Varonis debuts trailblazing features for securing Salesforce. Learn More

Introducing Athena AI our new generative AI layer for the Varonis Data Security Platform.

Learn more

INVEST in America Act: Billion-Dollar Funding for Cybersecurity

3 min read
Last updated October 11, 2022

The INVEST in America Act provides nearly two billion dollars in funding to enhance the nation's cybersecurity.

Who should care?

  • State, local, and tribal governments.
    • $1 billion in funding over four years to address cybersecurity risks
  • Federal agencies.
    • $21 million to fund the office of the new National Cyber Director
    • $20 million annually to fund the Cyber Response & Recovery Fund through 2028
  • Power, water, and infrastructure companies.
    • $600 million in funding for smart grid cybersecurity R&D
    • $375 million in funding for more secure water systems

The continuing onslaught of devastating data breaches has put pressure on the United States Government and the Biden administration to rapidly upgrade the nation's critical infrastructure defenses.

Over the last year, multiple federal agencies and governmental bodies have released statements, guidance, and recommendations outlining how organizations in both the public and private sectors should improve and modernize their cybersecurity infrastructure and defenses to protect against ransomware.

Get the Free Essential Guide to US Data Protection Compliance and Regulations

What is the INVEST in America Act?

The "Investing in a New Vision for the Environment and Surface Transportation in America Act" or "INVEST in America Act" is a passed spending bill that invests billions in funding over the next five years towards securing and modernizing State, Local, and Tribal governments, and U.S. infrastructure such as mass transit (Amtrak and DOT), water, power, green technologies, and other similar projects.

With high-profile ransomware attacks proving that core aspects of America's infrastructure can be brought to a screeching halt with a single attack, portions of this bill set out to ensure that organizations responsible for core infrastructure are well prepared to prevent similar incidents from happening again.

To achieve this, this bill includes nearly two billion dollars of funding earmarked for helping organizations improve their cybersecurity posture and harden their defenses.

Along with direct funding, INVEST in America makes cybersecurity efforts such as the employment of forensic consultants, cybersecurity experts, and third-party pen testers eligible expenses under the Mobility Through Advanced Technologies (MTAT) program. (source)

Cybersecurity funds for State, Local, Municipal, and Tribal governments

This bill establishes a National Cyber Resilience Assistance fund and allocates around a billion dollars in funding to modernize and harden the nation's cybersecurity ecosystem from 2022 to 2026.

These resources are meant to help non-federal governmental bodies detect, respond to, investigate, and recover from ransomware and other cyberthreats.

Previously congress passed the Cyber Response and Recovery Act that enables the Secretary of Homeland Security through CISA and the National Cyber Director to declare a "significant cyber incident" across ALL Federal, State, Local, and Tribal systems.

Through the INVEST in America act, this fund will have millions in funding replenished annually to help prepare for and respond to major cyber incidents.

Guidance: To apply for these funds, local agencies and organizations should reach contact your State Administrative Agency (SAA) to learn more about your state’s application process and the next steps to take to receive funding.

Additional resources:

INVEST in the nation's cybersecurity

The INVEST in America act requires organizations receiving funding to follow frameworks created by the National Institute of Standards and Technology (NIST).  Compliance with NIST's frameworks requires organizations to implement strict and robust cybersecurity solutions to reduce risk to their critical data and safeguard individual privacy.

Within two years of receiving funding, administrators must develop a tool to identify, detect, protect against, respond to, and recover from cyber incidents. Organizations will also be required to designate a Cyber Coordinator and establish a structured cybersecurity assessment and development program.

Federal funds received under the INVEST in America Act cannot be used to pay ransoms, so it is essential for organizations to utilize these resources effectively and invest in a holistic cyber security platform to quickly detect cyberthreats and mitigate any potential damage.

INVEST in America's cybersecurity with Varonis

Varonis' Data Security Platform can help organizations achieve least privilege and Zero Trust, ensuring that only those that require access to data have it.

With Varonis, you can identify and reduce risk to your sensitive and regulated data and secure your data, apps, and infrastructure against cyberthreats like ransomware.

Varonis can remediate excessive access to data at scale, reducing the blast radius of a potential attack and using automation to get to Zero Trust without years-long projects and manual work.

Our industry-leading UEBA alerting can catch suspicious activity before threats take hold.

Varonis logs a full audit trail of events across Active Directory and core data stores, making it easy to investigate cybersecurity incidents or meet strict compliance requirements.

Try Varonis

Schedule a personalized demo to learn how Varonis can help you secure your most valuable data.

What you should do now

Below are three ways we can help you begin your journey to reducing data risk at your company:

  1. Schedule a demo session with us, where we can show you around, answer your questions, and help you see if Varonis is right for you.
  2. Download our free report and learn the risks associated with SaaS data exposure.
  3. Share this blog post with someone you know who'd enjoy reading it. Share it with them via email, LinkedIn, Reddit, or Facebook.
Try Varonis free.
Get a detailed data risk report based on your company’s data.
Deploys in minutes.
Keep reading
Speed Data: The Next Generation of Cybersecurity With Mark Weber
Executive in Residence for the Catholic University of America Mark Weber shares tips for mentoring future cybersecurity professionals.
Varonis Leads DSPM Market on Gartner Peer Insights
As a leader in data security, Varonis is proud to be rated No. 1 in Gartner’s Data Security Posture Management category.
Speed Data: Fusing Empathy and Enterprise With Illena Armstrong
Illena Armstrong shares her advice for future executives, discusses the importance of teamwork, and explains why empathy is powerful for leaders.
AI At Work: Three Steps To Prepare And Protect Your Business
Discover how your business can prepare and protect your sensitive data from the risks that generative AI presents.