COMMON MAPS
Map version new-york activity top-down
Main site Contact
Menu
↑ parent activity group ·
research dossier

CENTER FOR INTERNET SECURITY INC

EAST GREENBUSH, NY · EIN 522278213 · Form 990 · FY2025 · NTEE W50 · Public & Societal Benefit · Very Large (>$50M) · cisecurity.org
revenue
$126.3M
expenses
$143.1M
net assets
$11.0M
employees
542
volunteers
80
program ratio
63%
mission · from form 990

CIS IS A NON-PROFIT THAT SAFEGUARDS ORGANIZATIONS AGAINST CYBER THREATS.

profile · synthesized from sources

The Center for Internet Security (CIS) is a nonprofit that improves cybersecurity readiness for public and private organizations. It operates the Multi-State Information Sharing and Analysis Center (MS-ISAC) to support state, local, tribal, and territorial governments, and provides widely adopted security benchmarks and controls. CIS also offers services and tools to help organizations strengthen their cyber defenses and manage risk.

irs program accomplishments · form 990 part iii · fy2025

What they reported doing

  1. #1 primary $13.46M
    THE MS-ISAC PROGRAM PROVIDES A COMMON MECHANISM FOR RAISING THE LEVEL OF CYBERSECURITY READINESS AND RESPONSE IN EACH STATE AND WITH LOCAL GOVERNMENTS AND U.S. TRIBES AND TERRITORIES WITH THE GOAL OF IMPROVING THE OVERALL CYBERSECURITY POSTURE OF U.S. STATE, LOCAL, TRIBAL, AND TERRITORIAL (SLTT) GOVERNMENT ENTITIES. THE MS-ISAC PROGRAM COLLABORATES AND SHARES INFORMATION WITH ITS SLTT GOVERNMENT MEMBERS, PRIVATE SECTOR AND FEDERAL GOVERNMENT PARTNERS. THE MS-ISAC PROGRAM LEVERAGES TRUSTED RELATIONSHIPS WITH GOVERNMENT AND PRIVATE SECTOR ENTITIES TO GENERATE COORDINATED AND ACTIONABLE INTELLIGENCE PRODUCTS TO IMPROVE THE SECURITY POSTURE OF ALL PARTNERS. THE MS-ISAC ALSO PRODUCES EDUCATIONAL MATERIALS, MANAGES WORKGROUPS MADE UP OF SLTT MEMBERS, AND OPERATES IMPORTANT NATIONAL CYBER SECURITY PROGRAMS. THE DEPARTMENT OF HOMELAND SECURITY (DHS) DISCONTINUED FUNDING FOR THIS PROGRAM ON SEPTEMBER 29, 2025, AT WHICH TIME A FEE-BASED MEMBERSHIP MODEL WAS IMPLEMENTED, WHERE SLTT MEMBER ORGANIZATIONS PAY A YEARLY MEMBERSHIP FEE TO RECEIVE MS-ISAC BENEFITS AND SERVICES.
  2. #2 $31.94M
    THE CIS SERVICES PROGRAM OFFERS SERVICES TO ALL STATE, LOCAL, TERRITORIAL, AND TRIBAL ENTITIES AND PUBLIC AUTHORITIES TO IMPROVE THEIR OVERALL CYBER AND ELECTION SECURITY. THESE SERVICES INCLUDE SCANNING, SECURITY ASSESSMENTS, PHISHING EXERCISES, AND OTHER CYBER SECURITY RELATED SERVICES.
named programs · 6 · from sources

What they call their work

CIS Benchmarks
Over 100 configuration guidelines for securely setting up IT systems and software across more than 25 vendor product families.
CIS Controls
A prioritized set of actions to defend against known cyber attacks, developed and refined by global cybersecurity experts.
CIS CyberMarket
Leverages collective purchasing power to provide SLTT organizations with vetted, cost-effective cybersecurity solutions from trusted vendors.
CIS SecureSuite
Membership program providing access to tools, resources, and services to implement CIS Benchmarks and Controls.
EI-ISAC
Supports election infrastructure security through collaboration, information sharing, and threat prevention for state, local, tribal, and territorial election offices.
MS-ISAC
Provides real-time threat intelligence, 24x7x365 support, and member-exclusive tools to improve cybersecurity readiness for state, local, tribal, and territorial government entities.
activities · 2 groups

What they do

  • Privacy-Preserving Cybersecurity & Data Collaboration 11 activities
    • Deliver managed cybersecurity detection and response services
      Provides 24x7x365 monitoring and management of endpoint and network security through CIS Managed Detection and Response (MDR), including real-time threat protection, automated malware analysis, remote incident analysis, and centralized visibility across multiple organizations.
    • Develop and maintain CIS Controls and Benchmarks
      Creates and updates globally recognized best practices for securing IT systems, including the CIS Controls and over 100 configuration guidelines (CIS Benchmarks) across more than 25 vendor product families.
    • Lead global cybersecurity community collaboration
      Engages a global community of IT professionals to collaboratively evolve cybersecurity standards, share knowledge, and develop products and services that defend against emerging threats.
    • Offer vulnerability assessment and penetration testing services
      Conducts network and web application penetration tests and vulnerability assessments to identify security weaknesses and enable remediation, improving organizational security posture.
    • Operate EI-ISAC for election infrastructure security
      Improves the cybersecurity posture of state, local, tribal, and territorial election offices through collaboration, information sharing, and coordinated threat intelligence with federal partners and private sector entities.
    • Operate Malicious Code Analysis Platform (MCAP)
      Provides a web-based sandbox environment using Cisco Secure Malware Analytics that allows U.S. SLTT members of MS-ISAC to analyze suspicious files and URLs, identify malware, and generate threat intelligence.
    • Operate Multi-State Information Sharing and Analysis Center (MS-ISAC)
      Provides cyber threat prevention, protection, response, and recovery support to U.S. state, local, tribal, and territorial (SLTT) governments through a 24x7x365 Security Operations Center, actionable alerts, incident response assistance, and threat intelligence sharing.
    • Provide CIS Hardened Images for secure cloud computing
      Delivers secure, on-demand, scalable cloud computing environments through pre-configured, hardened virtual images designed to reduce attack surface and improve security in cloud deployments.
    • Provide Malicious Domain Blocking and Reporting Plus (MDBR+)
      Operates a cloud-based protective DNS service that blocks access to malicious domains using integrated threat intelligence from Akamai and CIS, enables custom acceptable use policies, and delivers real-time reporting and off-network device protection for SLTT governments and private hospitals.
    • Publish cybersecurity research and white papers
      Produces and disseminates research publications, including white papers on cybersecurity incident response, to promote coordinated defense practices and inform the broader security community.
    • Support major event cybersecurity preparedness
      Partners with international organizations and law enforcement to strengthen cybersecurity defenses for high-profile events such as the FIFA World Cup through planning and coordination.
  • Uncategorized 1 activity
    • Negotiate cost-effective cybersecurity solutions for SLTT organizations
      Leverages collective purchasing power of over 18,000 MS-ISAC members to negotiate and provide trusted, affordable cybersecurity products and services for state, local, tribal, and territorial organizations.
financials · form 990 · fy2025
revenue
Total revenue$126.26M
Contributions & grants$17.22M14%
Program service revenue$104.57M83%
Investment income$4.23M3%
Other revenue$235K
expenses
Total expenses$143.06M
Program expenses63%
Admin / overhead37%
Fundraising0%
Salaries & benefits$84.44M
Grants paid out$548K
Largest expense lineCompensation
balance sheet
Total assets$83.63M
Cash$12.72M
Investments$39.01M
Liabilities$72.58M
Net assets$11.05M
Liquid reserves4.3 mo
6 years on record · 2020–2025 · YoY revenue -4.9%
leadership · form 990 part vii · fy2025

Who runs it

paid leadership · 25
NameTitleHours/wkCompensation
JOHN GILLIGAN PRESIDENT & CEO 40 $1.24M
JOHN COHEN EXECUTIVE DIRECTOR, COUNTE 40 $641K
REGINA CHAPMAN COO (FORMER) 40 $601K
LISA GREENE GENERAL COUNSEL AND CLO 40 $555K
CURTIS DUKES EXECUTIVE VP AND GM OF SBP 40 $537K
ALBERT SZESNAT CHIEF FINANCIAL OFFICER 40 $522K
THOMAS MICHELLI EXECUTIVE VP & GM OF OSS (FORMER) 40 $508K
LEE NORIEGA EXECUTIVE DIRECTOR OF CSO 40 $486K
CAROLYN COMER CHIEF HUMAN RESOURCES OFFI 40 $455K
ANGELO MARCOTULLIO CHIEF INFORMATION OFFICER 40 $400K
JANE JUDGE VP OF PROGRAM MANAGEMENT 40 $352K
TONY WILSON SAGER SVP & CHIEF EVANGELIST 40 $348K
CARLOS PERRY KIZZEE SVP, MS-ISAC STRATEGY & PL 40 $344K
ROBERTA BOBBIE STEMPFLEY BOARD CHAIR 5 $101K
CYNTHIA VALLES DIRECTOR 2 $75K
CHRIS PAINTER DIRECTOR 3 $73K
WILLIAM PELGRIN DIRECTOR 2 $73K
TRACY DOAKS DIRECTOR 2 $71K
JANE HOLL LUTE DIRECTOR 2 $67K
BRUCE MOULTON DIRECTOR 3 $66K
RICHARD SCHAEFFER DIRECTOR 2 $65K
RAMON BARQUIN DIRECTOR (FORMER) 2 $37K
DAN DEENEY DIRECTOR 2 $29K
ELIZABETH MORA DIRECTOR 2 $29K
MELVIN WESLEY TREASURER 3 $29K
relationships · 23

Who they work with

  • Akamai Partner — Industry partner providing threat intelligence feeds and the Akamai Control Center for the MDBR+ service.
  • Akamai Partner — Supplies multiple cybersecurity products including MFA, Guardicore Segmentation, DNS Posture Management, Edge PDNS, and App & API Protection via the CIS CyberMarket.
  • Amazon Web Services (AWS) Partner — Hosts the MDR Spotlight capability in AWS Cloud.
  • Censys Partner — Provides a platform for threat hunting through the CIS CyberMarket.
  • Cisco Partner — Partners with Cisco to leverage Cisco Secure Malware Analytics in the Malicious Code Analysis Platform (MCAP).
  • Cisco Partner — Partners with Cisco to use Secure Malware Analytics sandbox for malware analysis within the MCAP platform.
  • CyberWA Partner — Offers a cyber audit platform for risk assessment through the CIS CyberMarket.
  • DuoCircle Partner — Offers Phish Protection and DMARC reporting for email security through the CIS CyberMarket.
  • Enzoic Partner — Offers Active Directory integration for password policy compliance through the CIS CyberMarket.
  • FIFA Partner — Collaborated with CIS to prepare cybersecurity defenses for the World Cup.
  • Invary Partner — Provides runtime integrity service for vulnerability management through the CIS CyberMarket.
  • MS-ISAC Network — Operates the Cyber Incident Response Team (CIRT) that provides free incident response support to Albert members.
  • Multi-State Information Sharing and Analysis Center Network — Operates the MS-ISAC as part of its core services for U.S. state, local, tribal, and territorial governments.
  • Multi-State Information Sharing and Analysis Center Network — U.S. SLTT member organizations of MS-ISAC receive access to the Malicious Code Analysis Platform (MCAP).
  • Multi-State Information Sharing and Analysis Center Partner — Operates the MS-ISAC to support state, local, tribal, and territorial governments with cybersecurity threat intelligence and collaboration.
  • Multi-State Information Sharing and Analysis Center (MS-ISAC) Partner — Provides cybersecurity support services to public-sector agencies through a paid membership program.
  • Multi-State Information Sharing and Analysis Center® Network — CENTER FOR INTERNET SECURITY INC operates the MS-ISAC and provides MCAP services exclusively to its U.S. SLTT member organizations.
  • National Governors Association Partner — Collaborates on initiatives related to state cybersecurity preparedness and critical infrastructure protection.
  • Palo Alto Networks Partner — Provides cybersecurity services and products including Cortex Cloud, Unit 42, and Prisma Browser through the CIS CyberMarket.
  • SANS Partner — Offers workforce security training, technical training courses, and cyber ranges through the CIS CyberMarket.
  • U.S. Department of Homeland Security Government — Collaborates with the MS-ISAC and EI-ISAC programs on cybersecurity information sharing and intelligence coordination.
  • Zscaler Partner — Provides the Zero Trust Exchange platform for secure network access through the CIS CyberMarket.
  • host-city law enforcement Partner — Collaborated with CIS to prepare cybersecurity defenses for the World Cup.
strategies · 4

How they approach the work

Named approaches extracted from this org’s sources. Where others share an approach, follow it to see the full set of orgs running it.

  • Community-Driven Cyber Defense
    methodology: community-driven collaboration
    By fostering collaboration among state, local, tribal, and territorial (SLTT) governments and leveraging collective expertise, we produce more effective and timely defenses against emerging cyber threats because shared knowledge and peer-vetted practices lead to faster adaptation and stronger collective resilience.
  • Equitable Access Through Collective Capacity Building
    methodology: equitable-access_model
    By aggregating purchasing power and extending protective services regardless of organizational size, we ensure equitable access to advanced cybersecurity tools because economies of scale and inclusive service design lower barriers for under-resourced public entities.
  • Prioritized, Expert-Driven Security Controls
    methodology: cid-controls
    By implementing the CIS Controls—a prioritized set of expert-driven security actions—we produce stronger cyber defenses because focusing on high-impact measures ensures efficient use of limited resources and addresses the most common attack vectors first.
  • Trusted Intelligence Sharing Network
    methodology: trusted-intelligence-sharing-network
    By operating a trusted, nonpartisan, and vendor-agnostic information-sharing network, we improve cybersecurity posture across public-sector organizations because neutrality builds trust, encourages participation, and enables timely dissemination of actionable threat intelligence.