Local Government Cyberattacks Are Disrupting Public Services. MSPs Need to Prepare Now.

Share Article:

Table of Contents:

A recent string of cyber incidents has forced local governments in multiple states to shut down networks, interrupt public-facing services, and shift emergency operations to backup processes. For MSPs supporting municipalities, this is a reminder that ransomware recovery is not just an IT exercise — it can become a public-safety obligation.

The incidents are not publicly attributed as one coordinated campaign. But they share a practical lesson: a small municipality with limited internal security resources can still be a high-impact target, especially when its network supports 911 routing, police and fire dispatch, public records, utility billing, and other essential services.

Municipal disruption is a public-safety issue

In early August, Suisun City, California, shut down its entire IT network after malicious software compromised city systems. The city said the incident affected critical public-safety operations, including 911 routing, police and fire dispatch, records, and city services. Emergency calls continued to be handled through Solano County’s dispatch center while the city activated emergency procedures and recovery operations.

Other municipalities and counties reported similar disruption:

  • Coweta, Oklahoma, said a ransomware attack affected its computers, files, and digital services. The town relied on off-site backups and unaffected external systems while recovery work continued.

  • Mitchell, South Dakota, shut down government networks following a cyberattack, disrupting normal government operations even though emergency services remained available.

  • Coryell County, Texas, and Washburn County, Wisconsin, also disclosed cyberattacks. Washburn County reported network and phone-service disruption while responders investigated the incident.

The public record does not establish that all of these events were caused by the same threat actor or malware family. That distinction matters. MSPs should avoid presenting unrelated incidents as a single confirmed campaign.

But the business risk is consistent across every event: when municipal networks go down, leaders must preserve public safety, maintain critical services, communicate with residents, recover systems, investigate the intrusion, and make high-stakes decisions under intense pressure.

Why MSPs are in the blast radius

Many small and midsize municipalities rely on MSPs as their practical IT department. That often means the provider manages identity, endpoints, backups, Microsoft 365, network infrastructure, remote access, servers, security tooling, and incident response coordination.

A successful attack against one municipal client is serious. A compromise of an MSP’s administrative tools, remote-management platform, shared credentials, or support environment can be much worse.

Threat actors understand this model. They look for trusted access paths that provide broad reach, including:

  • Remote monitoring and management platforms

  • Shared or reused administrative credentials

  • VPN and RDP services exposed to the internet

  • Weakly protected Microsoft 365 or identity-provider accounts

  • Flat networks that allow movement from administrative systems to operational systems

  • Backup platforms accessible with the same privileged accounts used for production administration

For a municipality, the consequences go beyond encrypted file shares. A disruption can affect court systems, permitting, utility billing, public records, communications, dispatch operations, and residents’ ability to reach local government.

The Suisun City incident shows why resilience planning matters. While city systems were impacted, emergency calls were rerouted through the county dispatch center and emergency response continued. That outcome depended on alternate operating procedures — not simply on having an endpoint protection agent installed.

The controls that matter most

MSPs supporting local government should treat this moment as an opportunity to verify (not merely assume) that each client can withstand a disruptive cyber event.

Test recovery, not just backups

A successful backup job is not proof of recoverability.

For every municipal client, confirm that backups are:

  • Isolated from normal domain and administrative credentials

  • Immutable, offline, or otherwise protected from deletion or encryption

  • Covering critical servers, line-of-business applications, configurations, and identity systems

  • Monitored for failed jobs, unusual deletion activity, and retention changes

  • Tested through documented restore exercises

The recovery plan should identify restoration priorities. A town may be able to defer restoration of a public website or internal file share, but it may need to restore dispatch support, emergency communications, public-safety records, utility systems, or finance operations first.

Every client should be able to answer three questions before an incident:

  1. What must be restored first to protect life, safety, and essential operations?

  2. How long will recovery actually take?

  3. Who has the authority to make recovery and public-communications decisions?

Separate critical systems from general administration

Segmentation is one of the strongest ways to limit the impact of a compromised user account or workstation.

Administrative networks should not have unrestricted pathways into public-safety, dispatch, operational technology, or other critical environments. Municipal clients should work with their MSP, public-safety vendors, and internal leadership to document:

  • Which systems are mission-critical

  • Who needs access to them

  • Which remote-access methods are allowed

  • How those systems are monitored

  • What alternative procedures exist when systems are unavailable

Segmentation is not a one-time firewall project. It requires maintaining access rules, reviewing exceptions, validating vendor connectivity, and ensuring that recovery systems are not reachable from compromised production networks.

Harden every remote-access path

Remote access remains one of the most valuable entry points for ransomware operators. Review VPN, RDP, remote-support tools, cloud administration portals, and vendor connections across every municipal client.

At a minimum:

  • Require phishing-resistant MFA wherever possible, especially for administrator and remote-access accounts.

  • Disable unused accounts immediately and review privileged access on a recurring schedule.

  • Restrict remote access by role, device posture, network location, and time where practical.

  • Remove direct RDP exposure from the internet.

  • Review authentication logs for impossible travel, repeated failures, unfamiliar devices, new MFA registrations, and suspicious administrator activity.

  • Require separate, named accounts for privileged administration rather than shared credentials.

This work is not glamorous, but it reduces the number of ways an attacker can turn one stolen password into a municipal outage.

Validate EDR and MDR coverage

EDR and MDR are valuable only when coverage is complete, healthy, and actively monitored.

MSPs should verify that all supported endpoints and servers are enrolled, reporting, properly licensed, and assigned to the correct tenant or policy group. Pay particular attention to systems that are often missed:

  • Legacy servers

  • Virtual machines

  • Dispatch-adjacent systems where vendor compatibility limits agents

  • Backup infrastructure

  • Administrator workstations

  • Network-management systems

  • Cloud workloads

For systems where standard EDR cannot be installed, document the compensating controls: network isolation, application allowlisting, enhanced logging, limited administrative access, and vendor-approved monitoring.

Turn preparation into a client service

The best time to discuss incident response is before a city council meeting, emergency declaration, or media inquiry forces the conversation.

MSPs can turn this risk into a structured municipal cyber-resilience review:

Review areaQuestion to answer
RecoveryCan the client restore essential services from isolated backups within an agreed recovery objective?
Public safetyAre dispatch, emergency communications, and related systems separated from general administration?
IdentityAre privileged accounts protected with MFA, least privilege, and regular access reviews?
Remote accessAre VPN, RDP, vendor connections, and remote-support tools inventoried and restricted?
DetectionAre EDR/MDR tools deployed, monitored, and validated on every eligible system?
ResponseDoes the client have named decision-makers, legal and insurance contacts, communication procedures, and a tested incident-response plan?

A tabletop exercise can be especially effective. Present a realistic scenario: the municipal network is unavailable at 7:30 a.m.; email is down; residents are calling; public-safety systems are operating in a backup mode; and a ransomware note claims data was stolen.

Then work through the decisions. Who calls the incident-response provider? Who contacts law enforcement and cyber insurance? Who determines whether systems can be brought back online? Who communicates with employees, residents, elected officials, and the press?

Those answers should not be improvised during an active incident.

The takeaway for MSPs

Small towns are not low-value targets. They are often organizations with broad community responsibility, sensitive data, essential services, limited IT staff, and little tolerance for downtime.

The recent incidents in California, Oklahoma, South Dakota, Texas, and Wisconsin demonstrate how quickly a local-government cyber event can become an operational emergency. In Suisun City, critical public-safety operations were affected and calls had to be routed through a county dispatch center; in Coweta, ransomware affected the town’s computers, files, and digital services.

MSPs supporting municipalities should act now: validate backups through restore testing, segment critical services, harden remote access, confirm EDR/MDR health, and practice incident-response communications with client leadership.

Cyber resilience is not just about stopping every attack. It is about ensuring that when an attack happens, the community can keep operating.

Schedule a Demo of Blacksmith!

Check Out Our Compliance Podcast on Spotify!