Categories
Basics & Actionable Steps Governance & Funding

You Paid For The Lock — Now USE IT!

The Gap Between Owning & Fully “Implemented” Cyber Tooling You Already Own

You fought for the budget. You built the business case, presented the risk landscape to leadership, justified every line item, and won cybersecurity funding. New tools were purchased — Identity and Access Management, advanced EDR/XDR, SIEM and more. Boxes checked. Audit requirements are satisfied. A genuine win.

But here is the uncomfortable question nobody asks in the post-purchase debrief: did you actually fully implement them?

Not install. Not license. Implement — fully configured, integrated into your architecture, with every feature activated, monitored and tested. Because there is a dangerous gap between owning a security tool and deriving security from it. And that gap is exactly where attackers live.

Only 14%of organizations are confident they have the people and skills required to meet their cybersecurity needs today — WEF Global Cybersecurity Outlook 2025

The Stryker Wake-Up Call

On March 11, 2026, medical technology giant Stryker suffered a devastating cyberattack that wiped data from thousands of employee and personal devices across 79 offices worldwide. The attackers — an Iran-linked group — did not deploy malware. They did not exploit a zero-day vulnerability. They simply obtained high-privilege administrative credentials and weaponized Microsoft Intune’s Remote Wipe feature, a legitimate IT management tool built for lost or stolen device recovery, to factory-reset tens of thousands of enrolled devices simultaneously.

The lesson is not that Intune is dangerous. The lesson is that privileged access was not properly governed, identity boundaries between on-premises and cloud environments were not enforced, and monitoring either did not exist or did not trigger fast enough. All of these are configuration failures in tools organizations already owned.

The attackers did not break in through a sophisticated exploit. They walked through a door left open by an incomplete implementation.

The Preparedness Gap Is Real — and Growing

The Stryker attack is not an anomaly. It is a symptom of an industry-wide crisis that the World Economic Forum’s (WEF) Global Cybersecurity Outlook 2025 has quantified and it is sobering.

72%of organizations report that cyber risks increased in the past year — WEF Global Cybersecurity Outlook 2025
2 in 3organizations report moderate-to-critical cybersecurity skills gaps, lacking the talent needed to meet their security requirements — WEF Global Cybersecurity Outlook 2025
54%of large organizations cite third-party and supply chain risk management as their biggest barrier to achieving cyber resilience — WEF Global Cybersecurity Outlook 2025
35%of small organizations believe their cyber resilience is inadequate — a proportion that has increased sevenfold since 2022 — WEF Global Cybersecurity Outlook 2025

These numbers describe an industry buying security and not implementing it. Organizations are acquiring the tools, but the talent, architecture, and operational discipline needed to extract full value from those investments is not keeping pace. The result is a fleet of half-deployed, partially configured tools that create a false sense of security while leaving real gaps wide open.

The Agentic AI Threat Multiplier

Attackers are not waiting for organizations to catch up. Generative AI is reshaping the cybercrime landscape at an accelerating pace and the gap between offense and defense is widening.

47%of organizations cite the advance of adversarial AI capabilities — including AI-enhanced phishing, malware development and deepfakes — as their primary GenAI cybersecurity concern — WEF 2025
66%of organizations believe AI will have the most significant impact on cybersecurity in the next 12 months, yet only 37% have processes in place to assess the security of AI tools before deployment — WEF 2025

In an Agentic AI attack scenario where AI autonomously chains together reconnaissance, credential harvesting, lateral movement and execution — a monolithic, single-vendor security stack is a structural liability. If the attacker understands your provider’s architecture better than you do, and your tools are not fully configured, they will find the path of least resistance.

This is not hypothetical. It is the architecture of the Stryker attack, translated into the AI era.

Do You Have the Talent to Use What You Bought?

Before the next purchase order is signed, every security leader, technical and executive alike, should answer these questions honestly:

  • Do we have in-house expertise to fully configure and operationalize the features in our existing tools?
  • Was our tool selection driven by a holistic architecture strategy, or were tools purchased reactively to satisfy an audit requirement?
  • Are all features within our EDR/XDR, IAM, and SIEM platforms fully activated, integrated, and effectively monitored?
  • Do we have unified, normalized logging across every layer of our technology stack feeding a well-configured and monitored dashboard?
  • Is every vendor connection to our environment governed by Zero Trust principles — remote browser isolation, VPN-less access, and Just-In-Time privileged access with approval notification chains configured?

If the honest answer to any of these is ‘no’ or ‘I’m not sure,’ you are not alone — but you are exposed.

A Layered, Heterogeneous Defense: The Architecture That Holds

A monolithic, single-vendor solution may be cost-effective and operationally convenient. But in an Agentic AI threat environment, it is a single point of architectural failure. A breach that understands one vendor’s toolset can traverse your entire environment.

A heterogeneous, layered defense, built intentionally, implemented fully, and integrated across every layer of your stack is a fundamentally different proposition for an attacker. When one protective layer is compromised, the next one holds. The following architecture has proven itself in real-world attack scenarios:

External Perimeter

  • SASE and next-generation firewall with full north-south traffic decryption and inspection and integrated real time defense
  • Advanced API gateways for all internet-facing applications with bot detection and agentic AI defense capabilities
  • All vendor and third-party remote access governed exclusively through remote browser isolation and VPN-less Zero Trust Network Access (ZTNA)

Internal Network

  • Switch-to-switch encryption across internal network segments
  • Micro-segmentation with east-west firewall inspection, full traffic decryption, and XDR/API integration with network admission control policies
  • Patch panel and port-level monitoring via MAC device admission control with logging and firewall integration feeding XDR

Endpoint

  • EDR/XDR deployed with all features fully activated
  • Consider stacking heterogeneous endpoint agents from different vendors — if one provider’s agent is compromised or bypassed, a second independent layer remains active

Identity and Privileged Access

  • Isolate privileged identities: on-premises admins must not carry high-privilege roles in Microsoft 365 or Entra ID — a critical lesson from the Stryker attack
  • Deploy Entra Private Access for Domain Controllers, extending Conditional Access and MFA requirements to sensitive Active Directory operations including LDAP and Kerberos
  • Implement Just-In-Time (JIT) access with approval workflows for all privileged identity management (PIM) accounts
  • Replace manual service account passwords with Active Directory Group Managed Service Accounts (gMSAs)
  • Rotate the KRBTGT password at minimum twice per year; in a breach scenario, rotate immediately — do not wait
  • Restrict all Domain Controller network access; ensure DCs cannot directly reach the internet
  • Audit and enforce strict anomaly monitoring across all security logs

Cloud Security

  • Conduct cloud security posture reviews frequently — cloud providers release new security features continuously; newly available controls should be assessed and implemented as a priority, not deferred
  • Consider disabling Password Hash Sync to keep credential validation on-premises through pass-through authentication or federation
  • All Saas tenant entry points should be isolated to just your agency IP block, with access for remote users only via browser based isolation and ZTNA solutions and fronted by advanced application gateways or proxies
A layered, heterogeneous defense does not require unlimited budget. It requires deliberate architecture and full implementation of the tools you already own.

How to Close the Configuration Gap Without Starting Over

1. Request a Free Implementation Assessment From Your Vendors

Most enterprise security vendors will conduct a complimentary implementation health check if asked directly. They will identify misconfigured features, unused capabilities, and integration gaps. Many will also provide staff education sessions at no additional cost. This is one of the highest-ROI actions available to any security team and it costs nothing but time.

2. Consider an MSP With Cybersecurity Depth

If in-house talent is the constraint — and the WEF data confirms it is for the majority of organizations — a Managed Security Service Provider (MSSP) with genuine cybersecurity staff, 24/7 monitoring capabilities, and a contractual cyber retainer for incident response is not a cost; it is a force multiplier. The right MSSP partner helps you operationalize the tools you already own and ensures that someone is watching when your team cannot be.

3. Build a Unified Visibility Layer

Every device, every endpoint, every cloud workload, every network segment should feed normalized logs into a centralized, well-configured SIEM or XDR dashboard. Visibility gaps are where attackers operate undetected. Unified logging is not glamorous, but it is foundational.

4. Prioritize Identity Above All Else

The Stryker attack was an identity attack. The WEF report confirms that identity theft has become the top personal cyber risk for both CISOs and CEOs in 2025. If you can only harden one area this quarter, harden identity: implement JIT access, enforce MFA everywhere without exception, isolate privileged accounts, and audit every administrative role in both your on-premises and cloud environments.

5. Review Attack Anatomy Regularly

An easy way to have a leg up on all attacks is to regularly review the anatomy of attacks.  This is a free and easy way to identify gaps within your architecture and alerting.  You can implement additional custom alerts from the indicators of compromise you review in attack anatomy, address configuration updates and hardening, and review with your team or your Managed Service Provider.  Attack review should be part of your day-to-day operations.  You cannot protect against what you do not understand.  Also, you cannot harden architecture if you have not operationalized architecture review.

The Bottom Line

The cybersecurity industry has a spending problem masquerading as a security problem. Organizations are acquiring tools at scale while the skills gap required to effectively implement them grows faster than the workforce can fill it. The result is a fleet of expensive, partially deployed technology that creates compliance confidence without creating actual resilience.

The WEF Global Cybersecurity Outlook 2025 reports that 49% of public-sector organizations lack the talent to meet their cybersecurity goals — an increase of 33% in a single year. The private sector is not immune.

The answer is not more tools. It is full implementation of the tools you already own, a deliberate layered heterogeneous architecture designed to survive a breach of any single component, and the operational talent — whether in-house or through a trusted partner — to run it.

You paid for the lock.

Now use it.

About the Author

Eudora Fleischman  |  Infrastructure Architect & Retired CISO Eudora Fleischman is the Infrastructure Architect and Retired with over 31 years of experience in infrastructure architecture, cybersecurity, governance risk, and disaster recovery management and serves as an Advising Member of the Local Government Cybersecurity Alliance.

Sources

World Economic Forum — Global Cybersecurity Outlook 2025 (January 2025, in collaboration with Accenture)

Stryker SEC Filing & Incident Reports, March 2026

Categories
Basics & Actionable Steps Governance & Funding Press Release

Announcing the Local Government Officials Guide to Cybersecurity

We are thrilled to announce the official publication of a critical new resource: the Local Government Officials Guide to Cybersecurity (LGOGC)!

This project was developed by the Local Government Cybersecurity Alliance (LGCA) specifically to empower elected and appointed officials—from supervisors and council members to city managers and agency heads—to effectively navigate the increasingly complex world of cyber risk.

Moving Beyond the Technical Jargon

Cybersecurity is not just an IT department problem; it is an enterprise-wide, whole-of-government issue that impacts finance, legal compliance, emergency services, and public trust.

The LGOGC cuts through technical jargon to focus on what matters most to community leaders: governance, accountability, and resilience. This guide was truly built by and for local government professionals, ensuring every concept is practical and immediately relevant to your fiduciary duty to protect the systems that serve your communities.


What the Guide Will Help You Achieve

The LGOGC provides a clear, actionable framework to help local leaders translate responsibility into practical action. Inside, you’ll find guidance to:

  • Integrate cybersecurity into your strategic and budget planning.
  • Strengthen oversight and reporting mechanisms.
  • Align your efforts with nationally recognized frameworks, such as NIST CSF 2.0.
  • Build a culture of cyber resilience that spans all departments and elected offices.

Download and Share Your Feedback

We believe that making cybersecurity governance as natural and necessary as financial oversight is achievable in every county, city, town, village, and district. This guide is a huge step toward that goal.

Download the Local Government Officials Guide to Cybersecurity (LGOGC) now.

We invite your feedback! Tell us how your jurisdiction is addressing these challenges and what resources would be most valuable to you next in our community forum or white paper.

Categories
Basics & Actionable Steps

Relevant Laws & Compliance Checklists: What Local Governments Need to Know

Cybersecurity laws and regulations are evolving rapidly. For local governments, staying compliant isn’t just about checking boxes—it’s about protecting public trust, ensuring operational continuity, and avoiding costly legal exposure. As the threat landscape changes, so do the legal obligations that govern how municipalities handle data, respond to incidents, and manage third-party risks.

Why Legal Review Matters

Boards and senior leaders must be regularly updated on both existing laws and proposed legislation that could impact current practices. This includes federal mandates, state-specific statutes, and sector-based requirements. Engaging your general counsel or external legal advisors is essential to ensure that your organization remains compliant and prepared.

Legal teams can help:

  • Interpret new regulations and assess their applicability.
  • Identify gaps in current policies and procedures.
  • Draft or revise internal compliance checklists.
  • Advise on risk exposure and liability mitigation.

Federal Laws to Watch

Several federal statutes directly affect state and local governments:

  • Federal Information Security Modernization Act (FISMA): Now applies more stringently to local governments, requiring robust protections for information systems and timely incident reporting.
  • Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA): Requires organizations in critical infrastructure sectors—including many municipal services—to report cyber incidents within 72 hours and ransomware payments within 24 hours.
  • State and Local Government Cybersecurity Act of 2021: Provides federal support through grants, cooperative agreements, and training programs.
  • Federal Rotational Cyber Workforce Program Act of 2021: Encourages talent development and resource sharing across government agencies.

These laws are designed to improve coordination, transparency, and resilience across public sector entities.

State-Level Regulations

Cybersecurity legislation continues to evolve rapidly across the United States. In 2025, 48 states and Puerto Rico introduced or considered more than 500 bills or resolutions related to cybersecurity. These laws reflect growing concerns about ransomware, data breaches, and the need for stronger digital infrastructure in government.

Key Trends and Examples
  • New York: Updated procurement laws now require endpoint device purchases to align with the NIST Cybersecurity Framework. As of 2025/2026, there is a .gov web domain mandate, incident reporting requirements, and a training mandate for local governments.
  • Arkansas: Mandated the Division of Information Systems to maintain cybersecurity policies aligned with state standards.
  • Idaho: Requires all state agencies to implement multifactor authentication and maintain cybersecurity best practices.
  • Mississippi: Established limits on cyber liability claims and introduced new requirements for cybersecurity insurance.
  • Montana: Expanded its workforce development program to include cybersecurity roles beyond entry-level analysts.
  • Hawaii: Adopted resolutions to build cybersecurity education pipelines and strengthen its innovation economy.

These laws vary widely in scope and applicability. Some focus on procurement, others on workforce development, insurance, or incident reporting. Local governments must consult legal counsel to determine which laws apply and how to comply.

Compliance Checklists and Internal Oversight

To manage compliance effectively, local governments should maintain internal checklists that cover:

  • Data classification and retention policies.
  • Incident response and reporting protocols.
  • Vendor risk assessments and contract language.
  • Employee training and awareness programs.
  • Access controls and audit trails.
  • Insurance coverage and legal disclosures.

These checklists should be reviewed and updated regularly, especially when new laws are enacted or existing ones are amended. Legal advisors can help tailor these tools to your organization’s structure, risk profile, and regulatory environment.

Cybersecurity compliance is not one-size-fits-all. Each state may have different laws, and local governments must navigate these requirements with care. Legal review should be a standing agenda item for boards and councils, and compliance checklists should be living documents that evolve with the law.

If your organization hasn’t conducted a legal review recently, now is the time. Engage your legal team, update your checklists, and ensure that your cybersecurity practices are aligned with current and emerging regulations.

Categories
Basics & Actionable Steps

Cybersecurity Is a Team Sport: Why Local Governments Must Partner Up

In the face of increasingly sophisticated cyber threats, local governments must recognize that cybersecurity is not a solo endeavor. Defending against bad actors with more resources and reach requires collective action. No single entity can fully secure its digital infrastructure in isolation. By fostering collaboration—across departments, municipalities, and with state and federal partners—local governments can strengthen their defenses and build a more resilient cybersecurity posture.

Why Collaboration Matters

Cybersecurity is a shared responsibility. Collaboration enables local governments to:

  • Share threat intelligence and best practices.
  • Pool resources for tools and training.
  • Coordinate incident response and recovery.
  • Reduce costs through economies of scale.

Boards should actively support cross-departmental collaboration between IT, finance, legal, and risk management teams to ensure cybersecurity is integrated into all aspects of governance 

Risk Pooling and the Weakest Link

Risk pooling is one of the most effective collaborative strategies. By combining cybersecurity resources—such as firewalls, intrusion detection systems, and threat monitoring—municipalities can achieve stronger protection at lower cost. Shared services models, including CISO-as-a-Service, are especially valuable for smaller jurisdictions with limited budgets 

However, collaboration also means shared risk. A weak link in one organization’s defenses can expose others. For example, outdated software in one municipality could become an entry point for attackers targeting interconnected systems. This underscores the need for consistent security standards across all partners.

Information Sharing Platforms

Timely threat intelligence is critical. Local governments can stay ahead of cyber threats by participating in trusted information-sharing platforms:

Examples of Collaborative Initiatives

  • Cybersecurity Shared Services
    Some states offer centralized threat monitoring, incident response teams, and access to specialized tools for local governments.
  • Public-Private Partnerships
    Collaborating with cybersecurity firms can provide access to advanced technologies and expertise that may be out of reach for smaller municipalities.
  • Joint Cybersecurity Exercises
    Simulated cyberattacks involving multiple agencies help test response protocols, improve coordination, and identify gaps in preparedness.

Practical Steps to Foster Collaboration

  1. Formalize Agreements
    Establish MOUs or service-level agreements with partners to define roles, responsibilities, and expectations.
  2. Participate in Regional Consortia
    Join or form regional cybersecurity alliances to share resources and coordinate efforts.
  3. Conduct Tabletop Exercises
    Practice incident response scenarios with internal teams and external partners to build readiness.
  4. Align on Frameworks
    Use common cybersecurity frameworks like NIST CSF to ensure consistency across organizations 2.
  5. Engage Leadership
    Ensure boards and senior officials understand the value of collaboration and support cross-agency initiatives.
Categories
Basics & Actionable Steps

Staffing Models and Outsourcing Options: Strengthening Cybersecurity in Local Government

Cybersecurity is not a one-time project—it’s a continuous, evolving responsibility. For local governments, building and sustaining a capable cybersecurity workforce is one of the most critical challenges in protecting public assets and maintaining operational continuity. Whether through internal staffing or external partnerships, the goal is the same: ensure readiness, resilience, and accountability.

The Human Capital Challenge

Many municipalities operate with lean IT teams, and cybersecurity roles are often under-resourced or entirely absent. This creates gaps in monitoring, incident response, and strategic planning. Without dedicated cybersecurity personnel, even basic tasks like patch management, access control, and threat detection can fall behind—leaving systems vulnerable to attack.

Staffing decisions must reflect the evolving threat landscape. Cyber risks are dynamic, and the workforce must be equipped to adapt. This means investing in ongoing professional development, clarifying roles and responsibilities, and embedding cybersecurity into broader governance structures.

Internal Staffing Models

Local governments can consider several internal staffing approaches depending on their size, budget, and risk profile:

  • Dedicated Cybersecurity Roles: Larger municipalities may benefit from hiring full-time cybersecurity specialists, such as a Chief Information Security Officer (CISO), security analysts, and compliance officers. These roles provide strategic oversight and technical depth.
  • Integrated IT-Cyber Roles: In smaller agencies, cybersecurity responsibilities may be embedded within general IT roles. While cost-effective, this model risks diluting focus and accountability unless supported by clear expectations and training.
  • Cross-Functional Teams: Cybersecurity can be distributed across departments—legal, procurement, emergency management—ensuring that risk awareness is embedded throughout the organization. This model requires strong coordination and leadership engagement.

Outsourcing Options

For municipalities with limited internal capacity, outsourcing can offer access to specialized expertise and scalable services. However, outsourcing should complement—not replace—internal readiness.

  • Managed Security Service Providers (MSSPs): These vendors offer 24/7 monitoring, threat detection, and incident response. MSSPs can be cost-effective for small governments but require careful contract management and performance oversight.
  • Virtual CISO (vCISO): A vCISO provides strategic guidance on a part-time or project basis. This model is ideal for agencies that need executive-level insight without the cost of a full-time hire.
  • Shared Services and Risk Pools: Regional collaborations allow multiple municipalities to share cybersecurity resources, training programs, and insurance coverage. This approach fosters community resilience and reduces duplication.
  • Consultants and Project-Based Support: External experts can assist with specific initiatives—such as risk assessments, policy development, or compliance audits. These engagements should be clearly scoped and aligned with internal goals.

Making the Right Choice

Choosing between internal staffing and outsourcing is not binary. Most local governments benefit from a hybrid approach that balances internal knowledge with external support. Key considerations include:

  • Size and Complexity: Larger agencies may require in-house teams, while smaller ones can leverage shared services.
  • Budget Constraints: Outsourcing can reduce overhead but may introduce long-term costs if not managed carefully.
  • Risk Profile: High-risk environments demand deeper expertise and faster response times.
  • Governance Structure: Cybersecurity must be aligned with leadership priorities and embedded into decision-making processes.

Tips for Implementation

  1. Conduct a Workforce Gap Analysis
    Identify current capabilities, unmet needs, and future requirements.
  2. Define Clear Roles and Responsibilities
    Avoid overlap and ensure accountability across departments.
  3. Invest in Training and Upskilling
    Build internal capacity through certifications, workshops, and tabletop exercises.
  4. Establish Vendor Oversight Protocols
    Monitor performance, enforce service-level agreements, and conduct regular reviews.
  5. Promote Cyber Literacy Across the Organization
    Engage non-technical staff in awareness campaigns and basic security practices.
  6. Align Staffing Decisions with Strategic Goals
    Ensure that cybersecurity supports broader objectives like digital transformation, public trust, and operational resilience.
Categories
Basics & Actionable Steps

Protecting the Crown Jewels: How to Secure Mission-Critical Assets

In cybersecurity, not all assets are created equal. Some systems and data are so vital to a government’s mission that their compromise could result in severe disruption, financial loss, or public harm. These are known as high-value assets (HVAs)—the crown jewels of your organization’s digital infrastructure.

According to the Cybersecurity and Infrastructure Security Agency (CISA), HVAs are “information or an information system that is so critical to an organization that the loss or corruption of this information, or loss of access to the system, would have serious impact on the organization’s ability to perform its mission or conduct business.” For state and local governments, protecting HVAs is not optional—it’s foundational.


Step 1: Identifying and Assessing High-Value Assets

Before you can protect HVAs, you must know what they are. This begins with a thorough organizational assessment to identify systems and data that are mission-critical. Once identified, conduct a comprehensive risk assessment to evaluate vulnerabilities, dependencies, and potential impact.


Step 2: Patch Management

Unpatched systems are one of the most common entry points for attackers. While scheduling maintenance windows can be challenging, timely patching is essential to reduce exposure to known vulnerabilities. Prioritize HVAs in your patching schedule and automate where possible.


Step 3: Malware Defense and Anti-Phishing

Deploy automated tools to detect and neutralize malware. Phishing remains a top threat vector—especially for systems that store sensitive data. Implement email filtering, sandboxing, and user training to reduce the risk of infection.


Step 4: Access Control

Limit access to HVAs based on job roles. Avoid shared administrative accounts and enforce logging and monitoring of all key security events. Regular audits help ensure that access privileges remain appropriate and that remote access is tightly controlled.


Step 5: Authentication

Multi-factor authentication (MFA) is a must for all users accessing HVAs. It adds a critical layer of protection against unauthorized access and credential theft. Ensure MFA is enforced across all access points, including remote and mobile connections.


Step 6: Network Segmentation

Segment networks to isolate HVAs from less secure systems. This limits lateral movement in the event of a breach. Define zones with specific rules and restrictions, and monitor traffic between zones to detect anomalies.


Step 7: Employee Education

Human error is a leading cause of cybersecurity incidents. Train staff to recognize phishing attempts, avoid risky behaviors, and follow security protocols. Use awareness campaigns, simulations, and role-specific training to reinforce best practices.


CISA’s Recommended Actions for HVA Protection

CISA outlines five key actions to help organizations secure HVAs:

  1. Establish an Organization-Wide HVA Governance Program
    Make HVA protection a strategic priority across departments.
  2. Identify and Prioritize HVAs
    Focus resources on the most critical systems.
  3. Consider Interconnectivity and Dependencies
    Understand how systems interact and rely on one another.
  4. Develop a Methodology for Prioritizing HVAs
    Use mission impact to guide protection efforts.
  5. Develop an Assessment Approach for HVAs
    Determine how often to assess and whether to use internal or external evaluators.

Protecting mission-critical assets requires more than technical controls—it demands strategic oversight, cross-functional collaboration, and continuous improvement. By identifying HVAs, implementing layered defenses, and following CISA’s guidance, state and local governments can reduce risk and ensure continuity of operations.

Categories
Basics & Actionable Steps

Cybersecurity Laws Every Local Government Should Know

As local governments expand their digital services and manage increasing volumes of sensitive data, understanding cybersecurity laws and regulations becomes essential. These laws are designed to protect public information, ensure transparency, and reduce risk across critical infrastructure and public-facing systems.

While some regulations apply nationwide, many cybersecurity laws are state-specific and subject to frequent updates. Municipal leaders must stay informed and consult legal counsel or state regulatory agencies to ensure compliance with the laws applicable in their jurisdiction. Staying current is key to avoiding penalties and building resilient cybersecurity programs that align with both federal and state requirements.

Below is an overview of key cybersecurity laws and standards that local governments and affiliated organizations should be familiar with:


Health Insurance Portability and Accountability Act (HIPAA)

Jurisdiction: United States
HIPAA sets national standards for protecting health information. It applies to healthcare providers, insurers, and any entity handling patient data.
Key Provisions:

  • Requires security safeguards for health information.
  • Mandates breach notification and penalties for non-compliance.
  • Grants patients rights to access and correct their records.

Federal Information Security Modernization Act (FISMA)

Jurisdiction: United States
FISMA mandates that federal agencies and contractors secure their information systems using a risk-based approach aligned with NIST standards.
Key Provisions:

  • Establishes security requirements for federal systems.
  • Requires annual assessments and reporting.
  • Aligns with the NIST Cybersecurity Framework.

State and Local Government Cybersecurity Act of 2021

Jurisdiction: United States
This law supports state and local governments with resources to strengthen cybersecurity and defend critical infrastructure.
Key Provisions:

  • Provides grants for cybersecurity improvements.
  • Enhances defense against infrastructure threats.
  • Encourages collaboration across government levels.

Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)

Jurisdiction: United States
CIRCIA requires timely reporting of cyber incidents and ransomware payments by critical infrastructure entities.
Key Provisions:

  • Cyber incidents must be reported within 72 hours.
  • Ransomware payments must be reported within 24 hours.
  • Supports federal tracking and response efforts.

Gramm-Leach-Bliley Act (GLBA)

Jurisdiction: United States
GLBA governs how financial institutions collect, use, and protect consumer financial data.
Key Provisions:

  • Requires data security and privacy policies.
  • Regulates data sharing and disclosure practices.

Payment Card Industry Data Security Standard (PCI DSS)

Jurisdiction: Global
PCI DSS sets security standards for organizations handling payment card data.
Key Provisions:

  • Requires encryption and secure transmission protocols.
  • Mandates regular security assessments and audits.

Cybersecurity Enhancement Act of 2014

Jurisdiction: United States
This act promotes cybersecurity R&D and public-private collaboration to protect critical infrastructure.
Key Provisions:

  • Encourages joint efforts between government and industry.
  • Supports development of cybersecurity technologies.
  • Establishes national protection standards.

California Consumer Privacy Act (CCPA)

Jurisdiction: California
CCPA gives residents control over their personal data and applies to businesses meeting certain thresholds.
Key Provisions:

  • Right to access, delete, and opt out of data sale.
  • Requires disclosure of data collection practices.
  • Enforces penalties for mishandling personal data.

California Privacy Rights Act (CPRA)

Jurisdiction: California
CPRA expands CCPA protections and establishes a dedicated enforcement agency.
Key Provisions:

  • Adds rights to correct inaccurate data.
  • Limits use of sensitive personal information.
  • Creates the California Privacy Protection Agency.

Cybersecurity compliance is a moving target. Local governments must stay informed, build governance structures that support accountability, and ensure that cybersecurity policies reflect current legal requirements. Understanding these laws is the first step toward building a secure, resilient digital environment for public service.

Categories
Basics & Actionable Steps

What Good Cybersecurity Looks Like for Local Governments

In today’s digital landscape, cybersecurity is not just a technical safeguard—it’s a cornerstone of public trust and operational continuity. For local governments, good cybersecurity means more than installing antivirus software or responding to threats as they arise. It’s about creating a proactive, strategic, and resilient approach that protects public services, sensitive data, and community confidence.

Municipalities face unique challenges: limited budgets, legacy systems, and growing digital demands. Yet, with the right governance and mindset, they can build cybersecurity programs that are not only effective but sustainable. So, what does “good cybersecurity” actually look like in practice?

1. Risk-Driven Decision Making

Effective cybersecurity begins with understanding risk. Local governments must identify their most critical assets—emergency services, financial systems, citizen data—and prioritize protections based on threat likelihood and impact. This means moving beyond generic checklists and tailoring strategies to the specific risks facing each department and service.

2. Adaptive and Responsive Systems

Cyber threats evolve quickly. Good cybersecurity programs are flexible enough to respond to new vulnerabilities, emerging technologies, and changing operational needs. This includes regularly updating policies, patching systems, and adjusting access controls to reflect current realities.

3. Proactive Prevention

Prevention is always more cost-effective than recovery. Strong cybersecurity programs focus on stopping incidents before they happen—through layered defenses, continuous monitoring, and employee training. This includes phishing simulations, endpoint protection, and network segmentation to reduce the blast radius of any potential breach.

4. Clear Roles and Shared Responsibility

Cybersecurity is a shared responsibility. From elected officials to frontline staff, everyone plays a role. Good programs define responsibilities clearly—whether through a dedicated cybersecurity officer, cross-departmental governance committees, or vendor oversight. This clarity ensures accountability and reduces gaps in coverage.

5. Measurable Performance

You can’t improve what you don’t measure. Good cybersecurity includes metrics for performance—such as incident response times, patching rates, and training completion. These indicators help leaders monitor progress, identify weaknesses, and make informed decisions about resource allocation.

6. Collaboration and Communication

Local governments don’t operate in isolation. Good cybersecurity involves sharing threat intelligence with regional partners, state agencies, and trusted networks. It also means communicating clearly with the public—especially in the event of a breach—to maintain transparency and trust.

7. Continuous Learning and Awareness

Cybersecurity is not a one-time fix—it’s an ongoing process. Good programs invest in continuous education for both technical staff and decision-makers. This includes staying current on best practices, participating in training, and fostering a culture of vigilance across departments.

Why It Matters

When cybersecurity is strong, local governments can:

  • Deliver uninterrupted public services.
  • Protect sensitive data from misuse.
  • Avoid costly breaches and reputational damage.
  • Build public confidence in digital systems.

Ultimately, good cybersecurity is not just about technology—it’s about leadership, strategy, and community resilience.

Categories
Basics & Actionable Steps

Why Hackers Hack: Understanding Cyber Threat Motivations

Cyberattacks are not random acts of digital vandalism—they are calculated, purposeful, and often deeply strategic. To effectively defend against these threats, local governments must understand not just how hackers operate, but why they do it. The motivations behind cyberattacks are as diverse as the actors themselves, ranging from financial greed to ideological warfare.

Why Motivation Matters

To build stronger defenses, local government leaders must not only know who is behind cyber incidents, but also why they occur:

  • Prioritize defenses based on threat likelihood.
  • Identify high-risk assets and systems.
  • Tailor incident response plans to attacker profiles.
  • Improve staff awareness and training.

Motivations Behind Cyber Threats

MotivationActorsWhat They DoExamples
Financial GainOrganized Crime, Cybercriminals, InsidersExtort money, steal data for resale, manipulate systems for profitRansomware (REvil, Conti), BEC scams, data breaches, cryptojacking
Political ActivismHacktivists, Nation-StatesTarget governments or corporations to advance political agendasWebsite defacement, leaks tied to causes (e.g., Flint water crisis, Ukraine conflict)
EspionageNation-States, Insiders, Foreign Intelligence ServicesSteal sensitive data or intellectual property for strategic advantageAPT10 targeting defense contractors, research theft
Terrorism & DisruptionCyber Terrorists, Nation-StatesAttack infrastructure to cause fear or instabilityPower grid sabotage, water system disruption
Ideological MotiveHacktivists, InsidersAttack perceived enemies of their beliefsData leaks targeting anti-abortion groups or political dissenters
Mischief & Thrill-SeekingScript KiddiesLaunch attacks for fun, curiosity, or recognitionDDoS attacks, website defacement, bragging rights
Retaliation & GrudgeInsiders, HacktivistsSeek revenge against organizations or individualsDisgruntled employees leaking data or sabotaging systems
Social ChangeHacktivistsPromote civil disobedience or social justiceAttacks tied to BLM, environmental protests, anti-censorship

Implications for Local Governments

Understanding the motivations behind cyberattacks is not just an academic exercise—it’s a practical necessity for local government leaders. Each motivation corresponds to different tactics, targets, and levels of sophistication. For example:

  • Financially motivated attackers may exploit vulnerabilities in payment systems, tax databases, or procurement platforms.
  • Politically motivated actors might target law enforcement, election systems, or public health departments to make a statement or disrupt operations.
  • Insiders with grievances could misuse access to leak sensitive data or sabotage systems from within.

This diversity in threat profiles means that a one-size-fits-all approach to cybersecurity is insufficient. Local governments must tailor their defenses to the specific risks they face, based on the motivations most likely to target their operations.

Turning Insight into Action

To effectively counter these threats, municipalities should adopt a motivation-aware cybersecurity strategy. Here are key steps to consider:

1. Threat Modeling Based on Motivation

Map out which motivations are most relevant to your organization. For example, if your agency handles sensitive personal data, financial gain and espionage may be top concerns. If your work intersects with controversial public policies, ideological motives and hacktivism may be more likely.

2. Layered Defense Architecture

Implement multiple layers of security controls—technical, administrative, and physical—to protect against both external and internal threats. This includes firewalls, endpoint protection, access controls, and data encryption.

3. Insider Risk Management

Develop policies and monitoring systems to detect and prevent insider threats. This includes background checks, access reviews, and behavioral analytics to identify anomalies.

4. Staff Training and Awareness

Educate employees on the tactics used by different threat actors. Tailored training can help staff recognize phishing attempts, social engineering, and suspicious behavior.

5. Incident Response Planning

Prepare for different types of attacks by creating scenario-based response plans. A ransomware attack requires a different response than a politically motivated data leak or a DDoS attack launched for mischief.

Cybersecurity is not just about technology—it’s about understanding human intent. By recognizing the motivations behind cyberattacks, local governments can build smarter, more resilient defenses that protect public trust and ensure continuity of services.

Categories
Basics & Actionable Steps

Know Your Enemy: The 8 Types of Cyber Threat Actors

Cybersecurity is no longer a niche concern—it’s a frontline issue for local governments. From ransomware attacks that paralyze public services to data breaches that expose sensitive resident information, the threat landscape is growing more complex and dangerous. At the heart of this digital battleground are the cyber threat actors, often referred to as “bad actors.” These individuals or groups exploit technology to conduct malicious activities such as hacking, phishing, and malware deployment.

Bad Actors vs. Defenders: The Asymmetry of Cyber Conflict

The economic dynamics of cybersecurity are starkly imbalanced. Attackers only need to succeed once, while defenders must be flawless every time. This asymmetry creates a daunting challenge for local government cybersecurity teams.

  • Low Cost of Entry for Attackers: The barrier to entry for launching cyberattacks has never been lower. On the dark web, malicious tools and services are readily available for purchase or rent. For example:
    • Ransomware-as-a-Service (RaaS) platforms allow even non-technical criminals to deploy sophisticated attacks.
    • Phishing kits with pre-built templates and spoofing tools can be bought for under $50.
    • DDoS-for-hire services can be used to overwhelm public websites or internal systems for as little as $200.
  • High Cost for Defenders: In contrast, defenders must secure every endpoint, every user, and every system—24/7. Even a single overlooked vulnerability can lead to catastrophic consequences. For local governments, this means:
    • Maintaining up-to-date patches across legacy systems that may not be easily upgradeable.
    • Training staff to recognize and report phishing attempts, despite high turnover or limited cybersecurity awareness.
    • Monitoring networks for anomalies, often without a dedicated security operations center (SOC).
    • Complying with regulations and reporting requirements, which add administrative overhead.

This uneven playing field means attackers can afford to be opportunistic, while defenders must maintain constant vigilance.

The Imbalance in Risk and Reward

This asymmetry creates a risk-reward imbalance:

AspectAttackersDefenders
CostLow (tools are cheap or free)High (tools, staff, training, compliance)
EffortOne successful exploit is enoughMust defend all vectors, all the time
RiskOften anonymous, low legal riskHigh accountability, legal and reputational consequences
ScaleCan automate and replicate attacksMust tailor defenses to each system and user

For defenders, the cost of failure is steep:

  • Financial Losses: Ransom payments, recovery costs, and lost revenue.
  • Reputational Damage: Loss of public trust, especially if resident data is compromised.
  • Operational Disruption: Downtime in essential services like emergency response, utilities, or public records.
  • Legal and Regulatory Penalties: Non-compliance with data protection laws can result in fines and audits.

Types of Cyber Threat Actors

Understanding the motivations, capabilities, and tactics of cyber threat actors is essential for building resilient defenses—especially for local governments that manage sensitive data and critical infrastructure. These actors vary widely in sophistication, intent, and impact, but each poses a unique risk to public sector organizations.

Type of ActorWho They AreWhat They DoMotivation
Nation-StatesGovernment-backed groups with extensive resources and strategic objectives.Launch Advanced Persistent Threats (APTs), conduct espionage, disrupt infrastructure, and manipulate political systems.Espionage, geopolitical advantage, economic disruption.
Organized CrimeSophisticated criminal syndicates operating like businesses.Deploy ransomware, steal data, commit fraud, and sell stolen credentials.Financial gain through extortion, blackmail, and identity theft.
HacktivistsIdeologically driven individuals or groups.Deface websites, leak sensitive data, disrupt services to promote causes.Political activism, social justice, retaliation.
InsidersEmployees, contractors, or vendors with privileged access.Leak data, sabotage systems, or unintentionally expose vulnerabilities.Grievance, financial reward, coercion, or ideological alignment.
Script KiddiesInexperienced individuals using pre-made tools.Launch DDoS attacks, deface websites, or breach systems for fun.Recognition, boredom, curiosity.
Cyber TerroristsExtremist groups seeking to cause fear and disruption.Target critical infrastructure, emergency services, and communication networks.Ideological warfare, political destabilization.
Foreign Intelligence ServicesState-sponsored espionage units.Steal sensitive data, conduct influence operations, and manipulate public opinion.National security, economic advantage, political leverage.
Terrorist OrganizationsRadical groups using cyber tactics as part of broader warfare.Attack infrastructure, disrupt governance, and spread propaganda.Retaliation, ideological extremism, destabilization.

Each actor type presents unique risks, and their tactics evolve constantly. Defenders must understand the Tactics, Techniques, and Procedures (TTPs) used by adversaries to stay ahead.

What Local Government Leaders Can Do

To counter this imbalance, local government must:

  • Prioritize cybersecurity as a strategic risk, not just an IT issue.
  • Invest in layered defenses, including endpoint protection, network segmentation, and incident response planning.
  • Foster a culture of security awareness across all departments.
  • Leverage partnerships with state and federal cybersecurity agencies for threat intelligence and support.

Sign In

Register

Reset Password

Please enter your username or email address, you will receive a link to create a new password via email.