Categories
Governance & Funding Public Safety (Police, Fire, EMS)

CJIS 6.0: Governance for Law Enforcement Leaders

Imagine waking up to a 3:00 AM phone call that instantly makes your blood run cold. It isn’t an officer-involved shooting or a pileup on the interstate—it’s worse. The dispatcher on the line tells you the entire Computer-Aided Dispatch (CAD) system has gone black. Out on the streets, officers are suddenly flying blind, unable to run plates, verify active warrants, or know if the suspect they are pulling over is armed and dangerous. Back at the station, every computer screen goes dark and snaps back on with a terrifying message: hackers have locked down all your files. They are demanding a $1 million ransom in 24 hours, or they will leak the home addresses of your officers, names of your undercover informants, and domestic abuse victims onto the dark web.

For generations, a police chief’s job description was clear-cut: fight crime, protect the community, build public trust, and make sure officers make it home safe at the end of their shift. Today, that entire landscape has been fundamentally altered. In a post-George Floyd era marked by intense public scrutiny, systemic staffing shortages, and heightened anti-police sentiment, the pressure on law enforcement executives is at an all-time high.

While protecting lives on the street remains the top priority, managing these compounding real-world challenges means that ignoring digital threats is no longer just a blind spot—it is a recipe for disaster. Modern chiefs and sheriffs can no longer act solely as tactical commanders; they must realize they are now the gatekeepers of massive, highly sensitive digital networks where a single breach can instantly shatter fragile community trust and compromise the physical safety of their personnel.

With the rollout of the FBI’s Criminal Justice Information Services (CJIS) Security Policy Version 6.0 (slated for full enforcement by October 1, 2027), cybersecurity is no longer an “IT issue” that can be blindly delegated. It is now a critical operational risk. If an agency fails to comply, the consequences are devastating: the FBI can completely cut off their access to vital criminal databases, freeze their federal grants, and strip away key agency partnerships. Beyond the administrative fallout, non-compliance invites catastrophic data breaches, ruined investigations, and massive civil or criminal liabilities for leadership.

Why Law Enforcement is a Prime Target

Law enforcement agencies are no longer just accidental targets caught in broad cyber nets—they are being intentionally hunted. To a sophisticated hacker, a police department is a digital goldmine. The networks maintained by local and state agencies house a concentrated treasure trove of highly sensitive, unredacted data: Social Security numbers, biometric records, active warrants, open homicide files, and the true identities of confidential informants.

Cybercriminals have realized that weaponizing this specific information against public safety infrastructure yields immense leverage. If a bank gets hacked, money is lost; if a police department gets hacked, lives are immediately put in jeopardy. This extreme pressure makes law enforcement agencies highly attractive targets for extortion.

The Critical Risks to the Command

When leadership treats cybersecurity as a secondary priority, they open the door to three devastating structural risks:

Total Operational Paralysis

Cyber criminals deliberately strike police departments because they know law enforcement cannot afford a single minute of downtime. When hackers successfully breach a network, they move fast—state and local government sectors face an overwhelming 98% data encryption rate during successful ransomware attacks.

If your Records Management System (RMS) or CAD system is suddenly locked behind an unbreakable encryption key, your agency plunges into the dark ages. Dispatchers are forced to use pen and paper, response times plummet, and officers on the street lose the ability to pull up critical hazards before entering a scene.

The Expanding Attack Surface

The modern patrol officer is a walking network of connected technology. Between the mobile data terminal (MDT) bolted into the cruiser, body-worn cameras, department-issued smartphones, automated license plate readers (ALPRs), and field tablets, the “attack surface” of a single precinct has exploded exponentially.

Every single one of these endpoints is a potential doorway into your core server room. Cybercriminals don’t need to crack your central firewall if they can exploit an unpatched vulnerability on a single officer’s tablet. Across all sectors, unpatched software vulnerabilities remain the number-one gateway for attackers, triggering 32% of all successful ransomware breaches.

Double Extortion and the Collapse of Trust

The playbook for modern cybercrime has evolved past simple data locking. Today, groups practice “double extortion.” First, they quietly clone and steal (exfiltrate) your entire database; only then do they deploy the ransomware to lock your screens.

For a police chief, this is the ultimate nightmare. Even if you manage to restore your systems from backups without paying a dime, the hackers still hold your data hostage. They will threaten to publish unredacted active wiretaps, sealed juvenile records, or undercover officer identities on public forums.

Worse yet, in today’s highly charged social climate, cybercriminals are actively weaponizing officers’ home addresses, internal affairs files, and disciplinary records. Dumping this information online doesn’t just destroy morale—it puts officers and their families directly in the crossfire. In a post-George Floyd era marked by intense scrutiny and heightened anti-police sentiment, a data leak of personal addresses transforms a digital breach into a terrifying physical threat, exposing an officer’s spouse and children to targeted harassment or worse. The moment that data hits the internet, ongoing criminal prosecutions are permanently compromised, informant networks evaporate, and decades of hard-earned community trust vanish overnight.

The CJIS Shift: Beyond the Checklist

Historically, many agencies treated CJIS compliance as a “point-in-time” chore—filling out a questionnaire, checking a few boxes, and putting it away until the next audit.

CJIS 6.0 completely dismantles that lazy approach. The FBI has overhauled and mapped the entire policy directly to the National Institute of Standards and Technology (NIST) SP 800-53 Moderate Baseline. This alignment forces a complete cultural pivot away from periodic “annual checkups” and straight toward continuous risk management and continuous governance.

Under this framework, law enforcement leaders must command four critical pillars of modern compliance:

  • Stronger Identity and Access Controls: Security parameters have advanced beyond simple password enforcement. Agencies must now verify exactly who an employee is before granting access, manage accounts tightly from their first day to their last, and have the power to instantly lock down a user’s account the second suspicious activity is detected.
  • Expanded Auditing and Evidence: The days of simply telling an auditor “yes, our systems are safe” are over. Under CJIS 6.0, you have to prove it. Agencies must show digital receipts, logs, and actual system data to demonstrate that security rules are actively running, regularly checked, and updated when threats change.
  • Formalized Leadership Governance: True security isn’t achieved by just making an IT technician watch a compliance video. The new rules place the responsibility squarely on leadership. Chiefs and sheriffs must explicitly define who is responsible for what, actively oversee security operations, and sign off on the department’s digital safety strategy.
  • Continuous Risk Tracking: Instead of checking for security gaps once every few years before an audit, departments must now maintain a rolling, real-time list of their digital vulnerabilities. You are required to create an active game plan that tracks exactly how and when you will fix security flaws, showing constant progress over time.

To achieve this baseline, chiefs and sheriffs must urgently enforce three non-negotiable operational requirements:

1. Phishing-Resistant Multi-Factor Authentication (MFA)

The days of relying on simple passwords or easily intercepted text-message codes are officially over. The new rules mandate a much tougher form of multi-factor authentication (MFA) whenever anyone accesses sensitive criminal justice data, especially from a cruiser or a remote location. To keep things moving fast for officers in the field without cutting corners on security, departments are switching to fingerprint scanning, smart cards, or physical USB security keys (like FIDO2 tokens). These tools cannot be bypassed by hackers trying to trick an officer or spam their phone with login approvals.

2. Maximum-Strength Data Encryption (FIPS 140-3 Encryption)

Information flying through the air over cellular networks or public Wi-Fi is incredibly easy for bad actors to intercept. To stop this, the updated rules require agencies to completely phase out older, weaker security methods. Any data moving outside the secure walls of your station must be scrambled using the government’s latest gold standard of protection: FIPS 140-3 encryption. Think of it as an uncrackable digital armored car for your data while it travels from the street to your servers.

3. Isolated Network Segmentation and Physical Security

Great digital firewalls mean nothing if someone can physically walk right up to your computers or if a hacker can slip in through a weak link on the municipality’s network. First, the new policy requires departments to completely separate police data from general municipal data (like the water department or village/town/city/county traffic). If a hacker hits the municipal hall, a digital wall prevents them from jumping over to your police records. Second, the physical rules are strictly enforced: server rooms must be locked down, entryways monitored by cameras 24/7, and any outside technician or contractor stepping inside must clear a full fingerprint-backed background check.

The High Cost of Non-Compliance

For a police chief, ignoring these requirements carries severe operational and political penalties:

Risk CategoryImmediate ImpactLong-Term Consequence
Sanctions & DisconnectionThe FBI or state CJIS systems agency can cut off access to NCIC (National Crime Information Center) and Nlets.Officers are left blind during roadside stops, unable to run plates, check warrants, or verify firearms.
Financial ExtortionRansomware recovery costs average hundreds of thousands of dollars in remediation, even if the ransom is paidLocal tax dollars are diverted from community policing and equipment into emergency IT restoration.
Legal LiabilitiesExposure of sensitive data (like officer records or domestic abuse victim info) triggers devastating civil lawsuits.Decades of built-up community trust vanish overnight under the weight of negligence headlines.

Why Leadership Cannot Simply “Outsource” the Problem

It is common for municipal leaders and police chiefs to pass the buck, saying, “I have a great IT director,” or “We hire a trusted tech vendor to handle all of that.”

While the actual technical work belongs to the tech experts, the ultimate accountability rests squarely on the shoulders of agency leadership. Under CJIS 6.0, the rules explicitly state that chiefs and sheriffs must personally own their agency’s cybersecurity strategy. You must be able to prove to auditors that you are actively tracking your department’s digital risks and making measurable progress to fix them.

When a compliance audit fails, or a catastrophic data breach occurs, the public, the media, and the municipal board aren’t going to call the network administrator to the podium for answers—they are going to demand answers from the Chief.

An Action Plan for Law Enforcement Leaders

Steering an agency through this high-risk digital landscape requires more than just acknowledging the threat; it demands an active, disciplined strategy from the top down. Chiefs and sheriffs can use the following roadmap to protect their networks, shield their personnel, and maintain absolute CJIS compliance:

  1. Map Your Agency’s Total Data Footprint:

Phase 1: The Critical Prerequisite.

You cannot protect what you do not know exists. Leadership must order a comprehensive audit to document exactly how sensitive criminal justice data enters, moves through, and leaves the department. Track every single destination—whether that data lives on a cruiser’s mobile data terminal, a cloud-based records system, a detective’s field tablet, or a desktop at the main precinct. If data is flowing through an unmapped channel, it is an open invitation for a breach.

2. Enforce Leadership-Led Tech Briefings:

Phase 2: Monthly Mandate.

Stop treating the IT department or your third-party technology vendor like an isolated island. Establish a recurring monthly briefing to actively review your security posture. Avoid asking vague, passive questions like “Are we safe?” Tech teams will usually say yes. Instead, ask targeted, specific questions that demand proof:

  • “Can we pull up audit-ready evidence of our MFA compliance right now?”
  • “When was our last critical software patch cycle completed?”
  • “Do we have any unpatched vulnerabilities older than 30 days?”

3. Instill a Culture of Security Awareness:

Phase 3: Continuous Operation.

The most advanced firewall in the world can be bypassed by a single employee clicking a bad link. Security is a continuous human obligation, not a yearly classroom chore. Ensure that every single employee, dispatcher, records clerk, and outside contractor undergoes a comprehensive fingerprint-based background check and completes CJIS security awareness training within six months of their hire date. Follow this up with engaging, mandatory annual refreshers and regular, unannounced internal phishing tests to keep the entire command sharp.

4. Operationalize Your Incident Response:

Phase 4: High-Priority Planning

When a cyberattack hits, confusion is your greatest enemy. Do not wait for a crisis to figure out your chain of command. Implement a formalized, written Cyber Incident Response Plan that explicitly outlines who does what when systems go dark. Under CJIS regulations, certain data breaches must be reported to state and federal authorities within a strict window of discovery. Regularly run tabletop exercises with your leadership team so everyone knows how to isolate systems, notify authorities, and keep emergency operations moving without panic.

The Bottom Line: Cybersecurity is no longer an administrative footnote. It is a foundational element of public safety. A department’s frontline defense is determined just as much by its firewall configurations and access privileges as it is by the tactical gear in its cruisers. Leading an agency requires protecting the data of the citizens who trust you—and the officers who rely on it to come home safe.

Categories
Governance & Funding

Cybersecurity Budgets Shouldn’t Be a Black Box

When local officials review the annual budget, they routinely make decisions involving millions of taxpayer dollars. They debate staffing levels, infrastructure projects, pension obligations, public safety priorities, and capital improvements. These decisions often involve weighing competing priorities and determining how much risk the organization is willing to accept. Then they arrive at the cybersecurity budget.

Too often, what they see is a single line item buried somewhere within Information Technology.

Cybersecurity: $1,500,000

What exactly does that mean?

Is the organization investing in prevention or merely reacting to incidents? Are critical systems adequately protected? Are emergency response capabilities sufficient? Is the municipality able to recover quickly from a ransomware attack? Most importantly, how can elected officials determine whether the proposed expenditures align with the organization’s cyber risk tolerance? The honest answer is that they often cannot.

This creates a significant governance challenge. Local officials have a fiduciary duty to protect public assets, ensure continuity of services, and maintain public trust. In today’s digital environment, that responsibility includes cybersecurity. As the Local Government Officials Guide to Cybersecurity notes, cybersecurity is no longer simply an IT issue—it is a strategic, enterprise-level risk that requires leadership engagement.

Yet many governing bodies are expected to approve cybersecurity budgets without a meaningful way to understand how those expenditures reduce organizational risk.

The result is predictable. Some organizations underinvest because decision-makers cannot see the connection between spending and risk reduction. Others overspend in areas that may not represent their greatest vulnerabilities. Still others make decisions reactively, increasing funding only after experiencing a major incident. There is a better approach.

Using NIST CSF 2.0 as a Budget Framework

The National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 provides a practical structure that helps local governments translate cybersecurity spending into governance language. Its six core functions are not technical product categories; they are high-level objectives for cyber resilience. Rather than debating specific technologies, cybersecurity activities can be organized around six conceptually straightforward objectives:

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

These functions provide a common language that bridges the gap between technical professionals and governing bodies.

Most elected officials do not need to understand the differences between endpoint detection platforms, security information and event management tools, or intrusion prevention systems. However, they do understand questions such as:

  • Are we effectively detecting cyberattacks?
  • Can we respond quickly enough to minimize damage?
  • Do we have the ability to recover critical services after a disruption?
  • Are we investing appropriately in governance and risk management?

Those are governance discussions.

Connecting Spending to Risk

Imagine that, alongside the proposed budget, the governing body received a cybersecurity assessment aligned with the NIST Cybersecurity Framework. The assessment might indicate that the organization demonstrates relatively strong capabilities in Protect and Recover, moderate maturity in Govern and Identify, but significant gaps in Detect and Respond. Suddenly, the conversation changes.

Instead of asking, “Why do you need another cybersecurity tool?” officials can ask:

“Our assessment shows that our ability to detect malicious activity is weak. How does this proposed investment improve that capability?”

The discussion shifts from technology purchases to risk management. Current expenditures, proposed expenditures, and assessment results can all be aligned under the six NIST functions. Decision-makers gain visibility into where resources are being allocated and whether those investments address areas of greatest concern. This allows governing bodies to exercise one of their most important responsibilities: setting organizational risk appetite.

Defining Risk Appetite

No organization can eliminate cyber risk entirely. Just as local governments accept certain financial, operational, and legal risks in pursuit of their mission, they must also determine what level of cyber risk they are willing to tolerate.

That determination belongs to leadership. Technical staff can explain vulnerabilities and recommend mitigation strategies. Auditors and assessors can provide independent evaluations of current capabilities. However, elected officials ultimately decide whether the residual risk is acceptable based on community priorities, available resources, and competing obligations.

The challenge is that these decisions require understandable information. A single cybersecurity line item does not provide that information. A budget structured around the six NIST objectives does.

From Technical Details to Governance Discussions

Consider two different budget presentations. The first includes line items for firewalls, endpoint detection software, log management platforms, and threat intelligence subscriptions. Typically in a single line item, like the one above. The second shows:

NIST FunctionRisk RatingCurrent SpendingProposed Spending
GovernModerate$75,000$100,000
IdentifyModerate$125,000$150,000
ProtectLow$500,000$525,000
DetectHigh$150,000$325,000
RespondHigh$100,000$250,000
RecoverModerate$200,000$225,000

Which presentation is more useful to a city council member, county supervisor, or special district board? The answer is obvious. The second presentation enables leaders to understand where risks exist, how resources are being allocated, and whether proposed expenditures align with the organization’s stated risk tolerance. It elevates cybersecurity from an operational discussion to a strategic one.

Building Better Governance

The NIST Cybersecurity Framework was never intended to be just a technical resource. It provides a structure for understanding and managing cybersecurity risk across the enterprise. By aligning cybersecurity expenditures with the six NIST CSF 2.0 functions, local governments can transform budget discussions into meaningful governance conversations.

Officials gain the ability to:

  • See how cybersecurity investments address material risks.
  • Understand the relationship between spending and organizational resilience.
  • Prioritize funding based on independent assessments.
  • Establish and communicate risk appetite.
  • Exercise effective oversight without becoming technical experts.

In short, they gain the information necessary to fulfill their fiduciary responsibilities. Cybersecurity should never be a black box. Local government leaders deserve clear, actionable information that helps them govern wisely, steward public resources responsibly, and strengthen the resilience of the communities they serve. If cybersecurity is truly an enterprise risk, as we increasingly recognize it to be, then our budgets should reflect that reality.

Perhaps it is time to stop asking, “How much are we spending on cybersecurity?” And instead begin asking, “What risks are we reducing, and are we investing where it matters most?”

Help is on the Way

The Local Government Cybersecurity Alliance (LGCA) is currently developing a whitepaper that explores this concept in greater depth, providing practical guidance for local governments seeking to align cybersecurity budgets with the NIST Cybersecurity Framework 2.0. The goal is to equip elected officials, executives, finance officers, and cybersecurity leaders with a common language for discussing cyber risk, prioritizing investments, and making informed, risk-based decisions. By connecting assessment results to budget allocations, local governments can move beyond viewing cybersecurity as a technical expense and begin managing it as the enterprise risk it truly is. We believe this approach has the potential to transform cybersecurity budgeting from an opaque line item into a transparent governance tool that strengthens resilience, accountability, and public trust.

Categories
Governance & Funding

Why “Silent Cyber” Should Alarm Local Government

The phrase “cyber risk” often conjures images of corporate data breaches or national espionage. But for municipalities, counties, and local agencies, the threat is far more immediate and complex—especially when considering Silent Cyber.

As local governments digitize records, automate critical infrastructure, and manage massive databases of sensitive resident information, they become prime targets for attackers. However, a major risk lurks not just in the network, but in the fine print of your existing insurance policies.


What is Silent Cyber for a Municipality?

Silent Cyber, or non-affirmative cyber risk, is the danger that a major cyber event—like a ransomware attack or a system breach—could trigger unexpected and massive claims under your municipality’s traditional insurance policies, such as:

  • General Liability
  • Commercial Property
  • Public Officials & Law Enforcement Liability

These policies were not originally written to address digital threats. They are “silent” on the issue, meaning they neither explicitly cover nor explicitly exclude losses caused by a cyber incident. This ambiguity can lead to an unexpected loss for the insurer (if they have to pay a claim they didn’t price for) or a crippling coverage gap for the municipality (if the claim is denied).


Real-World Scenarios for Local Government

For a city or town, a cyber attack is not just about stolen data; it’s about the disruption of essential public services.

Policy TypeCyber-Triggered EventPotential Silent Cyber Loss
Property/EquipmentRansomware infects the Industrial Control System (ICS) managing the water treatment plant, causing mechanical failure and physical damage to pumps.Physical damage to equipment and extended business interruption/loss of utility service income, covered under a policy not priced for cyber risk.
General LiabilityA malicious hack causes the municipal traffic light control system to fail catastrophically, leading to a major vehicle collision and subsequent bodily injury claims.Third-party bodily injury and property damage liability claims caused by the digital disruption of physical infrastructure.
D&O LiabilityA major data breach exposes resident tax and voter records, leading to a class-action lawsuit and an investigation into the Town Board/City Council for failure to maintain adequate security protocols.Litigation and defense costs covered by a Public Officials/ Law Enforcement policy that didn’t factor in cyber risk aggregation.

Historically, the ambiguous wording may have worked in the municipality’s favor. Today, regulators are demanding clarity, and insurers are introducing explicit cyber exclusions to avoid these unforeseen payouts.


Eliminating Ambiguity

As local governments operate on limited budgets, relying on traditional policies to “silently” cover a modern cyber catastrophe is a gamble your residents can’t afford.

Here are the critical steps your administration should take right now:

  1. Stop Relying on Silence: Understand that the days of assuming coverage from general policies are ending. New, clearer exclusions are rapidly being introduced to your insurance forms.
  2. Conduct a Full Policy Audit: Work with your risk manager and broker to review every liability and property policy. Identify the specific cyber exclusions (or lack thereof). Where possible, aim for language that is affirmative—it clearly states what is covered and what is excluded.
  3. Invest in Dedicated Cyber Insurance: A comprehensive, standalone Cyber Insurance Policy is the only way to reliably cover first-party losses unique to municipalities:
    • Ransomware Response: Cost of ransom negotiation, forensic IT, and decryption.
    • Public Notification: Mandated costs for notifying thousands of affected residents after a breach of PII (Personally Identifiable Information).
    • System Restoration: Costs for rebuilding and restoring municipal data and computer systems.

Cybersecurity is no longer just an IT issue; it is a fundamental public safety and fiscal responsibility. By actively addressing “silent cyber,” local government leaders ensure that when the inevitable digital crisis occurs, the city’s financial resilience and ability to serve its citizens are not compromised by an insurance dispute.

Categories
Governance & Funding

Cybersecurity is Financial Risk: The Hidden Million-Dollar Price Tag of Hacking Local Governments

When a cyberattack hits a local government, the price tag goes far beyond ransom demands and new computers. It triggers a financial tsunami of hidden costs that divert taxpayer money from vital public services for years. These aren’t just IT budget line items; they are existential threats to a municipality’s financial stability and ability to serve its citizens.


1. Direct Recovery Costs

The first wave of financial devastation hits during the frantic, high-priced effort to claw back control of municipal systems.

  • Emergency Procurement and Consultant Fees: When systems go dark, normal competitive bidding processes are thrown out the window. Municipalities are forced to hire specialized incident response firms and forensic investigators on an emergency basis, paying premium, last-minute rates to stop the attack, find the root cause, and clean systems.
  • System Rebuild and Replacement: Local governments frequently rely on decades-old, vulnerable infrastructure. Cyber insurance rarely covers the full cost of an upgrade. An attack often forces a massive, unplanned leap into modern infrastructure—costing millions more than any planned capital improvement project.
    • Case in Point: The 2018 Atlanta ransomware attack cost the city an estimated $17 million to recover—a sum equivalent to funding the city’s entire Parks and Recreation budget for a full year. One single breach effectively erased twelve months of community development.

2. Long-Term Financial Damage

The financial markets treat cyber vulnerability as a systemic operational failure, driving up the cost of a municipality’s future operations and debt.

  • Credit Rating Downgrades: Rating agencies like S&P Global and Moody’s view a severe cyberattack as a symptom of weak governance and operational instability. A major breach can trigger a direct downgrade of a municipality’s credit rating.
  • Increased Borrowing Costs: A lower credit rating—or even the public reputation of being digitally vulnerable—makes a municipality a high-risk borrower. When the municipality issues municipal bonds to fund critical infrastructure (like roads, water treatment plants, or schools), it is forced to offer higher interest rates to attract investors.
    • A seemingly minor 0.5% increase in a bond’s interest rate translates into millions of dollars in additional interest payments over a 20- or 30-year term. That is pure capital coming out of the community’s treasury forever.
  • The Cyber Insurance Impact: The insurance market has turned its back on soft targets. Because public entities are viewed as high-risk, local governments face a brutal insurance landscape:
    • Skyrocketing premiums paired with slashed coverage limits.
    • Strict, non-negotiable security mandates (like mandatory multi-factor authentication or EDR) that underfunded municipalities can’t afford to implement.
    • The looming threat of non-renewal leaves the municipality entirely exposed.

3. Operational and Reputational Costs

Some of the most damaging costs are non-financial, yet they have a profound effect on governance and citizen life.

  • Massive Productivity Losses: Municipal staff are idled, unable to perform basic functions like processing permits, managing utility billing, or accessing court records. The municipality continues to pay salaries while operations grind to a total halt.
  • Legal and Regulatory Fines: If the attack involved a data breach, the municipality may face regulatory fines from state or federal agencies (especially if health or law enforcement data was involved). They also face the potential for class-action lawsuits from affected citizens whose Personally Identifiable Information (PII) was exposed.
  • Erosion of Public Trust: When citizens can’t pay their water bill, apply for a license, or receive timely emergency services due to a hack, public confidence in the government plummets. This can hurt everything from voter turnout to bond measure support and the morale of the government workforce.

The true cost of a municipal cyberattack is measured by what the community is forced to abandon. Every dollar handed to a ransomware hacker, an emergency IT consultant, or a bond investor is a dollar stolen from parks, paved streets, public safety, and schools.

Cybersecurity is no longer an IT issue—it is the single most critical form of municipal fiscal risk management.

Sign In

Register

Reset Password

Please enter your username or email address, you will receive a link to create a new password via email.