⚠ Experiencing a security incident right now? Urgent contact — (813) 321-2006 · Send urgent message
NaviSec Blog

State and Local Government Cyber Security

2023-02-27 · NaviSec Team
State and Local Government Cyber Security

State and Local Government Cyber Security is becoming increasingly critical as threat actors frequently target these organizations. A cybersecurity research article notes that 44 percent of ransomware attacks worldwide targeted local government bodies like municipalities. Security concerns extend beyond federal agencies to various state and local government entities.

The Center for Internet Security research found that many state and local government agencies lack basic security measures, including multi-factor authentication and encryption. This makes data protection preparedness essential for public sector organizations.

Why are bad actors targeting state and local government agencies frequently?

  1. Valuable Data – These agencies collect sensitive information (social security numbers, tax records, personal data) that criminals exploit for identity theft and financial fraud.
  2. Limited Resources – Budget constraints prevent investment in advanced security measures or expert hiring, increasing vulnerability.
  3. Critical Infrastructure – Responsibility for internet-connected systems (transportation, water treatment, power grids) creates widespread disruption risks.
  4. Political Motivations – Some actors target these agencies to disrupt elections or steal data for political leverage.
  5. Easy Targets – Agencies may appear vulnerable due to less sophisticated security measures and delayed breach detection capabilities.

What are some major State and Local Government Cyber Security compliance mandates?

NIST Cybersecurity Framework – The National Institute of Standards and Technology provides guidelines for risk management, threat identification, and incident response.

Federal Information Security Modernization Act (FISMA) – Mandates proper security controls for protecting sensitive information, including access controls, network security, and incident response.

Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure – Requires comprehensive cybersecurity programs for networks and critical infrastructure protection.

FEDRAMP – The Federal Risk and Authorization Management Program mandates that cloud service providers meet security and compliance requirements. State and local governments can use FEDRAMP-compliant cloud providers.

Cybersecurity Information Sharing Act (CISA) – Demands that state and local governments share cybersecurity information with the Department of Homeland Security and other government agencies.

State Data Breach Notification Laws – Various states require organizations, including government entities, to notify individuals of data breaches. Notable state laws include:

These laws require state government agencies to implement robust cybersecurity measures.

Why is Penetration Testing crucial for State and Local Government authorities?

The Center for Internet Security research revealed that state and local government cybersecurity scored significantly lower than private sector organizations. On average, government entities scored 70.7 out of 100 on CIS Controls, compared to 83.7 for private organizations. Public sector bodies must strengthen frameworks using updated techniques.

Penetration testing remains essential for comprehensive cybersecurity programs:

Identifies key vulnerabilities – Testing helps identify exploitable network and system weaknesses, prioritizing investment and safeguard implementation.

Evaluates security controls – Testing assesses the effectiveness of security controls and policies, reviewing access controls, network segmentation, patch management, and incident response procedures.

Mitigates risks – Identifying vulnerabilities and evaluating controls prevents cyber attacks, saving time, money, and reputational damage.

Ensures regulatory compliance – Penetration testing compliance with frameworks like FISMA or PCI DSS is necessary for federal grants and maintaining public trust.

Which government funds are available for penetration testing?

Cybersecurity and Infrastructure Security Agency (CISA) funding – Provides financial assistance and technical support, including pen-testing and security assessments.

Department of Homeland Security (DHS) Grant Programs – Offers grants for pen-testing and security assessments.

National Science Foundation (NSF) Cybersecurity Grant Programs – Supports cybersecurity research and development, including penetration testing.

Federal Emergency Management Agency (FEMA) Grant Programs – Provides grants for preparedness and resilience against cyber threats, including pen-testing funding.

What areas of concern should state and local governments keep in mind while conducting penetration tests?

Regular penetration tests form fundamental defense measures. Agencies should address these aspects:

  • Obtain appropriate authorization – Follow proper chains of command and obtain permissions from CIOs, legal departments, or other officials.
  • Document and Report Findings – Create detailed reports describing vulnerabilities, associated risks, and remediation recommendations.
  • Address the Vulnerabilities – Implement patches, updates, configure security controls, and deploy additional security measures.
  • Hire a Qualified Penetration Testing provider – Engage firms with government experience and necessary certifications to identify significant weaknesses and provide accurate results.

Find actionable results and upgrade the cybersecurity posture at the local and state government level with NaviSec's penetration testing services. NaviSec assists government agencies through customized penetration testing, government regulations expertise, actionable recommendations, and ongoing support. Partnering with NaviSec enables proactive protection of sensitive data and systems.

Ready to strengthen your agency's cybersecurity posture?

Contact NaviSec today to learn how penetration testing can help your organization meet its compliance mandates.

Security is a journey, not a destination

Find out where you stand — free.

Take the free online risk assessment, or start with a confidential conversation about your risk, threats, and current cybersecurity posture.

Take the Free Risk Assessment
// online · confidential · no obligation