About SLCGP
A federal program, built for state and local governments
In September 2022, the Department of Homeland Security announced a cybersecurity grant program for State, Local, Tribal, and Territorial (SLTT) governments. SLCGP, alongside its companion Tribal Cybersecurity Grant Program, helps eligible entities address cybersecurity risks and threats to information systems owned or operated by, or on behalf of, SLTT governments.
In Delaware, the program supports a whole-of-state approach by connecting federal resources, statewide priorities, program governance, and local cybersecurity needs. SLCGP isn’t just funding — it’s planning, coordination, and risk reduction, aimed at moving Delaware from reactive incident response toward proactive resilience.
Three requirements anchor every award
Assessments and evaluations
The intake assessment establishes a baseline and helps the SLCGP team understand each municipality’s needs, risks, and priorities.
Cybersecurity best practices
Every project aligns to CISA’s recommendations for critical infrastructure and public-sector organizations.
A statewide Cybersecurity Plan
A planning document approved by the Committee and the State’s CIO/CISO, anchoring every award.
Delaware’s Cybersecurity Plan pursues this through four goals
Every SLCGP-funded project is prioritized against the current threat landscape and tied back to one of these.
Establish a risk baseline
Risk and cyber-maturity assessments, incident response plans, and SOPs to close the gaps.
Detect and respond
.gov domains statewide and threat detection tooling local governments couldn’t fund alone.
Modernize IT and OT
One coordinated strategy for IT, OT, and IoT — prioritized by impact to human life and sector.
Put CISA services to work
Enroll every entity in CISA vulnerability and web-app scanning, promoted statewide.
What the Program Helps Improve
SLCGP supports practical cybersecurity improvements tied to real risk — strengthening protection, improving visibility, reducing exposure, and preparing for threats that can disrupt public services.
Eligible municipalities may be able to receive certain cybersecurity tools and services at no additional cost, depending on program requirements, available resources, and current priorities.
Identity and access security
Authentication, access controls, account protection, and multi-factor authentication.
Security testing and assessments
Penetration testing, vulnerability assessments, and cybersecurity capability reviews.
Endpoint Protection (EPP)
Improved protection and visibility for workstations, servers, and other endpoint devices.
Web Application Firewall (WAF)
Protecting public-facing websites, payment portals, and citizen-facing services.
Security infrastructure modernization
Replacing end-of-life systems or network components that create cybersecurity risk.
Operational resilience
Public works, water/wastewater, SCADA, OT, network segmentation, and continuity planning.
Training and awareness
Helping staff, leadership, and partners understand cyber risk and good security practices.
