A small Florida city council voted last night to pay sixty-five bitcoin, something over half a million dollars at today's rate, to recover systems encrypted three weeks earlier after an employee opened an attachment. Six weeks before that, Baltimore refused a much smaller demand and is now several weeks into a recovery whose costs have been estimated in the tens of millions. Both decisions were defensible. Neither was a good outcome, and that is the shape of ransomware targeting municipalities in 2019. The pattern is no longer opportunistic. Local government has become a preferred target because it combines an unusually weak technology estate with an unusually strong pressure to restore service, and because the people making the payment decision are elected.
Why local government is the ideal victim
The technology estate is old, and it is old for structural reasons. Capital budgets for infrastructure are voted, not allocated, which means replacing a working-but-unsupported system competes directly with visible public priorities and loses. The result is a long tail of applications running on operating systems whose support ended years ago, held together because they work and because the vendor that wrote them no longer exists. The network is flat and inherited. Cities acquire systems by department over decades, and the practical consequence is that a compromised workstation in a parks office can often reach the finance and permitting systems. The services are essential and visible. When a city cannot issue permits, process property transactions, take utility payments or run its emergency dispatch, that is front-page news within a day and there is no commercial alternative for residents. The pressure to restore is political rather than economic, and it compresses the decision timeline enormously. Staffing is the quiet factor. Public sector pay for security engineers is not competitive with the private market in any developed economy, so the roles either sit vacant or are filled by generalists carrying five other responsibilities.
The payment question is genuinely hard here
In a private business, the calculation is commercial. In a city, it is a public decision made by people accountable to residents who need services now, using public money, in the open. The arguments against paying are well rehearsed: it funds the next attack, it marks the payer, it offers no guarantee of a working decryption tool, and it does nothing about data already exfiltrated. Baltimore's position has been consistent on those grounds and the city deserves some credit for it. The arguments for paying are not frivolous when recovery costs exceed the demand by a factor of thirty, when residents cannot transact with their own government, and when the alternative is months of manual workarounds. What makes it uncomfortable is that the decision is being made by councils with no technical advice of their own, under time pressure, frequently on the recommendation of an insurer whose interest is minimising the claim rather than ending the practice. The thing that removes the dilemma is not policy. It is a tested offline backup, and it is cheaper than either branch of the decision.
What actually reduces the risk
The controls are not different from anywhere else; the constraints are. Public sector organisations need advice that survives a procurement cycle and a vacant post. Segmentation delivers the most for the least in a flat municipal network. Separating operational technology, emergency services, finance and general office networks limits a single infection to one domain, and can be done incrementally. Immutable backups, verified by restore, come next. Then multi-factor authentication on remote access and email, which blocks the most common entry. Then the removal of internet-exposed remote desktop, which is how a surprising share of these incidents begin. And then the part that is genuinely public-sector specific: a manual continuity plan for the services residents cannot go without. Paper processes, delegated authority to accept alternative documentation, a communications plan. Cities that had one recovered visibly better than cities that improvised.
Name the resident service
Rank service interruption and dependency by public impact.
Limit shared failure
Review separation, remote access and unsupported dependencies.
Prove the fallback
Rehearse a system restore and a practical manual service procedure.
Agree decision authority
Document escalation, specialist legal advice and public communications.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for a Public Sector Security Assessment
- Map which services stop if the network stops. Rank them by public impact rather than by system criticality as the IT team sees it. That ranking drives everything else.
- Segment the flat network, starting with emergency services and finance. Full micro-segmentation is a multi-year programme; separating four zones is a quarter's work.
- Hold one backup copy offline or immutable, and restore from it annually. Not a file. A system, end to end, timed, with the staff who would actually do it.
- Inventory unsupported systems and give each one an owner and a date. Some cannot be replaced this year. They can be isolated, and the isolation can be documented for auditors and insurers.
- Enable multi-factor authentication on email and all remote access. In most public sector licence bundles this is already paid for and switched off.
- Write manual continuity procedures for the top five citizen services. Permits, payments, records, dispatch, benefits. Test one a year with the department that would run it.
- Agree the ransom decision framework before an incident. Who is authorised, on what criteria, with which legal advice, and what will be said publicly. A council debating this live is the worst possible version of it.
- Put security conditions into supplier and shared-service contracts. Regional and national shared platforms mean one authority's incident becomes several authorities' incident.
The Regional Angle
Gulf public sector organisations sit in an unusual position on this, and it is worth being precise about why. The centrally driven digital government programmes across the region, in the Emirates, Saudi Arabia, Bahrain and Qatar, have produced government technology estates that are in many respects newer and more consolidated than their American or European counterparts. National identity infrastructure, shared service platforms and unified government cloud initiatives mean a regional municipality is rarely running its own decade-old permitting system on an unsupported server in a basement. That removes a large part of the vulnerability described above. What it substitutes is concentration. Where a hundred American cities each carry their own weak estate and fail independently, a shared national platform fails once for everyone. The security of those platforms is generally strong, and the national cybersecurity authorities across the Gulf have been notably active in setting standards and issuing advisories. But the dependency profile is different and the continuity planning needs to reflect it: the question for a regional entity is less "what if our systems are encrypted" and more "what do we do for three days if a shared platform we do not control is unavailable". The softer edges are where the exposure actually sits. Municipal and quasi-government bodies here rely heavily on contractors and outsourced operators for facilities, utilities, waste, parking and permitting delivery, and those contractors run their own systems with their own security postures, connected to government networks by arrangements agreed years ago. Smaller emirates, municipalities and authorities outside the largest programmes also run leaner estates with less oversight than the flagship entities. That tier is where a regional version of this wave would land first. Threat context matters too. This region's public sector has lived with destructive, state-linked wiper attacks on critical infrastructure for the best part of a decade, which means board-level appetite for security investment here is considerably higher than in a comparable American city and the sophistication of national defence is correspondingly better. The risk is that criminal ransomware gets treated as a lesser variant of that threat and planned for less carefully, when in fact its entry routes, an employee's attachment, an exposed remote service, a contractor's laptop, are quite different and far more mundane. One last point, on disclosure. Public transparency about incidents is limited across the region, for understandable reasons of national security and public confidence. The trade-off is that regional entities learn very little from each other's experience, and the informal peer network that helps American municipalities warn one another does not really exist here. Whatever can be shared through the national authorities should be, because attackers already share everything.
The objection worth taking seriously
The objection from anyone who has worked in local government is that this analysis is correct and useless. Cities are not underspending on security because nobody explained the risk. They are underspending because the money is not there, because the procurement cycle for anything meaningful runs eighteen months, because the security engineer post has been open for a year at a salary nobody will accept, and because a council that raises taxes to fund segmentation of a network no resident has heard of will be asked why the roads are still bad. The constraint is fiscal and political, and security advice that ignores it is a lecture. The harder version goes further. Public sector ransomware is arguably a policing and national response problem that has been privatised onto individual cities. A municipality of forty thousand people cannot defend itself against an organised criminal group operating from a jurisdiction that will not extradite, any more than it can defend itself against a foreign air force. Expecting it to, and criticising it when it fails or when it pays, is a category error. The response belongs at national level, through law enforcement, sanctions, payment-channel disruption and funded shared services. That is right, and it is also not available this month. The useful posture is to separate what requires money from what requires decisions. Segmenting a flat network, holding one offline backup copy, turning on multi-factor authentication that is already licensed, removing exposed remote desktop and writing a paper fallback for five citizen services are largely decisions, not budget lines, and they account for most of the practical risk. The structural argument for national funding and national response is correct and should keep being made. In the meantime, the cheap controls are the difference between a bad fortnight and a council meeting about bitcoin.
Common Questions
Is paying ever the right call for a public body?
Sometimes it is the least bad option available at the moment of decision, which is not the same thing. The failure happened earlier, when no recoverable backup was maintained. Any authority that finds itself weighing payment should treat that as the finding, whichever way the vote goes.
Does cyber insurance solve this?
It funds response and sometimes ransom, which is valuable, but it also shapes the decision towards payment and is already being repriced as claims accumulate. Read the conditions, because failing to maintain basic controls can void cover precisely when it is needed.
What is the single most common entry point?
Email attachments and internet-exposed remote desktop, in that order, with compromised contractor or supplier access third. None of them require sophistication, which is why the basic controls work as well as they do.
What should we expect over the next twelve months?
Expect the wave through American local government to continue and to spread further into schools, health districts and utilities, which share the same profile. Expect a serious public policy argument about whether public bodies should be permitted to pay at all. Expect insurers to tighten municipal terms sharply. And expect at least one incident to move from data unavailability to data publication, which will change the calculation for every authority holding resident records.
Public Sector Security Assessment — we rank the services residents cannot do without, separate the networks that should never have been joined, and make sure the ransom decision is one you have already made in writing.
