Calling on Cyber Pros to Help Defend City Hall

Local Governments Vulnerable to Cyberattacks, But Experts Say There’s Hope for Improvement

A recent cybersecurity breach at a small local government agency has highlighted the alarming vulnerability of these institutions to cyber threats. The incident, which resulted in the loss of nearly $1 million, was a wake-up call for the agency, but also an opportunity for them to finally establish a robust security program.

The agency in question is not an isolated case. Many local governments face similar challenges when it comes to cybersecurity. With limited budgets and personnel, they struggle to keep pace with the ever-evolving threat landscape. According to Darshan Tiwari, CEO of Consultadd Public Services, who has worked with over 80 government agencies across 46 states, local governments often have fewer than five dedicated staff members handling security, making it a daunting task.

The problem lies not just in the resources available but also in the approach taken by many organizations. “Most enterprise security is priced and bundled for organizations with seven-figure budgets,” Tiwari explains. “A county working with $200,000 for all of IT can’t buy that way.” Instead, he advocates for breaking down the work into smaller, manageable pieces that fit within an agency’s budget.

One key takeaway from Tiwari’s experience is the importance of starting with basic questions about exposure and risk. “Every engagement I take begins with the boring questions: What are you running, what data are you sitting on, where are you actually exposed,” he says. By focusing on these fundamental aspects, agencies can develop a tailored security plan that meets their specific needs.

Another critical aspect is compliance. Local governments often operate under strict regulatory requirements, such as those set by HUD or CJIS. Tiwari stresses the need to address these compliance concerns upfront, rather than after the contract has been signed. This approach not only ensures that agencies are meeting their obligations but also helps build trust with leadership and stakeholders.

Finally, Tiwari emphasizes the importance of relationships and continued support. “When your whole IT department is one overworked person, that relationship matters more than any tool on the invoice,” he notes. Regular check-ins, training, and adjustments as threats evolve are essential for long-term success.

While the situation may seem dire, Tiwari remains optimistic. By taking a collaborative approach and tailoring solutions to fit smaller budgets, experts like him believe that local governments can improve their cybersecurity posture and better protect sensitive data.

In fact, one of the most effective ways to drive positive change is through knowledge sharing and community engagement. Anonymized findings from engagements should be shared with regional government-IT associations, allowing lessons learned to benefit multiple agencies at once.

Ultimately, improving cybersecurity in local governments requires a willingness to adapt and innovate within existing budget constraints. By treating smaller budgets as real customers and building solutions that fit their needs, we can help close the gap between vulnerability and resilience.


Source: Dark Reading — 2026-08-21