What Happens After the Grant? Sustaining Cyber Readiness in 9-1-1
A grant can help a 9-1-1 center start important technology and cybersecurity work. It cannot carry the recurring work by itself. Directors can make a stronger budget case when they show the full lifecycle cost of critical systems, identify who owns each ongoing responsibility, and connect cyber readiness to keeping 9-1-1 available under pressure.
There is a lot that falls at the feet of 9-1-1 leadership: staffing, technology modernization, training, governance, cybersecurity, and service continuity. And they’re all competing for funding. An agency can receive a grant, buy equipment, or complete a project; then next year arrives. Systems still need monitoring. Staff still need training. Software still needs maintenance. Plans still need to be tested.
The real budget question becomes: can the agency keep funding the people and work required to maintain cyber readiness year after year?
Grants Can Start the Work, but They Cannot Sustain It Alone
Grants have an important place in public safety. They can help agencies start assessments, upgrades, training efforts, or new capabilities that might otherwise remain out of reach. The challenge is not the grant itself. The challenge is what happens when the funding ends, but the responsibility continues.
This matters for directors preparing budget requests. If a grant pays for the first year of cybersecurity services, the agency still must answer what happens next. If a grant pays for a tool, someone still needs to manage it, monitor it, act on alerts, and keep the program current.
CISA's FY 2025 State and Local Cybersecurity Grant Program, or SLCGP, shows why agencies should not treat grants as a complete plan. CISA reported that total program funding decreased from $279.9 million in FY 2024 to $91.7 million in FY 2025. For most single-entity projects, the federal share was 60 percent, with the remaining 40 percent documented through allowable non-federal cash or in-kind contributions. Multi-entity projects were treated differently, and local arrangements can vary. This is historical FY 2025 context, not a statement about current availability. The point is simple: when grant rules, match requirements, or funding levels change, agencies still need a plan to sustain the work.
Readiness Has Ongoing Costs
A director does not need to become a cybersecurity engineer to ask better questions:
- What are we doing about cybersecurity today?
- Do we have monitoring?
- What protections are already in place?
- Who reviews alerts or suspicious activity?
- When did we last test our response plan?
- What recurring costs will continue after this purchase or grant ends?
Those questions move the conversation from tools to readiness.
The same funding pattern shows up across 9-1-1 technology. Computer-aided dispatch, or CAD, platforms used to manage and dispatch incidents; call-delivery software that routes emergency calls; administrative office suites; routers; firewalls; endpoint protection on workstations and servers; annual subscriptions; licensing; support; maintenance; upgrades; and training all create costs after the first purchase. Cybersecurity is one part of that larger operating reality.
A stronger cybersecurity budget also accounts for people and recurring work. That can include awareness training; tabletop exercises that let leaders practice incident decisions; vulnerability assessments that identify weaknesses; controlled penetration tests that show whether weaknesses can be exploited; response planning; ongoing monitoring and alert review; maintenance; and staff time. Some agencies may build that capacity internally, and others may contract with specialists. Either path creates recurring costs. That is why a one-time budget frame can make the agency look funded on paper while leaving the ongoing work exposed.
For a director, the goal is to turn recurring work into a defined operating capability. The budget should show what repeats, what service it sustains, who owns it, and what happens if funding lapses. For cybersecurity, that means naming who funds monitoring and alert response, recurring training and exercises, scheduled testing, maintenance, and staff or contracted support.
One example from OTM Cyber's work shows why the distinction matters. A public-safety customer operated within a larger county network. When the wider county environment experienced a cyber incident, the monitored public-safety environment did not experience operational interference. Early detection and automated response stopped anomalous traffic before it reached emergency operations.
The outcome did not come from a single purchase. It depended on monitoring and response that were funded, maintained, and active before the incident. That is the kind of capability recurring service, subscription, or staffing dollars keep available over time.
This Is a Continuity Case
The strongest cybersecurity argument is operational. Emergency communications must remain available when the surrounding environment is under pressure. Directors already understand continuity—backup power, redundant systems, staffing plans, radio procedures, and mutual aid all exist because the mission cannot pause while someone sorts out a failure. Cybersecurity belongs in that same conversation.
This continuity case raises a harder funding question: what level of interruption, confusion, response delay, recovery cost, or damage to public trust is the agency prepared to absorb if its systems are not ready?
That does not mean every center owns every part of the answer. Responsibility should follow authority and dependency. The director owns the mission case: what the center depends on, what interruption would mean, and what capability must remain funded. County or city IT may own the network, backups, identity systems, and technical controls. A state may shape policy, funding, or shared services. A vendor may provide monitoring, testing, or response support under a defined agreement.
The director still has a role when another group owns part of the technology. The director can make those dependencies visible, confirm who owns each recurring task, and bring any gap into the funding conversation. If the center depends on a county network, the director can ask how emergency-response systems are protected. If state policy affects funding, the director can explain what the current model does not cover. If local finance leaders see cybersecurity as a one-time IT expense, the director can reframe it as part of keeping 9-1-1 available.
A Better Technology Funding Conversation for 9-1-1 Directors
Directors can make the funding case stronger by asking for the full lifecycle of the systems the center depends on. That includes acquisition, implementation, annual subscriptions or licensing, maintenance, support, training, staffing, testing, upgrades, and eventual replacement.
Those costs sustain real services: call delivery, dispatch, administrative continuity, cyber monitoring, recovery, and staff readiness. They also help decision-makers see that the need does not end when the first invoice is paid.
That conversation needs the right people in it before the budget is due. Depending on the center, that may include county commissioners, city leadership, finance teams, state 9-1-1 offices, legislators, technology leaders, emergency management partners, and vendors. The exact group will vary, but the goal is the same: make recurring technology costs part of the ongoing public-safety funding conversation before they become late budget add-ons.
Cybersecurity is the clearest example in this article, but the same logic applies across 9-1-1 technology. The director does not have to own every technical control. The director does have to expose the dependencies, show where ownership is unclear, and make the mission case before the budget conversation is already closed.
For 9-1-1 leaders who want to continue the broader funding conversation, September's episode of The Ready Line will look beyond agency budgets. Devin Lukomski, OTM Cyber President, and Dan Koenig, Senior Manager of 9-1-1 Program Services in Palm Beach County (FL), will discuss advocacy, public support, government relationships, and creative paths to more sustainable funding for 9-1-1. Cybersecurity is one part of that larger conversation because reliable service depends on sustained investment in people, operations, security, and technology. Join us September 30 at 2 pm ET for The Ready Line; register here.
Sources and Further Reading
CISA, State and Local Cybersecurity Grant Program Key Changes, FY 2025
CISA, FY 2025 State and Local Cybersecurity Grant Program Frequently Asked Questions
Get practical cyber readiness updates
Receive OTM Cyber insights, relevant event invitations, and guidance for leaders who have to keep operations moving.
Continue the conversation.
Explore related services or talk with OTM Cyber about the cybersecurity pressures facing your environment.