THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Gov CIO Outlook Advisory Board.


The Need for Local Governments to Build Cybersecurity Awareness
Josh Erquiaga
Local governments need to consider both their internal organization and the communities they serve when building cybersecurity awareness. For internal staff, training should be short, recurring, relevant to their work and supported by internal policies, procedures and tools. Information Technology departments should build an environment where people feel comfortable reporting mistakes quickly, so potential incidents can be stopped before they become an issue.
Building cybersecurity awareness in the communities we serve is equally important. With the growth of online services over the past decade, and especially since the COVID pandemic, our communities have become increasingly dependent on digital interactions. Securing those interactions helps our communities and supports our organizations as we work to provide more accessible services to a wider range of our community.
The Role of Community Collaboration in Public-Sector Cybersecurity
Public-sector technology cannot succeed in isolation. Collaboration with residents, businesses, educational institutions, other agencies, professional associations and private-sector partners gives local governments access to expertise and resources they could not develop alone, especially as resources become more constrained for local governments amid economic uncertainty.
Our broadband work is a good example. Community difficulty accessing electronic resources led the City to examine broadband accessibility, engage consultants, and ultimately pursue a public-private partnership. That work also connected infrastructure with affordability, digital skills, education, economic opportunity and civic participation.
Local governments can build digital trust by listening to their communities, communicating transparently, protecting information responsibly and delivering tangible improvements. Information technology departments play a critical role in identifying tools, processes and procedures that support those goals across the departments they serve.
Cybersecurity Challenges That Require the Greatest Attention
The greatest challenge is maintaining critical services while threats, technology, regulatory requirements and employee workloads continue to change. Local governments manage financial information, public-safety communications, operational technology for utilities, resident data, emergency systems and aging infrastructure. Identity and access management, third-party risk, system resilience, incident preparedness, backups, employee awareness and sustainable staffing all need to be considered as information technology leaders evaluate how they will provide and improve services.
“Local governments can build digital trust by listening to their communities, communicating transparently, protecting information responsibly and delivering tangible improvements.”
Capacity is particularly important. When support demands pull skilled engineers away from infrastructure maintenance and modernization, security risks can slip through the cracks. Information technology leadership requires strong governance and a meaningful role in organizational decision-making, budgeting, continuity planning and service design to ensure these critical activities receive appropriate resources.
Strong Cybersecurity Measures Counterbalanced with Accessible Public Services
Security and accessibility are not mutually exclusive. Well-designed security should make services more dependable without creating unnecessary barriers.
The goal with security should be appropriate protection with the least necessary friction. That means using risk-based controls, involving users early, testing processes from their perspective, providing accessible alternatives, and clearly explaining why a control exists. Involving the community in developing public-facing services can help uncover blind spots you might otherwise overlook.
For example, we are currently updating our public meeting broadcasts and website, and we have partnered with our Office of Diversity, Equity, and Inclusion to identify community groups with accessibility challenges to help us test those changes, including updates designed to enhance security.
Our technology portfolio includes protective infrastructure alongside public-facing systems, wireless connectivity, communications platforms, meeting technology, and departmental applications. We measure success by whether technology securely enables employees to serve residents and carry out community priorities.
Building an IT Career in Public-Sector Technology and Cybersecurity?
I would encourage people to develop strong technical fundamentals, but understand that those fundamentals only provide a solid foundation for your career. Learning how budgeting, procurement, policy, accessibility, emergency operations, communications and individual departments work allows you to see the bigger picture of an organization and puts you in a position to propose innovative ways to meet the needs of the organization and the community it serves. The most effective public-sector technologists can translate between technical risks, operational needs and community outcomes.
Be curious, build relationships, participate in professional organizations and look for assignments outside your comfort zone. Municipal information technology offers opportunities to work in networking, cybersecurity, enterprise applications, public safety, telecommunications, broadband, governance and continuity planning—sometimes in the same week!
Most importantly, maintain a service mindset. For me, public service means using my abilities to improve the community where I live and work.