THE INVISIBLE REALITY
Cybersecurity in the private sector is rarely discussed in the open, mainly because the vast majority of incidents involving security breaches stay behind closed doors and never become public unless the attackers themselves disclose them to apply pressure during an extortion campaign.
When we talk about government institutions, cybersecurity carries different implications and consequences compared with the private sector. It is no secret that governments face enormous public scrutiny: they are exposed to public opinion, affected by biases driven by the frustration of certain groups, and subject to the pressure the media can exert.
This can create a false sense that things are worse than they really are, although to be fair there is a very mixed ecosystem, for better and for worse, when it comes to cybersecurity. Larger government agencies usually capture more budget, and there we find a higher level of maturity: they can acquire high-cost industry solutions and in many cases rely on large consultancies to keep their processes moving.
Smaller institutions tend to have proportionally smaller budgets and lower maturity. In many cases they have no dedicated cybersecurity department, yet they still operate processes and solutions managed by their IT team. And then there are very small agencies that depend on limited budgets and mostly struggle to do what they can with what they have; some basic cybersecurity practices are applied, though tight budgets often get in the way.
A pandemic of budget cuts
We are all tired of hearing about COVID-19, and its effects are too visible to need restating, but consider one interesting angle: the pandemic forced budget cuts across governments everywhere, and as you might expect, one of the hardest-hit line items was cybersecurity, which was already being squeezed by many other apparent priorities.
When things go wrong
When something goes wrong, it can always get worse.
Government agencies are among the most attractive targets for ransomware operators and state-aligned threat actors precisely because of the critical services they run and the sensitive citizen data they hold. A single intrusion against a tax authority, a health system, or a benefits agency can paralyze services nationwide, disrupt payments, and put public trust at risk for years.
So what tends to go wrong?
Here is the recipe for chaos.
- Budgets cut and cybersecurity treated as a low priority.
- Vulnerabilities reported long ago that were never remediated in a timely manner.
- Many agencies without staff trained in cybersecurity.
- Many agencies that never run periodic security reviews.
- Of those that do run reviews, most rely on traditional, point-in-time consulting models.
- Oversight bodies responsible for enforcing compliance lacking the resources to follow up.
- Incident response teams understaffed and unable to support hundreds of agencies at once.
- National cybersecurity strategies full of good intentions but short on real execution.
Now add a Ransomware-as-a-Service (RaaS) crew that sets its sights on public institutions. The effect is devastating: a finance ministry knocked offline halts electronic invoicing, imports, and exports across an entire country. The losses from service disruption easily exceed any ransom demand. When the agency in charge of social security and medical services is hit next, appointment systems collapse, follow-ups are lost, and even scheduled surgeries are affected. These are not hypotheticals; they have already happened to national governments.
They say it is hard to learn from other people's mistakes, but you can quietly run a self-assessment against this question: how many of those symptoms exist in your own public institution right now?
Perhaps the only missing ingredient is a criminal group interested in attacking you.
Doing the same thing yields the same results
Let's face it: we are no longer in the days when an annual penetration test was enough. If we try to force a traditional consulting model onto agile environments that change every day, the result becomes a headache and a bottleneck for you.
The lack of manual penetration testing based on up-to-date models and supported by on-demand service platforms makes it impossible to stay current with your security posture without reviewing it once a year and crossing your fingers.
In fact, the most comfortable path, and what many consulting firms take, is to justify the same old services to avoid at all costs the transition that would mean sacrificing their margins to share them with a third party or building the platforms themselves, which would be far more expensive for them.
Recalling the symptoms above, the absence of a process to manage every vulnerability is what lets time pass while issues go unresolved. By adopting modern, automation-driven methods for continuous security reviews (DevSecOps), agencies can surface risks as early as possible and fix them when it is cheapest to do so (from the start).
Few institutions run security awareness training to keep people from being the entry point for malicious software, and it is well known that phishing is the main gateway for ransomware. It is also uncommon for government agencies to perform proactive validation exercises such as Red Team engagements, which simulate what would happen during a real attack by an advanced criminal group. Finally, backups are scarce when they exist at all, and not having a process that runs constant backups with copies kept out of attackers' reach will determine whether you recover quickly or take a very long time after an attack.
Criminals evolve constantly; every week there is a new ransomware variant, or new vulnerabilities are discovered, shared, and exploited among criminal groups before they become public.
At WhiteJaguars we spent 10 years refining our process before we released it to the world. Of course there are other solutions for vulnerability management and penetration testing, but what really matters is honestly assessing whether what you are doing today is enough to protect you against attacker behavior that changes every single day.
How secure do you feel if you work for the government?
Government cybersecurity in the US, UK, and Canada is increasingly governed by clear frameworks. In the United States, agencies must align with FISMA, the NIST Cybersecurity Framework and NIST SP 800-53, and cloud services are held to FedRAMP authorization. The UK relies on the NCSC Cyber Assessment Framework and the Government Functional Standard for security, while Canada follows the CCCS guidance and ITSG-33 controls. Mapping your program to these standards is the foundation of a defensible public-sector security posture.
At WhiteJaguars we are proud of the government institutions that have decided to evolve and discover, alongside us, the practices that lead in the most mature markets, from public banking to municipalities. Doing things right is within everyone's reach.
It may be time to discover what you have been missing, the same approach many organizations in the US, UK, Canada, and Silicon Valley are already using.