Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

State and local cybersecurity: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: State and local governments are facing rising ransomware pressure, aging infrastructure, and shrinking budgets while carrying sensitive citizen data, according to Knowbe4’s whitepaper. Human risk management and awareness programmes are positioned as a cost-conscious way to reduce exposure when staffing and funding cannot keep pace.

NHIMG editorial — based on content published by Knowbe4: State and Local Cybersecurity: Facing New Burdens Amid Rising Threats

Questions worth separating out

Q: What fails when state and local agencies try to rely on awareness training alone?

A: Awareness training fails when it is treated as a substitute for identity and access control.

Q: Why do public sector agencies remain attractive ransomware targets?

A: They often hold sensitive personal information, run essential services, and operate mixed or legacy environments that are harder to standardise.

Q: How should security teams measure whether human risk management is actually reducing risk?

A: Use outcome metrics, not just participation data.

Practitioner guidance

  • Prioritise privileged access cleanup Review admin accounts, dormant service access, and remote administration paths before broader user hygiene initiatives.
  • Map ransomware containment to identity controls Define which accounts, systems, and segments must be isolated if ransomware appears, then test those controls against the agency’s real recovery workflow and backup dependencies.
  • Use human risk signals to target intervention Focus awareness and coaching on users who repeatedly fail phishing, MFA, or sensitive data handling checks, then measure whether the same behaviours decline over time.

What's in the full report

Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • The report’s breakdown of ransomware frequency across state and local government environments and why that matters for funding decisions.
  • The specific staffing and budget pressures agencies report when trying to maintain basic cyber hygiene and response readiness.
  • The way human risk management is positioned as a measurable mitigation model rather than a generic awareness programme.
  • The full framing for how citizen data exposure and critical infrastructure disruption change the risk equation for municipalities.

👉 Read Knowbe4's whitepaper on state and local cybersecurity burdens →

State and local cybersecurity: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Public sector cyber risk is increasingly a control-capacity problem, not just a threat-intensity problem. Underfunded agencies do not simply face more attacks. They face slower patching, weaker identity hygiene, and more difficulty sustaining routine access governance. That makes every control depend on people who are already overloaded, which increases the chance of drift. The practitioner conclusion is that resilience planning must account for operating capacity, not just threat volume.

A question worth separating out:

Q: Who is accountable when ransomware hits during a major business event?

A: Accountability should sit with the owners of privileged access, identity recovery, and business change governance, not with the SOC alone. During mergers, acquisitions, or layoffs, response depends on clear authority over access decisions and system restoration. If that authority is unclear, containment slows and the blast radius grows.

👉 Read our full editorial: State and local cybersecurity faces rising risk with fewer resources



   
ReplyQuote
Share: