Working With the Maryland Coordination And Analysis Center

Most people in Maryland government IT discover MCAC when something breaks and they need help fast. The Maryland Coordination And Analysis Center functions as the state's hub for cyber threat intelligence sharing, incident response coordination, and sector-specific guidance. It sits under the Maryland Department of Homeland Security and Emergency Management and serves as the primary point of contact between Maryland state agencies, local governments, and federal partners like CISA. MCAC operates as both an information clearinghouse and an operational coordination cell. When a critical infrastructure sector in Maryland — water utilities, transportation authorities, healthcare systems — reports a phishing campaign or ransomware indicator, that intelligence flows through MCAC and gets distributed across relevant stakeholders. The center runs 24/7 monitoring and provides actionable threat briefs rather than vague advisories. They also handle the Maryland-specific requirements around breach notification timing under state law, which differs from federal FCRA deadlines. I've worked with MCAC through multiple real-world incidents over the past several years. Here is what actually happens when you engage them.

How to Actually Get Help From MCAC

The most common mistake people make is trying to route everything through a generic state IT hotline instead of going directly to the MCAC emergency contact number. The MCAC operations center line is 410-841-5800 and that is the number you call when a live incident is happening. For non-emergency information requests, policy questions, or vulnerability disclosures, use the email channel at mcac@md.gov. Response times on the hotline during business hours are typically under 15 minutes. Outside business hours, you will get a voicemail but your incident will be picked up by the on-call analyst within 30 minutes. This matters because ransomware spreads fast and every hour of delay compounds the damage. Before you call, have three things ready: the timeframe of the incident, the affected systems or networks, and any indicators of compromise you have already identified. MCAC analysts can work with incomplete information, but they ask for it upfront because context determines how quickly they escalate. If you report a potential phishing email, tell them the campaign name if you have it from a threat intel feed. If you are dealing with ransomware, give them the file extension on the encrypted files. Specific details move the case forward faster than broad descriptions.

Accessing MCAC Resources and Reports

MCAC publishes regular threat bulletins through their public-facing portal and through the Maryland Cybersecurity Portal. The bulletins cover region-specific threats including ransomware groups targeting Mid-Atlantic jurisdictions, supply chain compromises affecting Maryland-based contractors, and phising campaigns impersonating state government entities. These are free to access but you do need to create an account with the Maryland cybersecurity portal, which requires a .md.gov or .gov email address for verification. For threat intelligence feeds, MCAC participates in the ISAC model and provides INDUE-based IOCs through trusted partner channels. If your organization holds a valid DHS Trusted Observer or Partner certificate, you can receive direct API-level feeds. The enrollment process takes roughly two weeks and requires proof of your organization's eligibility under Critical Infrastructure sectors defined in Presidential Policy Directive 21.

Get the Full Details

Maryland Coordination and Analysis Center | LinkedIn
Maryland Coordination and Analysis Center | LinkedIn

Common Pitfalls and What Beginners Miss

One thing that catches people off guard is the difference between MCAC's role and the Maryland State Firewall. MCAC is an intelligence and coordination body. They do not operate your firewalls, patch your servers, or directly intervene in an active breach. Their value is in connecting you to the right resources, providing threat context, and coordinating multi-agency response. Some organizations mistakenly assume MCAC can pull the plug on an infected network or restore compromised systems. They cannot. They will, however, connect you with the Maryland National Guard Cyber Defense Team if the incident crosses into National Event level and state resources are insufficient. Another counter-intuitive point: reporting an incident to MCAC does not automatically trigger a formal investigation or public disclosure. Most incidents are handled operationally without public fanfare unless they meet the threshold for regulatory notification under HIPAA, GLBA, or state data breach laws. The analysts understand that organizations are often hesitant to report because of reputational risk, and they have built processes to keep routine incidents quiet. That said, underreporting is still the biggest problem I see. Organizations sitting on known compromises because they fear audit findings end up being worse off because they missed the chance to get remediation guidance while the threat was still contained.

LIMITATIONS You Need to Know About

MCAC is not a silver bullet and several structural constraints matter in practice. The center has limited staffing relative to the scope of Maryland's critical infrastructure. During a large-scale regional incident like a coordinated ransomware wave hitting multiple counties simultaneously, response times for non-critical requests can stretch to several hours. They prioritize healthcare and public safety incidents over commercial or municipal IT issues, which is reasonable but frustrating if your organization falls outside those categories. The second limitation is that MCAC's authority is largely advisory for private-sector entities. If you run a private hospital or a water treatment plant, MCAC can guide you but they cannot compel you to follow their recommendations. Enforcement of cybersecurity standards for private critical infrastructure in Maryland relies on federal partnerships and sector-specific regulators. The third gap is that MCAC's threat intelligence coverage is strongest for local and regional threats. If you are dealing with an APT group operating globally with sophisticated infrastructure, CISA's operational cybersecurity service will likely provide more actionable and timely intelligence than MCAC's regional feeds.

What I Actually Recommend

If you work for a Maryland state agency or local government, establish your relationship with MCAC before you need it. Request a briefing from their outreach team and get your point of contact registered. The typical cycle is an annual tabletop exercise that covers incident escalation procedures and communication protocols. These exercises are not optional fluff — they are where you learn whether your incident response plan actually works under realistic conditions. I went through one where we discovered that our designated incident commander had left the agency six months earlier and nobody had updated the contact list. That would have cost us at least 45 minutes of confusion during a real event. MCAC caught that gap because they cross-reference contact lists against state HR records before every drill. For private-sector organizations in Maryland, the most practical path is to get your IT team comfortable with MCAC's reporting channels and to register for their bulletins. It takes about ten minutes to set up and the threat intelligence you get in return usually pays for itself after a single useful lead. When a phishing campaign specifically targeting your industry shows up in their bulletin before your employees click anything, that is the return on investment.

Maryland Coordination and Analysis Center: Stages of an Active Shooter | Public Intelligence
Maryland Coordination and Analysis Center: Stages of an Active Shooter | Public Intelligence

Bottom Line on Using the Maryland Coordination And Analysis Center

MCAC is functional, understaffed, and genuinely useful if you approach it with the right expectations. It is not a full-service managed security provider and it will not replace your SOC or your IR retainer. But for Maryland-based organizations that need regional threat context, coordination support during incidents, and a direct line to state-level cybersecurity resources, it is the single most practical tool available. Call the number when something breaks. Read the bulletins before something breaks. And fix your contact lists annually because apparently nobody else is going to do it for you.