovery support to U.S. state, local, tribal, and territorial (SLTT) governments through a 24x7x365 Security Operations Center, actionable alerts, incident response assistance, and threat intelligence sharing.
- Provide CIS Hardened Images for secure cloud computingDelivers secure, on-demand, scalable cloud computing environments through pre-configured, hardened virtual images designed to reduce attack surface and improve security in cloud deployments.
- Provide Malicious Domain Blocking and Reporting Plus (MDBR+)Operates a cloud-based protective DNS service that blocks access to malicious domains using integrated threat intelligence from Akamai and CIS, enables custom acceptable use policies, and delivers real-time reporting and off-network device protection for SLTT governments and private hospitals.
- Publish cybersecurity research and white papersProduces and disseminates research publications, including white papers on cybersecurity incident response, to promote coordinated defense practices and inform the broader security community.
- Support major event cybersecurity preparednessPartners with international organizations and law enforcement to strengthen cybersecurity defenses for high-profile events such as the FIFA World Cup through planning and coordination.
-
-
Uncategorized 1 activity
- Negotiate cost-effective cybersecurity solutions for SLTT organizationsLeverages collective purchasing power of over 18,000 MS-ISAC members to negotiate and provide trusted, affordable cybersecurity products and services for state, local, tribal, and territorial organizations.
-
financials · form 990 · fy2025
revenue
Total revenue$126.26M
Contributions & grants$17.22M14%
Program service revenue$104.57M83%
Investment income$4.23M3%
Other revenue$235K
expenses
Total expenses$143.06M
Program expenses63%
Admin / overhead37%
Fundraising0%
Salaries & benefits$84.44M
Grants paid out$548K
Largest expense lineCompensation
balance sheet
Total assets$83.63M
Cash$12.72M
Investments$39.01M
Liabilities$72.58M
Net assets$11.05M
Liquid reserves4.3 mo
6 years on record · 2020–2025 · YoY revenue -4.9%
leadership · form 990 part vii · fy2025
Who runs it
paid leadership · 25
| Name | Title | Hours/wk | Compensation |
|---|---|---|---|
| JOHN GILLIGAN | PRESIDENT & CEO | 40 | $1.24M |
| JOHN COHEN | EXECUTIVE DIRECTOR, COUNTE | 40 | $641K |
| REGINA CHAPMAN | COO (FORMER) | 40 | $601K |
| LISA GREENE | GENERAL COUNSEL AND CLO | 40 | $555K |
| CURTIS DUKES | EXECUTIVE VP AND GM OF SBP | 40 | $537K |
| ALBERT SZESNAT | CHIEF FINANCIAL OFFICER | 40 | $522K |
| THOMAS MICHELLI | EXECUTIVE VP & GM OF OSS (FORMER) | 40 | $508K |
| LEE NORIEGA | EXECUTIVE DIRECTOR OF CSO | 40 | $486K |
| CAROLYN COMER | CHIEF HUMAN RESOURCES OFFI | 40 | $455K |
| ANGELO MARCOTULLIO | CHIEF INFORMATION OFFICER | 40 | $400K |
| JANE JUDGE | VP OF PROGRAM MANAGEMENT | 40 | $352K |
| TONY WILSON SAGER | SVP & CHIEF EVANGELIST | 40 | $348K |
| CARLOS PERRY KIZZEE | SVP, MS-ISAC STRATEGY & PL | 40 | $344K |
| ROBERTA BOBBIE STEMPFLEY | BOARD CHAIR | 5 | $101K |
| CYNTHIA VALLES | DIRECTOR | 2 | $75K |
| CHRIS PAINTER | DIRECTOR | 3 | $73K |
| WILLIAM PELGRIN | DIRECTOR | 2 | $73K |
| TRACY DOAKS | DIRECTOR | 2 | $71K |
| JANE HOLL LUTE | DIRECTOR | 2 | $67K |
| BRUCE MOULTON | DIRECTOR | 3 | $66K |
| RICHARD SCHAEFFER | DIRECTOR | 2 | $65K |
| RAMON BARQUIN | DIRECTOR (FORMER) | 2 | $37K |
| DAN DEENEY | DIRECTOR | 2 | $29K |
| ELIZABETH MORA | DIRECTOR | 2 | $29K |
| MELVIN WESLEY | TREASURER | 3 | $29K |
relationships · 23
Who they work with
- Akamai Partner — Industry partner providing threat intelligence feeds and the Akamai Control Center for the MDBR+ service.
- Akamai Partner — Supplies multiple cybersecurity products including MFA, Guardicore Segmentation, DNS Posture Management, Edge PDNS, and App & API Protection via the CIS CyberMarket.
- Amazon Web Services (AWS) Partner — Hosts the MDR Spotlight capability in AWS Cloud.
- Censys Partner — Provides a platform for threat hunting through the CIS CyberMarket.
- Cisco Partner — Partners with Cisco to leverage Cisco Secure Malware Analytics in the Malicious Code Analysis Platform (MCAP).
- Cisco Partner — Partners with Cisco to use Secure Malware Analytics sandbox for malware analysis within the MCAP platform.
- CyberWA Partner — Offers a cyber audit platform for risk assessment through the CIS CyberMarket.
- DuoCircle Partner — Offers Phish Protection and DMARC reporting for email security through the CIS CyberMarket.
- Enzoic Partner — Offers Active Directory integration for password policy compliance through the CIS CyberMarket.
- FIFA Partner — Collaborated with CIS to prepare cybersecurity defenses for the World Cup.
- Invary Partner — Provides runtime integrity service for vulnerability management through the CIS CyberMarket.
- MS-ISAC Network — Operates the Cyber Incident Response Team (CIRT) that provides free incident response support to Albert members.
- Multi-State Information Sharing and Analysis Center Network — Operates the MS-ISAC as part of its core services for U.S. state, local, tribal, and territorial governments.
- Multi-State Information Sharing and Analysis Center Network — U.S. SLTT member organizations of MS-ISAC receive access to the Malicious Code Analysis Platform (MCAP).
- Multi-State Information Sharing and Analysis Center Partner — Operates the MS-ISAC to support state, local, tribal, and territorial governments with cybersecurity threat intelligence and collaboration.
- Multi-State Information Sharing and Analysis Center (MS-ISAC) Partner — Provides cybersecurity support services to public-sector agencies through a paid membership program.
- Multi-State Information Sharing and Analysis Center® Network — CENTER FOR INTERNET SECURITY INC operates the MS-ISAC and provides MCAP services exclusively to its U.S. SLTT member organizations.
- National Governors Association Partner — Collaborates on initiatives related to state cybersecurity preparedness and critical infrastructure protection.
- Palo Alto Networks Partner — Provides cybersecurity services and products including Cortex Cloud, Unit 42, and Prisma Browser through the CIS CyberMarket.
- SANS Partner — Offers workforce security training, technical training courses, and cyber ranges through the CIS CyberMarket.
- U.S. Department of Homeland Security Government — Collaborates with the MS-ISAC and EI-ISAC programs on cybersecurity information sharing and intelligence coordination.
- Zscaler Partner — Provides the Zero Trust Exchange platform for secure network access through the CIS CyberMarket.
- host-city law enforcement Partner — Collaborated with CIS to prepare cybersecurity defenses for the World Cup.
strategies · 4
How they approach the work
Named approaches extracted from this org’s sources. Where others share an approach, follow it to see the full set of orgs running it.
- Community-Driven Cyber Defensemethodology: community-driven collaborationBy fostering collaboration among state, local, tribal, and territorial (SLTT) governments and leveraging collective expertise, we produce more effective and timely defenses against emerging cyber threats because shared knowledge and peer-vetted practices lead to faster adaptation and stronger collective resilience.
- Equitable Access Through Collective Capacity Buildingmethodology: equitable-access_modelBy aggregating purchasing power and extending protective services regardless of organizational size, we ensure equitable access to advanced cybersecurity tools because economies of scale and inclusive service design lower barriers for under-resourced public entities.
- Prioritized, Expert-Driven Security Controlsmethodology: cid-controlsBy implementing the CIS Controls—a prioritized set of expert-driven security actions—we produce stronger cyber defenses because focusing on high-impact measures ensures efficient use of limited resources and addresses the most common attack vectors first.
- Trusted Intelligence Sharing Networkmethodology: trusted-intelligence-sharing-networkBy operating a trusted, nonpartisan, and vendor-agnostic information-sharing network, we improve cybersecurity posture across public-sector organizations because neutrality builds trust, encourages participation, and enables timely dissemination of actionable threat intelligence.