
The government has actively taken initiatives to combat continuously evolving cybersecurity threats. By looking at cybersecurity from various angles, agencies can reinforce their cyber defenses, allowing them to implement better plans and allocate resources more efficiently.
With growing cyber risks, including phishing attacks, data breaches, ransomware attacks, and data theft, cybersecurity awareness is being more widely recognized by the public sector.
Here are some of the latest trends concerning public sector cybersecurity:
1. Lawmakers Are Finally Paying Attention
Fortunately, legislators recognize the danger cyber threats pose to public funds and have started to put their knowledge into practice. Lawmakers not only created positions for information security officers but also allocated funding for them, prioritizing cyber security initiatives at the state level.
However, local governments are slightly behind when it comes to legislative support. For instance, most states still lack cyber threat information-sharing, cyber awareness training, or cybersecurity legislative review programs.
2. Local Governments Lagging
State and local governments are moving toward cybersecurity at different speeds. While state agencies are increasingly bolstering their security measures and capabilities, local governments are lagging.
For instance, recent reports reveal a significant disparity between the number of state agencies that have achieved the highest level of security awareness training (67%) and those of local governments (8%). The same discrepancy applies to incident response, risk and vulnerability assessments, threat monitoring, and identity and access management.
3. Increasing Budgets
The latest reports show that many states have taken steps to better manage cybersecurity risks by allocating a significant portion of their IT budgets to cybersecurity, with some devoting as much as 10%.
Moreover, most of these states have officially established a set amount of money to be used specifically for cybersecurity efforts, either by law, executive order or through other decision-makers.
4. Staffing Challenges
Despite the increase in cybersecurity budgets, cybersecurity staffing remains challenging for the government. In the past two years, it has taken at least three months for agencies to fill mid-level roles in the cybersecurity department and six months or longer for director-level positions.
Many state-level offices have started outsourcing to fill these talent gaps, with the number of third-party contractor hires spiking from 51% in 2020 to 78% in 2022.
5. Ransomware Resilience (or Lack of It)
Despite being a cybersecurity staple for the last twenty years, ransomware is still increasingly prevalent. Cybercriminals are repeatedly developing new types of malware and getting better at getting past standard threat detection systems to gain unauthorized access to information systems.
Aside from the apparent financial gain hackers get from ransomware, the continued reliance of government agencies on outdated technologies and the sudden switch to remote work are substantial factors in the increasing volume of attacks.
With several governments lacking the necessary human resources and infrastructure to combat ransomware, it's no wonder bad actors are looking to attack their information systems to gain access to high-profile information.
A Final Word on Public Sector Cybersecurity
The public sector continues to struggle with cybersecurity due to the talent gap and legacy infrastructure inadequate at combating new threats. Moreover, local governments are still quite behind in their cybersecurity strategy and execution, making them more vulnerable to advanced social engineering attacks.
In this accelerated digital transformation age, cyber threats continuously evolve and find innovative ways to harm and break into information systems. To improve cybersecurity, governments must constantly update their security teams and systems with the latest threat information.
