{"id":107007,"date":"2019-11-01T16:46:34","date_gmt":"2019-11-01T16:46:34","guid":{"rendered":"https:\/\/www.internetsociety.org\/?post_type=resources&#038;p=107007"},"modified":"2025-06-24T16:58:41","modified_gmt":"2025-06-24T16:58:41","slug":"security-factsheet-why-should-municipalities-make-network-and-data-security-a-priority","status":"publish","type":"resources","link":"https:\/\/www.internetsociety.org\/resources\/doc\/2019\/why-should-municipalities-make-network-and-data-security-a-priority\/","title":{"rendered":"Security Factsheet: Why Should Municipalities Make Network and Data Security a Priority?"},"content":{"rendered":"<p><em>Note: This factsheet was written in collaboration with <a href=\"https:\/\/nextcenturycities.org\/\">Next Century Cities<\/a>.<\/em><\/p>\n<p>As of August 2019, ransomware attacks had already targeted more than <a href=\"https:\/\/blog.barracuda.com\/2019\/08\/28\/threat-spotlight-government-ransomware-attacks\/\">50 municipal governments<\/a> this year. And as communities add more connected devices to their tech ecosystems and collect more data, the threat is ongoing. Experts now predict that the odds of a municipality becoming a target of a ransomware attack are <a href=\"https:\/\/www.govtech.com\/security\/1-in-4-Local-Governments-Will-Fall-to-Ransomware-Experts-Say.html?mc_cid=90a7e474b8&amp;mc_eid=4c4b31ca2e\">one in four<\/a>. Not only do attacks take local services offline and disrupt critical functions, but recovery can be extremely costly. Further, breaches of municipal data stand to expose sensitive information about residents. As municipalities manage existing networks and adopt new technologies, network and data security practices should be a top priority.<\/p>\n<h4>What can municipalities do to minimize risk?<\/h4>\n<p>Communities can minimize risk by being intentional about how and by whom networks and devices are used. Here are eight best practices for municipal governments to optimize security.<\/p>\n<h6>1. Set strong internal data policies<\/h6>\n<p>Only collect data that serves a purpose, and whenever possible, ensure that data is not personally identifiable. Be thoughtful when determining:<\/p>\n<p>A. What data is being collected?<br \/>\nB. Where and how is data stored? <br \/>\nC. Who has access to sensitive information? <br \/>\nD. What safeguards are in place to intercept a breach? <br \/>\nE. Is data being sold?<\/p>\n<h6>2. Set strong internal security policies<\/h6>\n<p>Security requires all team members to be cautious about how they use technology in the workplace. Comprehensive security policies should address network connections, use of Internet of Things (IoT) devices, password parameters, use of encryption, and consistent data backups and software updates. Learn more about best practices for how individuals can keep the workplace secure <a href=\"https:\/\/www.internetsociety.org\/resources\/doc\/2019\/keeping-your-workplace-safe-online\/\">in this factsheet<\/a>.<\/p>\n<h6>3. Conduct staff trainings<\/h6>\n<p>Hold regular trainings for all staff members that address basic privacy, security, and network vulnerabilities as well as the specific actions that individuals can take to minimize risks, including internal policies such as those outlined above.\u00a0<\/p>\n<h6>4. Backup data often<\/h6>\n<p>Having a recent, comprehensive backup of municipal data on hand can minimize the impact of a ransomware attack. Ideally, files will be backed up with both a Cloud provider and an external storage device, and backups should be disconnected from system computers and networks.<\/p>\n<h6>5. Run regular security updates<\/h6>\n<p>Ensuring that security patches and updates to network infrastructure are applied regularly can help prevent known threats.<\/p>\n<h6>6. Hold vendor partners to high privacy and security standards<\/h6>\n<p>It\u2019s critical to set privacy and strong security parameters for whenever new devices, software, or programs are being introduced into your network. Securing Smart Cities <a href=\"https:\/\/securingsmartcities.org\/wp-content\/uploads\/2016\/03\/Guidlines_for_Safe_Smart_Cities-1.pdf\">offers a guide<\/a> to security considerations for selecting, implementing, and disposing of smart city technologies.<\/p>\n<h6>7. Apply MANRS actions to networks<\/h6>\n<p>If your city owns or operates its own network, it should become a member of <a href=\"https:\/\/www.manrs.org\/\">Mutually Agreed Norms for Routing Security (MANRS)<\/a>, which sets concrete actions for network operators to take in order to eliminate common routing threats. If a new network operator wants to offer service in your community, you should encourage them to become a MANRS member as well.<\/p>\n<h6>8. Consider an insurance policy<\/h6>\n<p>While insurance can\u2019t prevent attacks, a policy can <a href=\"https:\/\/www.routefifty.com\/tech-data\/2019\/10\/protection-cyber-insurance-ransomware\/160387\/\">help mitigate risk<\/a> and assist with the cost of recovering from an attack, natural disaster, or prolonged service outage (e.g. power outages). Many larger cities purchase their own cyber insurance policies, while smaller communities have the option of opting-in to pooled plans offered by associations.<\/p>\n<div class=\"green-highlight\">\n<p class=\"small-text\"><strong>Additional Resources<\/strong><\/p>\n<p class=\"small-text\">The Internet Society provides fact sheets on best practices for IoT and network security for individuals and enterprises, including <a href=\"https:\/\/www.internetsociety.org\/resources\/ota\/2015\/security-privacy-best-practices\/\">Best Practices: Security &amp; Privacy for Enterprises<\/a>.<\/p>\n<p class=\"small-text\">The <a href=\"https:\/\/www.cisecurity.org\/ms-isac\/\">Multi-State Information Sharing &amp; Analysis Center<\/a> provides cyber threat prevention, protection, response, and recovery resources for state, local, tribal, and territorial governments.<\/p>\n<p class=\"small-text\">The <a href=\"https:\/\/www.nist.gov\/\">National Institute of Standards and Technology<\/a> published the Cybersecurity Framework which includes guidelines and recommended practices for municipalities of any size to develop their comprehensive cybersecurity strategy. The agency also publishes <a href=\"https:\/\/www.oas.org\/en\/sms\/cicte\/docs\/OAS-AWS-NIST-Cybersecurity-Framework(CSF)-ENG.pdf\">white papers<\/a> and hosts <a href=\"https:\/\/www.nist.gov\/news-events\/events\">events<\/a> to provide additional training.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Communities can minimize risk by being intentional about how and by whom networks and devices are used. These are eight best practices for municipal governments to optimize security.<\/p>\n","protected":false},"author":46,"featured_media":0,"template":"","categories":[30,4738],"tags":[],"region_news_regions":[5931],"content_category":[6090],"ppma_author":[4057],"class_list":["post-107007","resources","type-resources","status-publish","hentry","category-trust","category-security-1","region_news_regions-global","resource_types-resource","content_category-resources-type"],"acf":[],"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false,"post-thumbnail":false,"square":false,"gform-image-choice-sm":false,"gform-image-choice-md":false,"gform-image-choice-lg":false},"uagb_author_info":{"display_name":"Ivana Trbovic","author_link":"https:\/\/www.internetsociety.org\/author\/trbovic\/"},"uagb_comment_info":0,"uagb_excerpt":"Communities can minimize risk by being intentional about how and by whom networks and devices are used. These are eight best practices for municipal governments to optimize security.","_links":{"self":[{"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/resources\/107007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/resources"}],"about":[{"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/types\/resources"}],"author":[{"embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/users\/46"}],"wp:attachment":[{"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/media?parent=107007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/categories?post=107007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/tags?post=107007"},{"taxonomy":"region_news_regions","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/region_news_regions?post=107007"},{"taxonomy":"content_category","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/content_category?post=107007"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/ppma_author?post=107007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}