TL;DR: Government agencies remain attractive ransomware targets because they hold personal data, critical services, and politically sensitive information, according to Knowbe4's whitepaper on cybersecurity in government. The practical challenge is not only stronger tooling, but a multi-layered operating model that reduces exposure, hardens access, and improves staff resilience before attackers exploit the weakest link.
NHIMG editorial — based on content published by Knowbe4: Cybersecurity in Government
Questions worth separating out
Q: How should government agencies reduce ransomware risk across user and privileged access?
A: Start by reducing standing privilege, tightening authentication on critical systems, and limiting how far a single compromised account can travel.
Q: Why do public sector agencies remain attractive ransomware targets?
A: They often hold sensitive personal information, run essential services, and operate mixed or legacy environments that are harder to standardise.
Q: What do security teams get wrong about awareness training in government?
A: They treat it as a standalone compliance activity instead of a control that supports detection and decision-making.
Practitioner guidance
- Prioritise critical-service protection Identify the agency systems whose outage would create the greatest public impact, then apply stricter access controls, monitoring, and recovery requirements to those services first.
- Reduce standing administrative privilege Review privileged accounts, remove persistent admin rights where possible, and reserve emergency access for tightly governed, time-bound use cases.
- Harden phishing and reporting workflows Train staff on phishing, credential theft, and suspicious request handling using examples from everyday government email and service processes.
What's in the full report
Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- Practical advice on reducing ransomware exposure in government settings
- Specific reasons government agencies remain attractive targets to attackers
- Mitigation steps for protecting agencies against ransomware and other threats
- How security awareness training fits into the last line of defence
👉 Read Knowbe4's whitepaper on cybersecurity in government →
Government cybersecurity risk: what agencies need to do now?
Explore further
Government cybersecurity fails when agencies treat resilience as a technology problem instead of an access and recovery problem. Ransomware and other threats succeed where identity governance, backup assurance, and operational continuity are managed separately. That separation leaves attackers room to move from one compromised account into critical services. Practitioners should align access control, recovery planning, and incident response around the same critical systems.
A question worth separating out:
Q: Who is accountable when ransomware payment decisions must be reported to government?
A: Accountability should sit with a predefined incident decision group that includes security, legal, and executive ownership, because payment reporting is both a cyber response and a governance action. The team needs clear authority to classify the incident, preserve evidence, and decide whether reporting obligations are triggered before any payment discussion.
👉 Read our full editorial: Government cybersecurity risk: why public sector agencies stay targeted