Calling on Cyber Pros to Help Defend City Hall

Government agencies with limited budgets often find themselves vulnerable to cyber attacks due to a lack of resources. A recent case highlights this issue, where a local housing authority lost nearly a million dollars without even detecting it. Attackers gained access to staff email accounts, monitored financial transactions for months, and then quietly rerouted funds meant for an affordable-housing project. This breach could have been prevented with proper security measures in place.

The agency’s transformation into one of the better-defended shops in its field is a testament to the potential for change. Darshan Tiwari, CEO of Consultadd Public Services, has worked with 82 government agencies across the US and witnessed this turnaround multiple times. He emphasizes that local governments hold sensitive data similar to federal departments but often lack the personnel to protect it.

According to Tiwari, more than 80% of state and local organizations run security operations with fewer than five dedicated staff members. This is not due to carelessness, but rather a result of being outnumbered by resources required to secure their systems. To bridge this gap, agencies can start by assessing their exposure to potential threats, rather than focusing on tools or products.

Tiwari stresses the importance of meeting agencies where their budget actually is. Many enterprise security solutions are priced and bundled for organizations with large budgets, which local governments simply cannot afford. Breaking down security work into smaller, manageable pieces that fit within an agency’s budget can make a significant difference in getting help when needed.

Another key aspect is prioritizing compliance conversations from the outset. Agencies often live under specific regulations, such as HUD rules or CJIS-regulated records, and must demonstrate adherence to these standards. By leading with compliance discussions, Tiwari notes that small agencies’ leadership can feel more confident in investing in security measures.

Tiwari also highlights the importance of maintaining relationships with agencies after contracts are signed. He emphasizes that regular check-ins, retraining, and adjusting to evolving threats are crucial for long-term success. This is especially true when an agency’s IT department relies heavily on a single individual.

Finally, Tiwari encourages cybersecurity professionals to share anonymized findings from their work with regional government-IT associations. By doing so, valuable insights can be shared across agencies, providing a collective defense against common threats.

Ultimately, addressing the security needs of local governments requires treating smaller budgets as real customers and building solutions that fit within those constraints. This approach does not rely on federal funding or grants but rather on the willingness to adapt and innovate.


Source: Dark Reading — 2026-08-21