OPINION

A government agency I work with lost nearly a million dollars and never heard an alarm. No ransom note, no locked-up servers. Attackers slipped into a handful of staff email accounts, watched how the agency moved money for a couple of months, and then quietly rerouted a wire meant for an affordable-housing project. Nobody caught it until the money was already gone.

This wasn’t a federal department or a Fortune 500 company. It was a local housing authority, the kind of place that helps families make rent. And here’s the part I keep coming back to: The breach isn’t how the story ends. It’s what finally pushed the agency to stand up a real security program, and today it is one of the better-defended shops I work with. That turnaround is the whole point. The gap is real, but it closes faster than most people expect once someone decides to close it.

I’ve worked across 82 engagements in 46 states now, and I’ve watched that same turnaround happen too many times to call it luck. Local governments hold the same data the federal government does (i.e., Social Security numbers, medical records, criminal-justice files, payroll), usually with a fraction of the people to protect it. More than 80% of state and local organizations run security with fewer than five dedicated staff. Agencies like that aren’t careless; they’re outnumbered. Resourcing problems, though, can be designed around, and here’s what I’ve actually seen work.

Related:CISOs Break Their Silence in ‘Declassified’ Docuseries

Start With Basic Questions

Start with the exposure, not the tool. Every engagement I take begins with the boring questions: What are you running, what data are you sitting on, where are you actually exposed, before anyone brings up a product. A county with one administrator covering 14 departments does not need the same plan as a school district, and the hour spent seeing that difference is what decides whether any of it is still running a year later.

Then meet the agency where its budget actually is. Most enterprise security is priced and bundled for organizations with seven-figure budgets. A county working with $200,000 for all of IT can’t buy that way. It can buy a scoped risk assessment, an MFA rollout, or an incident-response retainer on its own terms. Breaking the work into pieces an agency can fund one cycle at a time is often the whole difference between getting help and going without. It’s slower, and slow is exactly what survives procurement, staff turnover, and the next election.

Why Compliance Matters

Put the compliance conversation up front. Housing authorities live under HUD rules, counties hold CJIS-regulated records, and districts hold student data. Leading with CJIS and SOC 2 in the first meeting instead of surfacing them after the contract’s signed is what lets a small agency’s leadership say yes without feeling like they’re gambling.

Related:Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

And don’t disappear when the contract closes. The agencies still standing years later are almost always the ones where somebody stayed in the room checking in, retraining the new hire, adjusting as the threats move. When your whole IT department is one overworked person, that relationship matters more than any tool on the invoice.

The last one is free. Those of us working across dozens of agencies see the same crews run the same playbook from one county to the next. Write up the anonymized findings, take them to the regional government-IT associations, and what you learned on one job becomes protection for the next agency down the road. More of us should be doing it.

None of this waits on Congress or a new grant. It’s a decision to treat a smaller budget as a real customer and to build the work to fit it.





Source link

#

Comments are closed