Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

City of Winchester
Dan Hoffman, City Manager & Skip Dickson, Manager Intern
Maximizing Cyber Resilience in Local Government


Sounds like an action movie, right? Unfortunately, it happened in Atlanta, Georgia, despite the city’s reputation as a hub of innovation and technical development. In 2018, two Iran-based hackers used brute force ransomware to access the city's closed information network. Their attack temporarily shut down city utility, parking and judicial programs, confusing and frustrating community members.
Ultimately, Atlanta's attack took $2.6 million and weeks for an outside firm to remediate. At the time of the attack, Atlanta was spending about $108 million per year—more than many cities’ entire budget – on cybersecurity. However, Atlanta's investment did not protect it from a well-planned cyberstrike, highlighting the need for a comprehensive approach to cyberdefense.
Further, if a major city like Atlanta is susceptible to malign actors, imagine the cybersecurity threat to smaller cities, towns and counties. Smaller localities may lack adequate funding or quick access to emergency support when an attack occurs, making them an easy target.
The cybersecurity threat to local governments extends beyond the disruption of public services. It includes data and identity theft. As data stewards, localities store residents' personally identifiable information, such as bank account details, healthcare and tax records, property information, criminal history, employment and educational background. An intruder might even find voting records on the servers.
In Winchester, Virginia, defending against and mitigating a cyberattack is one of our highest emergency management priorities. There's no such thing as absolute cybersecurity. However, like physical security, a defense-in-depth strategy provides redundancy at multiple levels and increased protection. This is important considering the resource-constrained environment faced by many local governments.
In Winchester, our defense-in-depth strategy includes deploying zero-trust architecture; endpoint protection; multifactor authentication; extended detection and response; improved governance; external partnerships; and public outreach.
• Zero-Trust Security Architecture involves moving beyond traditional perimeter-based security to a "never trust, always verify" model that authenticates and authorizes every user and device before granting network access. We use micro-segmentation to limit the movement of potential threats, while monitoring and validating network traffic and user activities in real time. This lowcost but highly effective tactic is beneficial in a funding-restricted, governmental environment.
• Advanced threat detection, response efficacy and traditional solutions such as firewalls and secure gateways across the city's 1,000+ devices and workstations bolster Endpoint Protection. Redundancy is key: if one defense fails, others remain operational.
• Nuanced deployment of Multi-Factor Authentication (MFA) employs physical tokens for critical system access and soft tokens for broader network access. When MFA rollout is coupled with comprehensive staff training, employees understand the "why" as well as the "what" when it comes to cybersecurity.
• Extended Detection and Response (XDR) consists of three primary elements: advanced threat detection, automated response capabilities and enhanced visibility. Think of XDR as a centralized Security Operations Center (SOC) – constantly monitoring, analyzing and responding to threats across the entire IT environment. By prioritizing XDR technology, city staff can correlate data across multiple endpoints, proactively hunt cyber threats in real time and strengthen monitoring across the entire digital ecosystem.
• Improved Internal Governance Framework standards boost the city's cyber hygiene practices for staff and vendors. For example, we refined our technology procurement process to require vendors to complete a third-party cybersecurity disclosure form before contract execution.
• External Partnerships at the federal and state levels leverage assessments, tabletop exercises and other joint activities to baseline the city's cybersecurity posture, expose gaps, build capacity and identify creative solutions.
• Public and private sector organizations sometimes shy away from cybersecurity-related Public Outreach, a potentially awkward subject that can highlight shortcomings and exploitable vulnerabilities. Yet, with the right approach, educating residents on cybersecurity can build public support for cyberdefense initiatives, whether technical solutions, additional staff, or increased funding. In Winchester, we update residents on important cybersecurity developments via social media and articles in the city magazine, "WinConnect.”
These efforts are no panacea. However, by hardening our city against cyber-attacks, we may make it a less attractive target for would-be intruders. Our tactics are dynamic; as the threat evolves, we will need to grow with it.
In Winchester, our defense-in-depth strategy includes deploying zero-trust architecture; endpoint protection; multifactor authentication; extended detection and response; improved governance; external partnerships; and public outreach.
• Zero-Trust Security Architecture involves moving beyond traditional perimeter-based security to a "never trust, always verify" model that authenticates and authorizes every user and device before granting network access. We use micro-segmentation to limit the movement of potential threats, while monitoring and validating network traffic and user activities in real time. This lowcost but highly effective tactic is beneficial in a funding-restricted, governmental environment.
• Advanced threat detection, response efficacy and traditional solutions such as firewalls and secure gateways across the city's 1,000+ devices and workstations bolster Endpoint Protection. Redundancy is key: if one defense fails, others remain operational.
• Nuanced deployment of Multi-Factor Authentication (MFA) employs physical tokens for critical system access and soft tokens for broader network access. When MFA rollout is coupled with comprehensive staff training, employees understand the "why" as well as the "what" when it comes to cybersecurity.
• Extended Detection and Response (XDR) consists of three primary elements: advanced threat detection, automated response capabilities and enhanced visibility. Think of XDR as a centralized Security Operations Center (SOC) – constantly monitoring, analyzing and responding to threats across the entire IT environment. By prioritizing XDR technology, city staff can correlate data across multiple endpoints, proactively hunt cyber threats in real time and strengthen monitoring across the entire digital ecosystem.
• Improved Internal Governance Framework standards boost the city's cyber hygiene practices for staff and vendors. For example, we refined our technology procurement process to require vendors to complete a third-party cybersecurity disclosure form before contract execution.
• External Partnerships at the federal and state levels leverage assessments, tabletop exercises and other joint activities to baseline the city's cybersecurity posture, expose gaps, build capacity and identify creative solutions.
• Public and private sector organizations sometimes shy away from cybersecurity-related Public Outreach, a potentially awkward subject that can highlight shortcomings and exploitable vulnerabilities. Yet, with the right approach, educating residents on cybersecurity can build public support for cyberdefense initiatives, whether technical solutions, additional staff, or increased funding. In Winchester, we update residents on important cybersecurity developments via social media and articles in the city magazine, "WinConnect.”
These efforts are no panacea. However, by hardening our city against cyber-attacks, we may make it a less attractive target for would-be intruders. Our tactics are dynamic; as the threat evolves, we will need to grow with it.
The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

