Cyberattacks on local governments are on the rise — and for good reason.
"They're target-rich and cyber-poor," explained Michael Klein, senior director for preparedness and response at the Institute for Security and Technology , a non-profit security think tank in Oakland, Calif.
"Local governments hold all kinds of data that criminals want — social security numbers, health data, kids' data, payment systems — and often those are only defended by small government levels of security," he told TechNewsWorld.
Local government agencies typically have more people wearing multiple hats for a variety of reasons, including budget and staffing constraints, noted Ashley Knowles, a senior cybersecurity consultant at Black Hills Information Security , a penetration testing, red teaming, and threat hunting company in Spearfish, S.D.
"So it can be harder to patch systems against security issues, stay ahead of current cybersecurity trends, and ensure business continuity should systems be affected by an attack," she told TechNewsWorld.
"Local government agencies are always going to be a target to attack because of their ability to affect large numbers of people," she added. "The more people affected by an attack, the bigger the payout may be, if it's a ransomware attack."
Taken together, those factors make local governments especially attractive targets for cybercriminals.
A recent report by Comparitech found ransomware is a global problem for governments, with at least one attack on a government entity every day during the first half of this year. It added that global attacks increased 13% during that period over the second half of 2025, and that nearly a third (31%) of 2026 first-half attacks were in the United States.
"Comparitech's numbers show the median demand on government entities fell to $100,000 in the first half of this year, a fifth of what it had been six months earlier," pointed out Bob Maley, chief security officer at Black Kite , a cyber risk management and assessment company in Boston.
"I read that as attackers pricing to what a small municipality can actually come up with," he told TechNewsWorld. "They've figured out the segment, and are running it like a volume business."
He recalled the challenges of setting up a cybersecurity program when he was CISO of Pennsylvania. "The Commonwealth ran a major consolidation called Operation Secure Enterprise," he explained. "Every agency had its own patching and monitoring, and the governor's office wanted it brought under one roof."
"You could have ordered the agencies to comply, and they would have found a hundred ways to slow-walk it," he said. "What the administration did instead was create the funding to pay for the consolidation and manage it centrally, and I could not have done what I did there without that."
"Almost no town or county gets that kind of deal," he noted. "The mandate arrives with no clear funding source, which then leaves the expectation sitting on whatever IT staff already exists, usually one person, and she is already getting recruited every week by companies offering twice her salary."
"She patches what she can reach and holds the rest together on a wing and a prayer, Band-Aids and bubblegum," he added.
"The town council usually does care," he continued, "but potholes just hold a better advantage in a budget fight. They get photographed. They get complained about at public meetings — and by Friday, somebody is standing next to fresh asphalt taking credit, wh…
