Virginia Public Agencies Are Rushing to Lock Down Networks Before Federal Grant Money Disappears
A 67% cut in federal cybersecurity grant funding has put Virginia localities on a spend-it-or-lose-it clock, and a ransomware attack on a suburban school district made the urgency impossible to ignore.
Virginia public agencies have issued six cybersecurity RFPs in the past 30 days, more than twice the 12-month average of 2.7 per month, and the specifics of those solicitations reveal exactly why: a water authority is hardening industrial control systems, a transit agency is auditing its train-control network, and the Attorney General's office is hiring outside counsel for cybersecurity litigation, all in the same procurement window.
This is not a single spike. Monthly counts have run at five to six since May, a sustained reversal from the one-to-three-per-month trough that stretched through January and March 2026. Something structural shifted in the spring, and three forces converged to produce it.
The most immediate is a funding deadline. CISA's State and Local Cybersecurity Grant Program cut its national allocation 67 percent, from $279.9 million in FY2024 to $91.7 million in FY2025. That cut does not cancel prior-year awards, but it signals that future tranches will be smaller or absent, which means the multi-year grants Virginia already holds are among the most valuable dollars on the table. Virginia's Department of Emergency Management, administered through VITA, is sitting on roughly $8.7 million in active SLCGP awards: a $6.55 million grant running to December 2028 and a $2.14 million grant running to August 2029. Unspent federal grant dollars that go unobligated through procurements get clawed back. The RFP surge is, in part, agencies racing the calendar.
Virginia cybersecurity RFPs per month, 2025–2026
Source: NationGraph.
The second force is a specific incident that gave every locality a concrete reason to accelerate. In March 2026, attackers breached Hanover County Public Schools, accessed school networks, and potentially exfiltrated Social Security numbers, financial account data, and government IDs belonging to students and staff. Hanover County is not a large, high-profile target. It is a mid-sized suburban school district north of Richmond, and that ordinariness was precisely the message it sent to every county administrator and IT director in the commonwealth: the threat does not discriminate by jurisdiction size.
Virginia's existing cyber incident 24-hour reporting law, which requires all state agencies and localities to notify the commonwealth's fusion center within a day of a confirmed intrusion, creates a compliance obligation that many entities are still building the tooling to meet. An agency without adequate detection and logging capability cannot satisfy a 24-hour reporting window. That gap, now visible in the aftermath of Hanover County, is accelerating procurement decisions that might otherwise wait another budget cycle.
The third force is legislative. Del. Michael Feggans (D-Virginia Beach) refiled Cyber Civilian Corps legislation in the 2026 General Assembly session after former Gov. Youngkin vetoed an earlier version, calling it premature. The new administration has not taken that position. The bill, modeled on programs already operating in Ohio, Michigan, and Wisconsin, would establish a volunteer surge capacity for state and local incident response, with a projected $410,000 startup cost at VITA. Whether or not it passes, the fact that it is moving through the General Assembly shifts the environment: agencies can reasonably expect that a formal cyber workforce apparatus is coming, which makes investments in detection and response infrastructure easier to justify now.
The Hampton Roads region is the most active cluster. Hampton Roads Transit issued a SCADA cybersecurity risk assessment RFP in May, targeting the industrial control systems that govern its transit operations. Rivanna Water and Sewer Authority posted a parallel SCADA and industrial controls solicitation the same month. Hampton Roads Sanitation District, separately, documented in its August 2026 board minutes the deployment of a Fortinet and Nutanix OT security stack across its operational technology environment, alongside a completed CISA assessment of its Oracle ERP platform. Water and wastewater utilities, transit systems, and port-adjacent infrastructure are precisely the categories CISA has identified as priority hardening targets nationally, and Virginia's Hampton Roads corridor concentrates all three within a single metropolitan area that also hosts the largest naval complex in the world.
At the other end of the state, the Virginia Attorney General's office issued a July 2026 solicitation for private counsel specializing in cybersecurity and data privacy affirmative litigation. That procurement signals a shift from purely defensive posture toward legal enforcement, suggesting the AG's office is positioning to bring claims, not just respond to breaches.
Among comparable states in the trailing 30 days, Virginia's six RFPs rank second only to California's nine, ahead of Texas at five and Maryland at four. Given Virginia's smaller overall government footprint relative to those states, the per-capita intensity of procurement activity is notable. Virginia's VITA-managed statewide IT model means a single standards update ripples across hundreds of entities simultaneously, which amplifies both the speed and the uniformity of procurement responses when the signal to move arrives.
The next visible checkpoint is the General Assembly's action on the Feggans bill. If it clears, VITA's advisory board stands up with a concrete budget and a mandate, which typically precedes another round of vendor solicitations. If it stalls, the SLCGP spend-down clock keeps running regardless: the $6.55 million award expires in December 2028, and obligating those dollars through qualified procurements requires lead time that agencies cannot afford to defer much longer.