https://www.americancityandcounty.com/wp-content/themes/acc_child/assets/images/logo/footer-logo.png
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcast
    • Latest videos
    • Product Guides
  • Resources & Events
    • Back
    • Resources
    • Webinars
    • White Papers
    • IWCE 2022
    • How to Contribute
    • Municipal Cost Index – Archive
    • Equipment Watch Page
    • American City & County Awards
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Privacy Statement
    • Terms of Service
American City and County
  • NEWSLETTER
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcasts
    • Latest videos
    • Product Guides
  • Resources/Events
    • Back
    • Webinars
    • White Papers/eBooks
    • IWCE 2022
    • How to Contribute
    • American City & County Awards
    • Municipal Cost Index
    • Equipment Watch Page
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Privacy Stament
    • Terms of Service
  • newsletter
  • Administration
  • Economy & Finance
  • Procurement
  • Public Safety
  • Public Works & Utilities
  • Smart Cities & Technology
  • Magazine
acc.com

Commentaries


Commentary

5 steps to protect municipal IT systems from a cyberattack

5 steps to protect municipal IT systems from a cyberattack

  • Written by Brian Vecci
  • 28th August 2019

Municipalities continue to be prime targets for cybercriminals. Unfortunately, many cities and county  governments are just one click away from a ransomware infection. If not caught quickly, the loss of encrypted files can grind everyday constituent services to a halt and erode public trust. Remediation, as municipalities such as Baltimore are finding, is often an expensive and time-consuming endeavor.

Here are five steps to consider right now to help your organization from becoming a victim.

Prioritize your files. It’s not databases that get hit with ransomware—hackers are targeting your organization’s file systems. Unfortunately, digital files are often copied, saved, shared, and moved to the point where many organizations have lost control. In a recent report, more than one in five files in the average company were open to everyone. In the event of a ransomware attack, a hacker will be able to access and encrypt every file the compromised account could open. Locking down your data to a least-privilege model, in which information is only available to employees who need it, will help keep data safer from unauthorized access by hostile insiders and external attackers.

Update and enforce your password policy. Network security once meant firewalls and spam filters, which are child’s play for most attackers today. Attackers only need to compromise one account to gain a foothold on a network. From there, they can move around and escalate their network privileges. When employees or department logins remain unchanged for months – or even years – hackers have the time they need to run brute-force attacks to crack passwords and gain access. Enforce password policies that require long passwords – shorter ones are much easier to crack and can leave a network exposed.

Remove access as employees and contractors leave. Municipalities could have thousands of employees and temporary workers leave or change roles over the course of a year. While onboarding new arrivals, it’s easy to overlook old accounts. In our recent report, we found that 40% of companies had more than 1,000 stale, but enabled, user accounts that allowed former employees, and any hackers with those login credentials, to gain access. Delete these accounts and remove a common on-ramp for hackers.

Follow a framework. The NIST Cybersecurity Framework was designed to be a repeatable, consistent and measurable approach to protecting critical infrastructure. This framework can also be used as a guide to protecting an organization’s data. Just as the framework helps IT and security personnel manage and defend systems and applications, it can help these same teams prepare for security events targeting your data. With the NIST Cybersecurity Framework as your guide, you can work to develop an approach that prioritizes the protection of your agency’s critical information.

Set your organization up for success. Ensure your organization’s standard operating procedures include regular back-ups across departments. Patches and system updates are easy ways to protect your organization, but are easily overlooked in the day-to-day rush of IT requests. Have a plan in place to respond to alerts and unusual activity in real-time, including off hours and holidays when attackers know they are less likely to be detected. Make it easy for employees to report unusual issues and suspicious emails. Bring your IT and security experts to your next leadership meeting for a candid conversation around your organization’s ability to fend off a ransomware attack or breach.

Hackers can remain undetected for weeks or months, biding their time before launching an attack. Don’t let your guard down. The time to act is now.

 

Brian Vecci is the Field CTO for Varonis, which offers data security and insider threat detection software solutions.

Tags: Smart Cities & Technology Commentaries Commentary

Most Recent


  • cybersecurity
    How state and local CIOs can prioritize security, cloud and legacy systems
    NASCIO recently released the annual State CIO Top Ten Policy and Technology Priorities for 2023—and cybersecurity and risk management, legacy modernization and cloud services rank near the top. With rising cybersecurity concerns, a growing emphasis on upgrading legacy systems, and a desire for more flexible, cloud-based technology, CIOs are focused on solutions that efficiently and […]
  • cloud services
    Cloud services: A cloudy forecast for state and local governments
    Cloud services continues to grow exponentially making it flourish into a multi-billion-dollar industry. According to a survey by Synergy Research Group, the global cloud infrastructure services market grew by 35 percent in 2020, with the top five cloud providers (Amazon Web Services, Microsoft, Google, Alibaba and IBM) capturing more than 70 percent of the market […]
  • cyber threats
    Four ways to protect resident data in the era of digital-first government
    Bad actors and cyber extortionists are continually staging attacks on public sector properties, making enterprise-grade security essential for every local government website. From small villages to counties with millions of residents, hackers increasingly target public sector websites with cyber threats like malware, ransomware, trojans and viruses. Even a relatively minor breach or infection can lead […]
  • wildfire
    Report: Technology can aid wildfire response that's 'stuck in the last century'
    With each passing season, the growing threat of wildfire and its impact on life safety, property, and the economy is underscored by dramatic fire events that ecologically alter entire regions, uproot communities and cost taxpayers billions of dollars. Last year, 68,988 wildfires burned 7.6 million acres of American land. And as of the end of […]

Leave a comment Cancel reply

-or-

Log in with your American City and County account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • North Texas alliance partners with Marketplace.city on smart government solutions
  • Harris County deploys next-generation security in 150 public buildings
  • Prioritizing rapid restore leads to stronger ransomware attack recovery
  • Today’s infrastructure needs greater than roads and bridges - It’s time to face our digital connectiveness

WHITE PAPERS


Digital Government Service Delivery – A Guide for Buyers

23rd February 2023

Modernizing government services for today’s resident expectations

24th January 2023

Preparing Your Community Now for the Next Generation of Older Adults

18th October 2022
view all

Webinars


Future-proof Your State and Local Government Finance: 5 Key Trends for 2023

6th February 2023

How To: Evaluate Digital Government Service Delivery Technologies

23rd January 2023

Using Technology to Enhance Communications

29th November 2022
view all

Podcast


Young Leaders Episode 4 – Cyril Jefferson – City Councilman, High Point, North Carolina

13th October 2020

Young Leaders Episode 3 – Shannon Hardin – City Council President, Columbus, Ohio

27th July 2020

Young Leaders Episode 2 – Christian Williams – Development Services Planner, Goodyear, Ariz.

1st July 2020
view all

GALLERIES


Gallery: America’s top 10 bicycle-friendly cities

20th March 2023

Gallery: Top 10 hardest working American cities

8th March 2023

Gallery: Top 10 least expensive American metro areas

24th February 2023
view all

Twitter


AmerCityCounty

Report: Technology is encouraging unprecedented collaboration in local government organizations dlvr.it/SlNYqx

23rd March 2023
AmerCityCounty

Metal buildings can be a lifesaver for local governments needing to expand dlvr.it/SlMCV1

23rd March 2023
AmerCityCounty

Transportation department to invest $94M into projects promoting innovation, safety dlvr.it/SlKRf7

22nd March 2023
AmerCityCounty

How state and local CIOs can prioritize security, cloud and legacy systems dlvr.it/SlK7H1

22nd March 2023
AmerCityCounty

St. Louis Communities Boost Great Energy Savings dlvr.it/SlFyV0

21st March 2023
AmerCityCounty

How Can Public Sector Best Tackle Their Unique Storage Needs? dlvr.it/SlFxXk

21st March 2023
AmerCityCounty

Taking a higher priority dlvr.it/SlFSrf

21st March 2023

Newsletters

Sign up for American City & County’s newsletters to receive regular news and information updates about local governments.

Resale Insights Dashboard

The Resale Insights Dashboard provides model-level data for the entire used equipment market to help you save time and money.

Municipal Cost Index

Updated monthly since 1978, our exclusive Municipal Cost Index shows the effects of inflation on the cost of providing municipal services

Media Kit and Advertising

Want to reach our digital audience? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • IWCE’s Urgent Communications
  • IWCE Expo

WORKING WITH US

  • About Us
  • Contact Us

FOLLOW American City and County ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.