Ready or Not – Here they Come
govciooutlook

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Gov CIO Outlook Advisory Board.

City Of Strongsville

Ready or Not – Here they Come

David E. Sems

Cybersecurity Resilience Leader

David E. Sems, is the Director of Communications and Technology for the City of Strongsville, Ohio and a nationally recognized expert in digital forensics with over 20 years of experience investigating digital crimes and advising law enforcement and public sector organizations.

Cybersecurity incidents continue to strike federal, state and local government agencies and how an agency responds in the first hours can determine whether the damage is contained or compounded. Public sector IT professionals need to know what to do first to protect their agency, their constituents and the organization itself. This article addresses two of the most damaging threats facing government today: ransomware and business email compromise (BEC), both of which put vast amounts of constituent data—supporting 911 dispatches, benefits payments, courts and utilities—at risk.

Government: a targeted sector

Ransomware operators know a government agency cannot tell constituents to come back next month. Suffolk County, New York, returned to pen and paper for 911 calls after its computerized dispatch system failed. In Dallas, the “Royal” hacking group degraded police, court and 311 systems for weeks. In the 2023 MOVEit campaign, motor vehicle agencies in Louisiana and Oregon were hit through a single compromised third-party file transfer tool.

The golden hours

The first 24 to 48 hours after an incident are golden. Evidence that can be lost will be lost in that window and the scope of the problem will likely grow if containment alone — without a full response — is the only action taken.

Federal civilian agencies must report major incidents to CISA on an accelerated timeline under FISMA. Under CIRCIA, covered critical infrastructure entities, including utilities and government service providers, must report significant incidents within 72 hours and ransom payments within 24 hours. State and local governments also face state breach-notification statutes, CIS Critical Security Controls, IRS Publication 1075 for incidents involving federal tax information and the FBI's CJIS Security Policy for law-enforcement data — often creating overlapping compliance obligations.

Four universal first steps

1. Contact your legal team in-house, agency counsel, or outside cyber counsel, as early as possible to preserve privilege and clarify notification obligations.

2. Contact your cyber insurance carrier or government risk pool. Most policies require notice within hours and have pre-approved response vendors ready to assist.

3. Engage a professional incident response team. State, local, tribal and territorial governments can request no-charge assistance from CISA and MS-ISAC.

4. Isolate, don't eliminate. Disconnect affected systems from the network rather than powering them off, since RAM holds system logs longer than a shutdown would preserve them.

Ransomware with data theft

Ransomware has evolved beyond simple encryption; attackers now exfiltrate data and demand payment to prevent its release. A common misperception is that paying resolves the problem—stolen data may already be in the hands of multiple groups, each capable of issuing its own demand. Disconnecting (rather than shutting down) systems preserves the evidence needed for proper forensic work, root-cause analysis and full recovery. An incident assessment team, technical staff plus legal counsel, should determine the scope of the breach and which notifications (state, federal, IRS Pub. 1075, CJIS, etc.) are required.

Business email compromise: a multibillion-dollar threat

BEC is now used to deliver ransomware and touches an estimated 80% of the current attack surface across government and its partners. According to the FBI's IC3 2025 Internet Crime Report, BEC caused $3.05 billion in losses during 2025, down from $2.77 billion in 2024, but the risk to government remains high wherever high-value vendor payments move through email approval chains. One common variant is payment diversion, where a criminal poses as a government contractor, changes the bank account on file and withdraws funds before the fraud is discovered.

If funds have been transferred, contact the FBI immediately—its Recovery Asset Team (1-855-292-3937, RAT@fbi.gov) can attempt to freeze and recover the transfer—and report the incident to IC3. Preserve mailbox audit logs and authentication logs, avoid deleting anything and reset compromised accounts. Enable mailbox audit logging and sender authentication (SPF, DKIM, and DMARC) in advance, with enough log storage to support a complete investigation.

Understand before you recover

Restoring systems before the root cause is fully investigated risks leaving the same vulnerabilities in place. A hasty restore often fails to remove hidden accounts, alternate access methods and other persistence mechanisms and can destroy the evidence needed to prevent future incidents.

Are you ready?

Public sector IT teams should inventory key systems — constituent data repositories, benefits and eligibility systems, computer-aided dispatch, court and land records, financial systems, utilities and facilities — and test controls for effectiveness, not just presence. That means verifying multifactor authentication for all privileged access, encryption, segmentation and email authentication. A strong response plan names decision-makers, documents reporting clocks and is tested annually. Mapping all platforms against frameworks such as the CIS Critical Security Controls or NIST CSF helps identify where risk and readiness efforts should be focused.

Conclusion

Threats to government will continue to evolve and public sector IT leaders must build the resiliency needed to deliver services and protect constituent information. Testing, monitoring and honestly assessing risk across all IT platforms is the best preparation for the incident that will, eventually, occur.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief