Cybersecurity for Cities and Counties: A Practical Guide for Municipal Leadership
Published by the 0g0 research team
Cities and counties are among the most frequently attacked government entities in the United States — and among the least equipped to defend themselves. The combination of outdated infrastructure, limited cybersecurity budgets, small IT teams, and highly sensitive operational systems creates an attack profile that ransomware operators and other adversaries actively target.
The consequences of successful attacks on municipal systems are immediate and visible to citizens: 911 services degraded, permit offices closed, tax payments unable to be processed, emergency responders unable to access critical information. Unlike a corporate data breach that manifests primarily as a financial and reputational event, a municipal cyberattack disrupts the essential services that citizens depend on daily.
This guide is written for municipal officials — mayors, managers, council members, and department heads — who are responsible for cybersecurity outcomes but who are not technical specialists. It provides the context needed to ask the right questions, make informed investment decisions, and hold staff accountable for security outcomes.
Why Municipal Government Is Targeted
Municipal governments are attractive targets for several compounding reasons:
Essential services under pressure: Like healthcare, municipal services cannot simply stop. A city that cannot process payroll faces immediate crisis. An emergency services system that is offline is a life-safety issue. This pressure to restore operations quickly is leverage that ransomware operators deliberately exploit.
Rich databases of sensitive citizen information: Municipal systems contain Social Security numbers, financial information, property records, business license information, court records, and the full range of personal information that government collects to serve citizens. This data has significant criminal market value.
Limited security resources: A city of 50,000 people may have a single IT director who is also the network administrator, helpdesk, and de facto security officer. The budget for cybersecurity tools, training, and external expertise is a fraction of what a comparable private organisation would invest.
Aging infrastructure: Municipal IT systems often include software and hardware purchased under budget cycles that prioritised initial cost over long-term security. End-of-life systems running unsupported software are common.
Multiple entry points: Modern municipalities use dozens of software systems — utility billing, permits, courts, payroll, public works, emergency services. Each system is a potential entry point, and the vendors who maintain those systems introduce additional supply chain risk.
Real Attacks on Real Cities
The scale and frequency of ransomware attacks on municipal governments makes sobering reading:
Atlanta, Georgia (2018): A SamSam ransomware attack took city systems offline for days, disabled court and utility services, and cost the city an estimated $17 million to remediate — against an initial ransom demand of $51,000.
Baltimore, Maryland (2019): A RobbinHood ransomware attack encrypted city servers, shutting down email, bill payment systems, and other services for weeks. Recovery cost exceeded $18 million.
New Orleans, Louisiana (2019): A Ryuk ransomware attack forced the city to declare a state of emergency and take all city computers offline. Recovery took months.
Colonial Pipeline (2021): While a private company, the Colonial Pipeline ransomware attack demonstrated the cascading consequences of attacks on critical infrastructure — fuel shortages across multiple states from a single cyberattack.
These are not exceptional events. The MS-ISAC (Multistate Information Sharing and Analysis Center) reports hundreds of significant cyber incidents affecting state and local governments annually.
The Right-Sized Approach: Security Without a Fortune 500 Budget
Municipal cybersecurity does not require the budget of a large federal agency. The most impactful security improvements are not the most expensive, and a disciplined focus on the fundamentals delivers substantial risk reduction at manageable cost.
Multi-factor authentication: The most common initial access vector for ransomware attacks is compromised credentials — stolen passwords used to access email, VPN, or management systems. MFA prevents credential theft from translating into system access. It costs relatively little to implement, is not technically complex, and prevents a large proportion of the attacks that have devastated comparable municipalities. Implementing MFA for all staff — starting with administrator accounts and remote access — should be the first priority of any municipal security programme.
Regular, tested backups: The ability to restore from backup without paying ransom is the single most important ransomware resilience capability. Backups must be stored separately from the systems being backed up (ideally offline or in immutable cloud storage), tested regularly to confirm they can actually be restored, and retained for sufficient time periods to detect slow-moving attacks before the backup set is entirely compromised.
Patching: Unpatched vulnerabilities in internet-facing systems are a primary entry point for attackers. A systematic patching programme that keeps operating systems and critical applications current significantly reduces the available attack surface. This requires a known inventory of all systems (which many municipalities lack) and a process for deploying patches promptly when they are released.
Staff training: Phishing emails are the entry point for a majority of cyber incidents. Staff training that helps employees recognise and report suspicious emails — combined with technical controls that reduce the effectiveness of phishing — addresses the most exploited human vulnerability.
Network segmentation: Preventing a ransomware attack from spreading from a compromised workstation to the entire city network requires basic network segmentation. At minimum, critical operational systems (911, utilities, financial) should be separated from general administrative networks so that a compromise in one area cannot immediately propagate to all others.
Leveraging Federal and State Resources
Municipal governments do not have to build security entirely with their own resources. Several federal and state programmes provide significant free or heavily subsidised security capabilities:
MS-ISAC membership (free): The Multistate Information Sharing and Analysis Center provides threat intelligence, 24/7 security operations center services, and security assessments at no cost to state and local governments.
CISA resources (free): The Cybersecurity and Infrastructure Security Agency provides free vulnerability assessments, network monitoring tools, and incident response assistance to state and local governments.
FEMA Cybersecurity grants: Federal grant programmes support cybersecurity investment at state and local levels. The State and Local Cybersecurity Grant Programme provides hundreds of millions of dollars annually for cybersecurity improvements.
State cybersecurity programmes: Many states maintain programmes that provide security assessments, shared services, and technical assistance to local governments within the state.
Governance: Who Is Responsible?
Cybersecurity accountability in municipal government often falls into a gap between the IT department (which does not have decision-making authority over all the systems it needs to secure), department heads (who see cybersecurity as an IT responsibility), and elected officials (who may not engage with cybersecurity until after an incident).
Effective municipal cybersecurity requires clear governance: an identified individual (CISO, IT Director, or equivalent) with clear authority and responsibility for cybersecurity across all municipal systems, access to decision-makers, and a reporting relationship that reaches the city manager or mayor.
Regular security briefings to elected officials — not technical briefings, but business-risk briefings that communicate in terms of operational impact and budget — create the executive engagement that drives appropriate investment and accountability.
Building Your Municipal Security Programme
The realistic starting point for most municipalities is:
1. Conduct a basic security assessment — understand your current exposure before investing in solutions
2. Implement MFA for all staff, starting with administrators
3. Establish regular, tested backup procedures
4. Join MS-ISAC for free threat intelligence and security monitoring
5. Implement a systematic patching process
6. Conduct phishing awareness training for all staff
These six steps, implemented consistently, substantially reduce municipal cyber risk at manageable cost. They address the most common attack vectors and provide the foundational capabilities that more sophisticated security programmes build on.
0g0 Aegis works with municipal governments of all sizes, recognising that our job is to deliver appropriate security for the resources available rather than the ideal programme regardless of budget. We provide municipal security assessments, programme design, and managed security services that deliver enterprise-level protection at a cost that municipal budgets can sustain.
Need a product briefing?
Talk about the 0g0 Appliance for your environment — available now. Services are light support as the practice grows.
Request a BriefingFree Assessment Tools
Test your own security posture with our free tools — no account required.
Explore free toolsProtect your organisation
Request a briefing on the 0g0 Appliance. Research is context — the product conversation is next.
Request a Briefing