Cybersecurity Expert Calls on Professionals to Help Defend Local Governments Against Cyber Threats
A shocking case of cyber theft has highlighted a critical vulnerability in local governments across the United States. A small housing authority lost nearly a million dollars after attackers quietly infiltrated staff email accounts and rerouted funds meant for an affordable-housing project. The breach was not discovered until it was too late, but the aftermath has sparked a call to action from cybersecurity expert Darshan Tiwari.
Tiwari, CEO of Consultadd Public Services, has worked with over 80 local government agencies across 46 states and has witnessed firsthand the devastating impact of cyber attacks on these organizations. “The breach isn’t how the story ends,” he notes. “It’s what finally pushed the agency to stand up a real security program.” That program is now one of the best-defended shops Tiwari works with, demonstrating that even the most vulnerable organizations can make significant improvements.
The problem lies in the fact that local governments often have fewer resources than their federal counterparts to devote to cybersecurity. More than 80% of state and local organizations run security with fewer than five dedicated staff members. These agencies are not careless; they’re outnumbered by the sophisticated cyber threats they face every day. Tiwari emphasizes that resourcing problems can be designed around, and he’s seen several strategies work in his experience.
One key approach is to focus on basic questions about exposure rather than jumping straight into product recommendations. “What are you running, what data are you sitting on, where are you actually exposed?” Tiwari asks. This involves understanding the unique needs of each agency and tailoring solutions accordingly. For example, a county with one administrator covering 14 departments requires a different plan than a school district.
Another crucial aspect is meeting agencies at their budgetary level rather than trying to fit them into expensive enterprise security packages. “Most enterprise security is priced and bundled for organizations with seven-figure budgets,” Tiwari notes. A county working with a limited IT budget can’t afford those solutions, but it can buy scoped risk assessments, MFA rollouts, or incident-response retainers on its own terms.
Tiwari also stresses the importance of compliance in this process. Agencies must meet regulations such as HUD rules and CJIS requirements for handling sensitive data. By leading with these compliance conversations upfront, agencies’ leadership can feel confident in their security decisions without feeling like they’re taking unnecessary risks.
The final takeaway is that cybersecurity professionals have a responsibility to share their knowledge and expertise beyond just individual clients. Writing up anonymized findings and sharing them with regional government-IT associations can create a ripple effect of improved cybersecurity across multiple agencies.
Ultimately, Tiwari’s message is clear: local governments need help defending against cyber threats, but this requires a willingness to treat smaller budgets as real customers and build solutions that fit their unique needs. This is not a matter of waiting for Congress or new grants; it’s a decision to act now and make a difference in the lives of those most vulnerable to cyber attacks.
Source: Dark Reading — 2026-08-21