"We're too small to be worth attacking" is the single most common thing we hear from new government clients, usually right before we show them why that isn't true anymore — and possibly never was.
The pattern isn't slowing down
Ransomware against state and local government has been climbing for a couple of years running, and 2026 hasn't broken the trend. One firm that tracks these incidents globally found a government entity somewhere in the world was hit by ransomware at a rate of roughly once a day in the first half of this year, with the United States accounting for close to a third of them. The headline-grabbing cases are usually mid-size or large cities, but the underlying research keeps landing on the same point: smaller jurisdictions are frequently more exposed than the big ones, not less.
Why smaller often means more exposed, not less
None of this is about being singled out. It's structural:
- Older systems stay in service longer. A ten-year-old server that a bigger city would have replaced two budget cycles ago is often still doing real work in a smaller jurisdiction.
- Security is usually one person's part-time job. Many small counties don't have a dedicated security role at all — it's whoever handles "computers" alongside several other titles.
- Budget cycles move slower than the threat does. Approving a new tool or a policy change can take a full budget year, while attackers adjust their tactics constantly.
- Recent surveys back this up directly. One 2026 survey of local government professionals found a majority had increased their cybersecurity budgets over the prior year, but most still didn't have the in-house expertise to run what they'd bought.
The uncomfortable part: attackers aren't guessing which targets are undefended. Automated scanning finds outdated, unpatched systems regardless of the population of the town running them.
What actually moves the needle
None of the following requires a large budget, and we'd rather a jurisdiction do these four things well than buy an expensive tool and leave the basics undone:
- Multi-factor authentication everywhere — not just email, every remote-access tool and cloud application.
- Backups that are tested, not just scheduled. A backup nobody has tried restoring from is a hope, not a plan.
- A written incident response plan that names who does what, so a bad morning doesn't start with figuring out who's in charge.
- An honest asset inventory. You can't protect a system you've forgotten is still running.
If your jurisdiction hasn't had a plain-English assessment of where you actually stand against these four items, that's usually where we start — and it doesn't require assuming the worst about your current setup to be worth doing.