Tribal-ISAC Cybersecurity Report Highlights for Tribal Nations

Tribal-ISAC cybersecurity report Tribal Nations cyber resilience CISA cyber risks tribal cybersecurity
Edward Zhou
Edward Zhou

CEO & Co-Founder

 
October 2, 2025
3 min read

Tribal-ISAC Cybersecurity Report Release

The Tribal Information Sharing and Analysis Center (Tribal-ISAC) released its first report, "The Pulse – The State of Cybersecurity Within Tribal Nations," during the annual TribalNet Conference and Tradeshow in early September. This report was developed with input from TribalHub and presents vital cybersecurity insights gathered from multiple sources including the 2025 "Tribal Cybersecurity" survey, TribalHub's "How Prepared is Your Tribe for AI?" survey, and Gate 15's CHIEF and NATIVE Reports.

Adam Gruszcynski, a Steering Committee Member of Tribal-ISAC and IT Director at Potawatomi Casino Hotel, stated, "The Pulse provides something we’ve never had before — data-driven insight into the real cyber risks facing Tribal Nations." This report aims to equip leaders with the information necessary to advocate for resources essential for safeguarding tribal sovereignty.

Key findings from the report include:

  • Over two-thirds of responding tribes have zero or only one dedicated cybersecurity staff member.
  • More than 60% allocate less than 20% of their technology budget toward cybersecurity.
  • 73% of respondents expect increased cybersecurity spending in 2026, while only 1% anticipate a decrease.
  • 74% of organizations reported no federal or state cybersecurity grants received in 2025.

Toni Pepper, another Steering Committee Member, emphasized the importance of these findings, saying, "By sharing these findings, we hope to raise awareness of the underlying risk factors that compromise tribal cyber resilience and collective solutions that strengthen cybersecurity for all tribal governments and enterprises."

For more information, visit Tribal-ISAC and learn about their initiatives.

CISA Tribal Affairs

The Cybersecurity and Infrastructure Security Agency (CISA) collaborates with partners to enhance the safety and resilience of critical infrastructure for Native American and Alaska Native tribes. CISA provides various resources and tools aimed at bolstering the resilience of critical infrastructure, including improved communications and enhanced cybersecurity posture.

CISA's services focus on technical assistance, advocacy, and coordination. The agency recognizes the diversity within tribal communities and aims to tailor its approach to meet individual needs.

Key CISA initiatives include:

  • Tribal Emergency Communications: This program supports tribes in strengthening public safety communications.
  • CISA Services: An all-in-one resource that provides access to information on various services offered by CISA.
  • Physical Security: Focuses on protecting communities by addressing a broad range of physical security threats.
  • Chemical Security: Aims to prevent the misuse of chemicals in terrorist activities.

For more details, access CISA Services and Tribal Emergency Communications.

Tribal-ISAC Mission and Objectives

The mission of Tribal-ISAC is to bolster the cybersecurity posture of tribes by fostering a cooperative environment for sharing threat information and best practices. As a division of the not-for-profit Tribal Share, Inc., it serves as a platform for Native American tribal governments to enhance their security measures.

Objectives of Tribal-ISAC include:

  • Facilitating secure sharing of security threat information among tribes.
  • Improving overall security posture to safeguard critical infrastructure.
  • Providing access to federal, state, and local resources that support tribal resilience.

For more information on the objectives and initiatives, visit the Tribal-ISAC Steering Committee and Tribal Share Board Members.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

New Industry Report Defines Enterprise Maturity Benchmarks for Zero Trust Identity and Access Architecture
zero trust architecture maturity model

New Industry Report Defines Enterprise Maturity Benchmarks for Zero Trust Identity and Access Architecture

Discover how the new Zero Trust Maturity Model is replacing perimeter-based security with identity-centric frameworks for modern enterprise protection.

By Alan V Gutnov August 5, 2026 5 min read
common.read_full_article
Critical Ruflo MCP Bridge Vulnerability Enables Arbitrary Command Execution and AI Agent Hijacking
CVE-2026-59726

Critical Ruflo MCP Bridge Vulnerability Enables Arbitrary Command Execution and AI Agent Hijacking

Urgent: CVE-2026-59726 'RufRoot' vulnerability exposes Ruflo AI to RCE and agent hijacking. Update to v3.16.3 immediately to prevent total system compromise.

By Divyansh Ingle August 4, 2026 4 min read
common.read_full_article
Rising Endpoint Security Breaches Drive Shift Toward Zero-Trust Architectures for Global Enterprise Remote Access
zero trust architecture maturity model

Rising Endpoint Security Breaches Drive Shift Toward Zero-Trust Architectures for Global Enterprise Remote Access

Discover why Zero Trust is the new baseline for enterprise security. Learn how to combat rising endpoint breaches and secure a distributed, hybrid workforce.

By Brandon Woo August 3, 2026 5 min read
common.read_full_article
NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration
NIST post-quantum cryptography standards

NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration

Learn how to migrate to NIST PQC standards. Expert Andrew Regenscheid details strategies against 'harvest now, decrypt later' quantum threats in 2026.

By Alan V Gutnov July 31, 2026 4 min read
common.read_full_article