Improving State and Local Government Cybersecurity State and local governments face rising cybersecurity risks that strain budgets, disrupt services, and erode public trust. Governments need targeted investments in modern infrastructure, continuous monitoring, and stronger third-party risk management to protect critical services. KEY TAKEAWAYS Key Takeaways Contents State and Local Governments Face Increased Cybersecurity Risk. 4 State and Local Government Cybersecurity is Fragmented, Underfunded, and Unprepared. 9 Introduction Cyberattacks in the United States have surged in frequency and impact since the start of this decade, with the country facing several hundred on any given day.[1] The proliferation of digital systems and interconnected infrastructure has widened the attack surface, while adversaries have become more organized and technologically advanced, increasing the sophistication of their methods. These trends amplify both the scale and severity of incidents, making recovery costlier and disruptions more prolonged. These attacks strike federal, state, and local governments nationwide regardless of size or location, putting personal data, critical infrastructure, essential government services, and business operations at risk. State and local governments now stand on the front lines of a rapidly changing cyberspace, facing a range of cyberthreats, from opportunistic attackers exploiting basic security weaknesses to organized groups using advanced techniques. Underfunded IT departments, aging critical infrastructure sectors, and a chronic shortage of cybersecurity professionals leave many state and local governments exposed. At the same time, cybercriminals, organized groups, and nation-state adversaries such as Russia, China, and Iran are deploying increasingly sophisticated tools to exploit these weaknesses. Recent incidents demonstrate the scope of these threats, including the 2023 ransomware attack on Dallas, Texas, which disrupted police, fire, and court systems and exposed 30,000 residents’ data; the attack on Oakland, California, that compromised 600 gigabytes of the city’s employee data; the 2024 Salt Typhoon infiltration of U.S. telecommunications networks such as Verizon and