TL;DR: State and local governments are facing rising ransomware pressure, aging infrastructure, and shrinking budgets while carrying sensitive citizen data, according to Knowbe4’s whitepaper. Human risk management and awareness programmes are positioned as a cost-conscious way to reduce exposure when staffing and funding cannot keep pace.
At a glance
What this is: This whitepaper argues that state and local agencies are under sustained cyber pressure because constrained budgets, legacy systems, and sensitive data create a highly attractive target profile for attackers.
Why it matters: It matters to IAM, security, and GRC teams because the same resource constraints that weaken endpoint and recovery controls also delay identity hygiene, access review, and user-risk governance.
By the numbers:
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.
👉 Read Knowbe4's whitepaper on state and local cybersecurity burdens
Context
State and local cybersecurity is often framed as a funding problem, but it is also a governance problem. When agencies run aging infrastructure, manage large volumes of citizen data, and depend on understaffed teams, their control environment becomes brittle long before an attacker arrives. That is where identity governance, privilege discipline, and user behaviour controls become harder to sustain.
The whitepaper’s core argument is that human risk management can reduce exposure even when budgets are tight. For NHIMG, the identity angle is clear: when operational capacity is limited, organisations need stronger prioritisation around who has access, how access is reviewed, and how quickly risky behaviour is detected and corrected. That starting position is common across public sector environments, not exceptional.
Key questions
Q: What fails when state and local agencies try to rely on awareness training alone?
A: Awareness training fails when it is treated as a substitute for identity and access control. Users may still click phishing links, reuse credentials, or mishandle data if MFA, privilege restriction, and access review are weak. Training works best when paired with measurable governance controls that reduce the chance of a single user mistake becoming a major incident.
Q: Why do public sector agencies remain attractive ransomware targets?
A: They often hold sensitive personal information, run essential services, and operate mixed or legacy environments that are harder to standardise. That combination gives attackers both leverage and opportunity. The risk is amplified when identity controls, recovery planning, and staff readiness are uneven across departments or jurisdictions.
Q: How should security teams measure whether human risk management is actually reducing risk?
A: Use outcome metrics, not just participation data. Track behaviour such as phishing reporting, policy exception rates, risky link clicks, and secure workflow adoption by persona or business unit. Then compare those signals against identity and access outcomes so the programme shows whether human behaviour is changing in ways that reduce real exposure.
Q: Who is accountable when ransomware hits during a major business event?
A: Accountability should sit with the owners of privileged access, identity recovery, and business change governance, not with the SOC alone. During mergers, acquisitions, or layoffs, response depends on clear authority over access decisions and system restoration. If that authority is unclear, containment slows and the blast radius grows.
Technical breakdown
Why understaffed agencies struggle to maintain identity control
Understaffed public sector environments tend to accumulate control debt. Identity workflows such as account review, role cleanup, privilege escalation approval, and offboarding depend on consistent execution, but limited staff usually means exceptions pile up and stale access lingers. Over time, that creates a broader attack surface than the budget figures alone suggest. In practical terms, the security issue is not just fewer people, but fewer opportunities to keep identity and access controls aligned with real operational change.
Practical implication: reduce manual identity tasks to the few workflows that most directly cut risk, especially privileged access and stale account cleanup.
How ransomware pressure changes the control priority mix
Ransomware campaigns against public sector organisations exploit whichever control is weakest at the time of compromise. In many cases, that means phishing, exposed credentials, weak segmentation, or delayed detection, followed by privilege expansion and encryption or extortion. For agencies with limited response capacity, the priority shifts from trying to harden everything evenly to reducing the blast radius of inevitable compromise. That is why governance, segmentation, and identity restrictions matter as much as backup strategy.
Practical implication: treat access restriction and segmentation as containment controls, not just compliance tasks.
Human risk management as a compensating control
Human risk management works when it identifies the behaviours that most often lead to incidents, then applies targeted intervention instead of generic training alone. In public sector settings, that can include repeated phishing susceptibility, poor password and MFA habits, weak reporting behaviour, or unsafe handling of sensitive data. The model is strongest when it connects awareness to measurable outcomes such as fewer risky clicks, faster reporting, and reduced recurrence of the same failure pattern.
Practical implication: tie awareness activity to measurable behaviour change, not attendance counts or course completion.
Threat narrative
Attacker objective: The attacker seeks operational disruption and leverage over sensitive public sector data, often to force payment or maximise service downtime.
- Entry often begins with phishing, credential theft, or exposed remote access in a resource-constrained environment where controls are inconsistently maintained.
- Escalation follows when the attacker reaches privileged accounts or flat internal networks, allowing movement from one system to broader operational data and backups.
- Impact comes from ransomware encryption, data theft, service disruption, or extortion against agencies that cannot quickly isolate affected systems or restore operations.
NHI Mgmt Group analysis
Public sector cyber risk is increasingly a control-capacity problem, not just a threat-intensity problem. Underfunded agencies do not simply face more attacks. They face slower patching, weaker identity hygiene, and more difficulty sustaining routine access governance. That makes every control depend on people who are already overloaded, which increases the chance of drift. The practitioner conclusion is that resilience planning must account for operating capacity, not just threat volume.
Human risk management is most useful when it is tied to identity and access outcomes. Awareness campaigns alone do not stop ransomware or data loss if users still reuse passwords, ignore MFA prompts, or mishandle sensitive data. The value comes when HRM is connected to measurable reductions in risky behaviour and to specific IAM controls such as MFA enforcement, access review, and privilege restriction. The practitioner conclusion is to treat human risk as an access governance signal, not a communications metric.
Blast-radius reduction is the named concept this whitepaper points toward. In low-resource environments, the real question is not whether compromise can be fully prevented, but how far it can spread once it happens. That means limiting lateral movement, tightening privileged access, and separating critical services from everyday user accounts. The practitioner conclusion is to prioritise containment over broad but shallow control coverage.
State and local environments should be judged by their repeatable control discipline, not by policy intent. Many agencies have policy frameworks that look adequate on paper but lack staffing to execute them consistently. This is where governance fails: the control exists, but the operating model cannot sustain it. The practitioner conclusion is to audit which identity and response tasks are actually repeatable with current resources.
Identity governance becomes a force multiplier when budgets are constrained. If an agency cannot staff every defensive function equally, it should direct attention to the identity points that amplify other risks: admin accounts, remote access, access recertification, and account lifecycle gaps. That approach aligns with broader security frameworks and gives the highest return on limited effort. The practitioner conclusion is to fund the controls that reduce downstream workload the most.
What this signals
State and local agencies should expect identity governance work to become more operationally important as staffing pressure persists. The agencies that cope best will be the ones that can prove access review, MFA enforcement, and privileged account cleanup still happen when the security team is stretched thin. For that reason, the control problem is as much about repeatability as it is about policy. Blast-radius reduction: the practical aim is to limit how far one compromised account can move before containment starts.
Public sector programmes also need to recognise that awareness data can be an early warning indicator rather than a standalone success metric. If users continue to fail phishing simulations or mishandle sensitive records, the issue is usually control design as much as behaviour. Where identity risk is part of the problem, controls like least privilege and segmented access need to be tightened alongside training. That is where the governance signal becomes actionable rather than cosmetic.
Teams that can link human risk patterns to access decisions will get better resilience from the same budget. The most useful next step is to connect reporting behaviour, privilege exposure, and access review backlog into one operating view. That creates a clearer picture of where constrained resources are producing the most security debt.
For practitioners
- Prioritise privileged access cleanup Review admin accounts, dormant service access, and remote administration paths before broader user hygiene initiatives. This is where limited staff can remove the most dangerous standing access first.
- Map ransomware containment to identity controls Define which accounts, systems, and segments must be isolated if ransomware appears, then test those controls against the agency’s real recovery workflow and backup dependencies.
- Use human risk signals to target intervention Focus awareness and coaching on users who repeatedly fail phishing, MFA, or sensitive data handling checks, then measure whether the same behaviours decline over time.
- Automate access review for critical roles Reduce manual recertification load by automating reviews for the highest-risk roles first, especially where staffing shortages make quarterly or monthly checks unrealistic.
- Align response playbooks to limited capacity Write playbooks that match the number of people actually available to execute them, then identify which response steps can be pre-authorised or simplified under pressure.
Key takeaways
- State and local agencies face a combined threat of ransomware pressure, legacy infrastructure, and limited operating capacity.
- Human risk management only becomes meaningful when it changes access behaviour and reduces measurable exposure.
- The strongest use of scarce resources is to shrink blast radius, prioritise privileged access, and make governance repeatable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Access control and identity governance are central to reducing public sector blast radius. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is directly relevant to understaffed agencies with stale access and weak lifecycle controls. |
| CIS Controls v8 | CIS-5 , Account Management | Account management discipline is the clearest control lever in constrained public sector environments. |
| ISO/IEC 27001:2022 | A.5.15 | Access control governance maps directly to agencies that need repeatable approval and review processes. |
Use PR.AC-1 to verify each critical role has only the access it needs and that reviews are actually performed.
Key terms
- Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Privileged Access: Privileged access is any elevated entitlement that can change systems, data, or security settings. When privilege is excessive or poorly scoped, a single compromised identity can create outsized blast radius across environments.
What's in the full report
Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- The report’s breakdown of ransomware frequency across state and local government environments and why that matters for funding decisions.
- The specific staffing and budget pressures agencies report when trying to maintain basic cyber hygiene and response readiness.
- The way human risk management is positioned as a measurable mitigation model rather than a generic awareness programme.
- The full framing for how citizen data exposure and critical infrastructure disruption change the risk equation for municipalities.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management in a way that supports broader identity programmes. It helps practitioners connect access discipline to the wider security controls their organisations rely on.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org