A recent string of cyber incidents has forced local governments in multiple states to shut down networks, interrupt public-facing services, and shift emergency operations to backup processes. For MSPs supporting municipalities, this is a reminder that ransomware recovery is not just an IT exercise — it can become a public-safety obligation.
The incidents are not publicly attributed as one coordinated campaign. But they share a practical lesson: a small municipality with limited internal security resources can still be a high-impact target, especially when its network supports 911 routing, police and fire dispatch, public records, utility billing, and other essential services.
Municipal disruption is a public-safety issue
In early August, Suisun City, California, shut down its entire IT network after malicious software compromised city systems. The city said the incident affected critical public-safety operations, including 911 routing, police and fire dispatch, records, and city services. Emergency calls continued to be handled through Solano County’s dispatch center while the city activated emergency procedures and recovery operations.
Other municipalities and counties reported similar disruption:
Coweta, Oklahoma, said a ransomware attack affected its computers, files, and digital services. The town relied on off-site backups and unaffected external systems while recovery work continued.
Mitchell, South Dakota, shut down government networks following a cyberattack, disrupting normal government operations even though emergency services remained available.
Coryell County, Texas, and Washburn County, Wisconsin, also disclosed cyberattacks. Washburn County reported network and phone-service disruption while responders investigated the incident.
The public record does not establish that all of these events were caused by the same threat actor or malware family. That distinction matters. MSPs should avoid presenting unrelated incidents as a single confirmed campaign.
But the business risk is consistent across every event: when municipal networks go down, leaders must preserve public safety, maintain critical services, communicate with residents, recover systems, investigate the intrusion, and make high-stakes decisions under intense pressure.
Why MSPs are in the blast radius
Many small and midsize municipalities rely on MSPs as their practical IT department. That often means the provider manages identity, endpoints, backups, Microsoft 365, network infrastructure, remote access, servers, security tooling, and incident response coordination.
A successful attack against one municipal client is serious. A compromise of an MSP’s administrative tools, remote-management platform, shared credentials, or support environment can be much worse.
Threat actors understand this model. They look for trusted access paths that provide broad reach, including:
Remote monitoring and management platforms
Shared or reused administrative credentials
VPN and RDP services exposed to the internet
Weakly protected Microsoft 365 or identity-provider accounts
Flat networks that allow movement from administrative systems to operational systems
Backup platforms accessible with the same privileged accounts used for production administration
For a municipality, the consequences go beyond encrypted file shares. A disruption can affect court systems, permitting, utility billing, public records, communications, dispatch operations, and residents’ ability to reach local government.
The Suisun City incident shows why resilience planning matters. While city systems were impacted, emergency calls were rerouted through the county dispatch center and emergency response continued. That outcome depended on alternate operating procedures — not simply on having an endpoint protection agent installed.
The controls that matter most
MSPs supporting local government should treat this moment as an opportunity to verify (not merely assume) that each client can withstand a disruptive cyber event.
Test recovery, not just backups
A successful backup job is not proof of recoverability.
For every municipal client, confirm that backups are:
Isolated from normal domain and administrative credentials
Immutable, offline, or otherwise protected from deletion or encryption
Covering critical servers, line-of-business applications, configurations, and identity systems
Monitored for failed jobs, unusual deletion activity, and retention changes
Tested through documented restore exercises
The recovery plan should identify restoration priorities. A town may be able to defer restoration of a public website or internal file share, but it may need to restore dispatch support, emergency communications, public-safety records, utility systems, or finance operations first.
Every client should be able to answer three questions before an incident:
What must be restored first to protect life, safety, and essential operations?
How long will recovery actually take?
Who has the authority to make recovery and public-communications decisions?
Separate critical systems from general administration
Segmentation is one of the strongest ways to limit the impact of a compromised user account or workstation.
Administrative networks should not have unrestricted pathways into public-safety, dispatch, operational technology, or other critical environments. Municipal clients should work with their MSP, public-safety vendors, and internal leadership to document:
Which systems are mission-critical
Who needs access to them
Which remote-access methods are allowed
How those systems are monitored
What alternative procedures exist when systems are unavailable
Segmentation is not a one-time firewall project. It requires maintaining access rules, reviewing exceptions, validating vendor connectivity, and ensuring that recovery systems are not reachable from compromised production networks.
Harden every remote-access path
Remote access remains one of the most valuable entry points for ransomware operators. Review VPN, RDP, remote-support tools, cloud administration portals, and vendor connections across every municipal client.
At a minimum:
Require phishing-resistant MFA wherever possible, especially for administrator and remote-access accounts.
Disable unused accounts immediately and review privileged access on a recurring schedule.
Restrict remote access by role, device posture, network location, and time where practical.
Remove direct RDP exposure from the internet.
Review authentication logs for impossible travel, repeated failures, unfamiliar devices, new MFA registrations, and suspicious administrator activity.
Require separate, named accounts for privileged administration rather than shared credentials.
This work is not glamorous, but it reduces the number of ways an attacker can turn one stolen password into a municipal outage.
Validate EDR and MDR coverage
EDR and MDR are valuable only when coverage is complete, healthy, and actively monitored.
MSPs should verify that all supported endpoints and servers are enrolled, reporting, properly licensed, and assigned to the correct tenant or policy group. Pay particular attention to systems that are often missed:
Legacy servers
Virtual machines
Dispatch-adjacent systems where vendor compatibility limits agents
Backup infrastructure
Administrator workstations
Network-management systems
Cloud workloads
For systems where standard EDR cannot be installed, document the compensating controls: network isolation, application allowlisting, enhanced logging, limited administrative access, and vendor-approved monitoring.
Turn preparation into a client service
The best time to discuss incident response is before a city council meeting, emergency declaration, or media inquiry forces the conversation.
MSPs can turn this risk into a structured municipal cyber-resilience review:
| Review area | Question to answer |
|---|---|
| Recovery | Can the client restore essential services from isolated backups within an agreed recovery objective? |
| Public safety | Are dispatch, emergency communications, and related systems separated from general administration? |
| Identity | Are privileged accounts protected with MFA, least privilege, and regular access reviews? |
| Remote access | Are VPN, RDP, vendor connections, and remote-support tools inventoried and restricted? |
| Detection | Are EDR/MDR tools deployed, monitored, and validated on every eligible system? |
| Response | Does the client have named decision-makers, legal and insurance contacts, communication procedures, and a tested incident-response plan? |
A tabletop exercise can be especially effective. Present a realistic scenario: the municipal network is unavailable at 7:30 a.m.; email is down; residents are calling; public-safety systems are operating in a backup mode; and a ransomware note claims data was stolen.
Then work through the decisions. Who calls the incident-response provider? Who contacts law enforcement and cyber insurance? Who determines whether systems can be brought back online? Who communicates with employees, residents, elected officials, and the press?
Those answers should not be improvised during an active incident.
The takeaway for MSPs
Small towns are not low-value targets. They are often organizations with broad community responsibility, sensitive data, essential services, limited IT staff, and little tolerance for downtime.
The recent incidents in California, Oklahoma, South Dakota, Texas, and Wisconsin demonstrate how quickly a local-government cyber event can become an operational emergency. In Suisun City, critical public-safety operations were affected and calls had to be routed through a county dispatch center; in Coweta, ransomware affected the town’s computers, files, and digital services.
MSPs supporting municipalities should act now: validate backups through restore testing, segment critical services, harden remote access, confirm EDR/MDR health, and practice incident-response communications with client leadership.
Cyber resilience is not just about stopping every attack. It is about ensuring that when an attack happens, the community can keep operating.