Most Local Governments Do Not Have a Cybersecurity Problem First. They Have an Ownership Problem.

By Michelle Johnson

Why Cybersecurity Ownership Matters in Local Government

Most local governments do not intentionally ignore cybersecurity.

In many cases, leadership teams believe they are handling it reasonably well. Security software is in place. Cyber insurance has been renewed. There is outside IT support. Policies exist. Employees complete awareness training.

From the surface, the environment appears stable.  Cybersecurity ownership is what determines whether those safeguards are actually reviewed, assigned, maintained, and understood across departments.

Then something happens that forces people to look closer.

A payroll request gets approved too quickly. A former employee still has access to systems months after leaving. A vendor account nobody remembered is still active. Sensitive files turn out to be accessible far beyond the people who actually need them.

When those situations are investigated, the same pattern tends to appear underneath almost all of them.

Responsibility became fragmented over time.

Not because employees were careless or leadership ignored the issue entirely. Most of the time, it happened gradually as systems expanded, departments adopted new workflows, and operational pressure pushed decisions forward faster than oversight structures evolved around them.

That is where many municipal technology risks actually begin.

Most Technology Problems Start as Operational Problems

Cybersecurity discussions often move quickly toward tools and technical controls. Firewalls, monitoring systems, filtering platforms, endpoint protection, multifactor authentication.

Those controls matter. They are necessary.

But many public agencies are not struggling because they failed to buy technology. The deeper issue is usually operational ownership.

As departments grow more dependent on Microsoft 365, cloud platforms, vendors, shared workflows, and remote collaboration, responsibilities begin spreading across multiple people and departments. Over time, processes that once felt simple become difficult to fully track.

How Fragmented Responsibility Creates Cybersecurity Risk

A vendor is approved during a busy period and nobody formally reviews access again afterward.

Departments begin sharing files differently because no consistent governance standard was established.

Offboarding depends on manual communication between supervisors, HR, and IT.

A Teams site created for a project remains active years after the work itself ended.

None of these situations initially feel like cybersecurity problems. They feel administrative. Routine. Operational.

That is part of what makes them difficult to recognize early.

The risk usually builds quietly through inconsistency. These quiet technology oversights rarely announce themselves. They accumulate until a disruption forces accountability into view.

What This Looks Like Inside Real Municipal Operations

Inside local government, operational workflows rarely stay contained within a single department.

Finance depends on Human Resources. Administration depends on outside vendors. Public safety relies on shared systems and coordinated communication. Board packets, resident records, legal discussions, permitting systems, and payroll processes all move across interconnected environments.

As those systems expand, accountability can slowly become less visible.

A finance director may assume IT already reviewed permissions. IT may assume department leadership understands who still requires access. Human Resources believes account removals are already handled elsewhere. Vendors maintain access because nobody formally owns periodic review responsibilities.

Everyone involved is busy. Everyone is acting reasonably based on their own responsibilities.

The problem is that operational gaps often form between departments, not inside them.

That distinction matters.

Many municipal cybersecurity incidents are not caused by one catastrophic failure. They are the result of multiple small assumptions stacking together over time until something eventually exposes the weakness underneath the process.

Ownership gaps are easier to address when leadership can see where responsibilities, dependencies, access, vendor oversight, and recovery expectations are unclear. RWK’s Municipal Technology Risk Assessment gives municipal leaders a practical way to start that review before an incident, audit, or insurance question forces it.

Early Warning Signs of Cybersecurity Ownership Problems in Local Government

Most agencies expect cybersecurity problems to appear as obvious technical failures.

In reality, the earlier warning signs often look operational long before they look technical.

Things like:

  • inconsistent approval processes between departments
  • uncertainty around who reviews vendor access
  • shared accounts that remain active because removing them feels disruptive
  • cybersecurity discussions that only happen during renewals or incidents
  • undocumented recovery responsibilities
  • department leaders assuming permissions were already reviewed elsewhere
  • software decisions made without continuity planning discussions
  • former employee offboarding handled differently depending on the department

Individually, these situations may not feel urgent.

Collectively, they create environments where accountability becomes difficult to trace clearly during incidents, audits, outages, legal requests, or insurance reviews. That difficulty becomes most visible when someone formally asks for proof, and proving ownership when accountability is questioned turns out to be harder than anyone anticipated.

That is when leadership teams often discover how much responsibility had quietly become informal.

A Simple Cybersecurity Ownership Model for Local Government

Cybersecurity ownership does not mean one person is responsible for every technical detail.

It means leadership has clearly assigned who is responsible for decisions, documentation, follow-through, and proof.

For most municipalities, ownership should be divided across several roles.

Executive ownership

The Village Manager, Township Administrator, City Manager, or senior administrator owns the overall risk conversation. This person does not need to configure systems, but they do need to make sure cybersecurity risk is visible, funded, reviewed, and connected to municipal operations.

Technical ownership

Internal IT staff or the outside IT provider owns technical execution. That includes implementing controls, maintaining systems, applying security standards, supporting recovery, and escalating issues when risk exceeds a routine support matter.

Department ownership

Department leaders own the way technology affects their work. Finance, police, fire, public works, administration, community development, and clerks’ offices all depend on systems, data, vendors, and workflows. Each department should know which processes are critical, who uses them, and what happens if they are unavailable.

Access ownership

Someone must own user access from start to finish. That includes onboarding, role changes, vendor access, administrative rights, and offboarding. Without clear access ownership, permissions tend to accumulate quietly until an incident, audit, or insurance review exposes them.

Vendor ownership

Every critical vendor relationship needs a municipal owner. That person should know what the vendor supports, who can contact support, what access the vendor has, what happens if the system is unavailable, and whether recovery expectations are documented.

Recovery ownership

Someone must own recovery expectations before systems fail. That means knowing which services need to come back first, whether restores have been tested, who makes decisions during downtime, and how departments will continue essential work during disruption.

Proof ownership

A defensible cybersecurity program depends on evidence. Someone should be responsible for maintaining proof of MFA enforcement, backup testing, access reviews, incident response planning, vendor oversight, and security decisions. Without proof, leadership may know work was done but still struggle to show it.

The goal is not to create more bureaucracy.

The goal is to remove uncertainty before pressure arrives.

When ownership is clear, cybersecurity becomes easier to discuss, easier to fund, easier to test, and easier to defend.

Why Local Governments Misdiagnose Cybersecurity as a Training Problem

A large portion of cybersecurity guidance still focuses primarily on employee awareness.

Employees clicked something.
Someone responded to a suspicious email.
A staff member made a mistake.

Those situations absolutely happen. But many operational failures begin long before an employee ever clicks on anything malicious.

They begin when ownership is unclear.

When responsibilities are assumed instead of documented. When review processes become inconsistent. When systems evolve faster than the structure surrounding them.

Over time, operational accountability weakens quietly in the background while day-to-day work continues normally.

At that point, what appeared to be a technical event becomes a leadership and accountability issue.

That aligns with the NIST Cybersecurity Framework 2.0, which treats governance as part of cybersecurity risk management, not a separate administrative exercise.

Why Treating Cybersecurity as a Separate Technical Issue No Longer Works

In many environments, cybersecurity is still treated as a separate technical conversation instead of part of operational governance.

That separation no longer works well.

Technology now directly affects:

  • continuity
  • financial operations
  • resident services
  • legal exposure
  • records management
  • public trust
  • departmental coordination

When accountability around those systems becomes unclear, risk expands with it.

What Strong Oversight Actually Looks Like

Strong cybersecurity ownership does not mean one person carries all the risk. It means leadership can clearly identify who owns access reviews, vendor accountability, recovery coordination, escalation decisions, system oversight, and policy enforcement.

Departments understand who approves access requests. Vendor relationships are reviewed on a regular schedule instead of only during renewals or emergencies. Offboarding follows a documented process regardless of staffing pressure or department structure.

Technology decisions are connected to operational continuity discussions instead of handled separately from them.

Clear Ownership Reduces the Number of Blind Spots

That structure does not eliminate risk entirely. No environment works that way.

What it does is reduce the number of blind spots that quietly accumulate over time inside growing municipal operations.

More importantly, it makes accountability visible before pressure forces leadership to untangle responsibilities publicly during an incident.

The Agencies Managing Technology Risk Best Usually Share One Trait

They stopped treating cybersecurity as a stand-alone technical issue.

Instead, they began treating it as operational accountability.

That shift changes how decisions are made. It changes how departments coordinate. It changes how leadership approaches oversight and continuity planning.

Most municipal technology failures do not begin with sophisticated attacks.

They begin with a responsibility nobody formally owned.

A process that evolved informally over time.

A system everyone assumed another department understood.

The agencies handling technology risk best are rarely the ones making the most noise about cybersecurity. In many cases, they are simply the ones that made accountability visible before a disruption forced the issue.

 

 

 

Questions Leaders Are Asking

Why do local governments have cybersecurity problems even when they have security software and IT support in place?

Many public agencies are not struggling because they failed to buy technology. The deeper issue is usually operational ownership. As departments grow more dependent on Microsoft 365, cloud platforms, vendors, shared workflows, and remote collaboration, responsibilities begin spreading across multiple people and departments. Over time, processes that once felt simple become difficult to fully track.

What are the early warning signs that a local government has a cybersecurity ownership problem?

The earlier warning signs often look operational long before they look technical. Things like: inconsistent approval processes between departments, uncertainty around who reviews vendor access, shared accounts that remain active because removing them feels disruptive, cybersecurity discussions that only happen during renewals or incidents, undocumented recovery responsibilities, department leaders assuming permissions were already reviewed elsewhere, software decisions made without continuity planning discussions, and former employee offboarding handled differently depending on the department.

Why doesn't employee cybersecurity awareness training solve the problem for local governments?

Many operational failures begin long before an employee ever clicks on anything malicious. They begin when ownership is unclear. When responsibilities are assumed instead of documented. When review processes become inconsistent. When systems evolve faster than the structure surrounding them. Over time, operational accountability weakens quietly in the background while day-to-day work continues normally.

What ownership responsibilities should municipal leaders formally assign to reduce cybersecurity risk?

Leadership teams know who owns: access reviews, vendor accountability, recovery coordination, escalation decisions, system oversight, and policy enforcement. That structure does not eliminate risk entirely. What it does is reduce the number of blind spots that quietly accumulate over time inside growing municipal operations.

What do local governments that manage technology risk well do differently?

They stopped treating cybersecurity as a stand-alone technical issue. Instead, they began treating it as operational accountability. That shift changes how decisions are made. It changes how departments coordinate. It changes how leadership approaches oversight and continuity planning. The agencies handling technology risk best are rarely the ones making the most noise about cybersecurity. In many cases, they are simply the ones that made accountability visible before a disruption forced the issue.