October is Cybersecurity Awareness Month — a reminder that being cyber-strong isn’t about having the most security tools. It’s about keeping government agencies working and continuing to serve citizens when an attack occurs.
When 911, benefits, schools or other critical services go down, citizens don’t experience a cyber event. They experience government not working. Every cyber decision is ultimately a citizen experience decision.
That is why the conversation must move beyond cybersecurity to cyber resilience: The ability to sustain the mission, recover quickly and preserve public trust when disruption occurs.
For state and local governments, the real question today isn’t simply whether an attack can be prevented. It’s whether essential services can keep running when one happens.
Can 911 dispatch stay online? Can residents still access benefits? Can schools still function? And when systems are disrupted, how quickly can they be brought back?
That's the difference between cybersecurity and cyber resilience.
As government becomes more digital and AI becomes embedded into more workflows, technology is no longer solely supporting the mission. It is increasingly part of how the mission is delivered. When that technology fails, government can lose the ability to perform part of its mission.
We’ve seen what that can look like. An August 2026 cyberattack on Suisun City, California, hit police and fire dispatch and critical records. It forced 911 dispatchers to relocate to a neighboring county’s center and closed City Hall for a week.
That is the real consequence of cyber disruption: interrupted services, frustrated residents and damage to public trust.
For leaders, start with three questions:
1. What services are truly mission-critical?
2. What data, systems and third parties do those services depend on?
3. What happens to citizens and the mission if those systems become unavailable tomorrow?
Those questions move the conversation away from technology for technology’s sake and toward the work government exists to do. They create the foundation for prioritizing investments, strengthening governance and building a realistic resilience roadmap around citizen and mission outcomes.
Take unemployment insurance. The mission-critical service depends on identity verification, the claims database and the payment processor. If those systems go down, people may not receive benefits and the state may face operational and compliance consequences. That simple walkthrough turns the three questions into a method leaders can apply to any service.
Threats aren’t easing. Ransomware remains a major source of disruption. Attackers are increasingly exploiting vulnerabilities and using AI to move faster and make attacks more convincing. The stakes for government are operational, financial and public-facing.
------------------------------------------------------------------------------------------------------------------
ALSO READ: Balancing security with public sector delivery — Atlanta Business Chronicle
------------------------------------------------------------------------------------------------------------------
Security can't be something we bolt on
State and local governments are expanding digital services, moving workloads to the cloud and using AI in more parts of their operations. Residents expect those services to be easy to use, reliable and trusted.
Security must be part of the transformation process from the outset — not something bolted on after a service is designed.
Consider an online portal for unemployment benefits or SNAP enrollment. Sensitive information flows through those systems, but as important are the people who depend on them to work. Security, privacy, governance and continuity all must be designed into the service from the beginning.
Building in security from the start doesn’t put the brakes on innovation. It gives agencies a stronger foundation to innovate with a clearer understanding of risk and fewer surprises later.
Innovation, security, resilience and transparency are no longer separate workstreams. They are part of one strategy for delivering trusted public services.
This comes back to trust. Citizens need to be confident that their information is protected, that government services will remain available, and that increasingly AI-enabled decisions are being used responsibly and can be explained.
------------------------------------------------------------------------------------------------------------------
National Life Group is investigating NTT DATA’s Data Analytics and AI methods to detect fraud using machine learning and artificial intelligence. They are looking at NTT DATA’s Security Services to further reduce risk. Read the case study.
------------------------------------------------------------------------------------------------------------------
AI is changing the cyber equation — for attackers and defenders
Government does not have the option of sitting AI out from a cybersecurity perspective. Bad actors use it. If defenders do not, they are being asked to fight at a serious disadvantage in speed, scale and sophistication.
For security teams, AI can recognize patterns faster, reduce alert volume, automate repetitive work, and accelerate investigations and response. That speed matters when attackers are moving faster, too.
AI also creates new risks, so it cannot operate without strong governance and human judgment. The strongest model is human + AI: AI provides speed and scale; experienced people provide context, judgment and accountability.
For state and local governments, where security teams are often stretched, that combination can materially improve defensive capacity. AI is becoming part of the defense, not simply another source of risk.
Attackers are demonstrating what that change looks like. The FBI has documented malicious actors using AI-powered voice cloning to impersonate senior US government officials. The message is clear: AI is changing both the speed and credibility of attacks, and government defenders must adapt accordingly.
Cyber resilience cannot be delegated to IT.
Leaders need to know what absolutely must keep running, what those services depend on, where they are exposed and whether the organization can recover when something happens. Every department holds information. Every executive makes decisions that affect resilience. This is a leadership issue and an enterprise risk issue — not simply a technology issue. Resilience requires clear executive responsibility. Cybersecurity leaders need the authority, resources and access to leadership to manage risk across the organization.
------------------------------------------------------------------------------------------------------------------
Explore what the emergence of frontier models signals to CISOs, CIOs and security leaders — and why the real challenge is not access to any single model but readiness for a fundamental shift in the threat environment. It’s now a more demanding security environment being shaped by advanced AI models. What Frontier AI means for Cybersecurity | NTT DATA
------------------------------------------------------------------------------------------------------------------
Measure resilience, not the size of the security stack
More security tools do not necessarily mean more security. The more important question is whether investments reduce the risks that could disrupt the services on which citizens rely.
Instead of focusing on product counts or treating every vulnerability as equally urgent, leaders should prioritize the systems, attack paths and dependencies that could create the greatest operational impact.
That changes the questions leaders ask:
• How quickly can we detect an attack?
• How quickly can we contain it?
• How quickly can we restore a mission-criticalservice?
• Which mission-criticalservices or processes remain most exposed?
• Are we reducing our highest-priority risks?
These are measures of resilience: outcomes, recovery and continuity of service — not the size of the technology portfolio.
The same principle applies to vulnerabilities. Prioritize what an attacker could exploit to create the greatest mission impact, rather than treating every issue as equally urgent.
That lets scarce resources go where they reduce operational risk most meaningfully.
St. Paul, Minnesota, offers a practical example. When ransomware disrupted internal networks and public-facing services, the city prioritized restoring 911, payroll and business services first. Preparation — including backups and an incident response plan — helped the city focus on continuity of mission when it mattered.
The basics still matter — because recovery matters
Identity management, multifactor authentication, patching, asset visibility, secure backups, employee awareness and practiced incident response remain important. But the goal is not the controls themselves; it is the ability to prevent disruption where possible and recover critical services quickly when prevention fails.
CISA’s Cybersecurity Awareness Month message captures that discipline in three priorities:
• Reduce vulnerabilities
• Replace end-of-support devices
• Recover quickly to sustain operations
The point is simple: Resilience is built through disciplined preparation, not technology alone.
From there, leaders can test readiness: practice an incident, verify that recovery works, identify the dependencies most likely to disrupt critical services and make sure the right people know their roles before a crisis begins.
In the end, cyber resilience is about sustaining the mission through disruption to protect the services people depend on and preserve their trust in the institutions that serve them. Technology matters, but technology alone cannot deliver that outcome. It takes leadership, preparation and consistent execution.
Looking ahead
My advice to state and local leaders: Prepare for disruption instead of assuming it can always be prevented. Know which services must keep running. Understand what they depend on. Use AI to strengthen defense while governing it responsibly. And treat cyber resilience as an executive leadership capability, not an IT capability.
Cybersecurity isn’t solely about protecting systems. It’s about protecting the mission of government — and preserving the trust citizens place in the institutions that serve them.
Explore more:
Cyber Frontiers 2026 explores emerging cyber risks, including AI-enabled deepfakes, skills gaps, breach defense and the coming disruption of quantum computing.
Cyber Frontiers 2026: A new era of cyber risk | NTT DATA Group
About the author:
Beth Howen
Executive Managing Director, State, Local and Education (SLED) North America
Beth is the executive managing director of state, local and education (SLED) at NTT DATA North America, responsible for driving profitable growth, industry strategy and client satisfaction through modern IT solutions. With over 30 years of leadership experience in the technology sector, Beth has held executive roles at Capgemini, Telus International, Atos and the City of Indianapolis. Her expertise spans strategic planning, process optimization and technology integration, and she has consistently delivered enterprise-wide initiatives that enhance operational efficiency and drive sustained growth. Beth is also a dedicated mentor to emerging leaders and a strong advocate for women in tech, actively supporting the Women & Hi-Tech organization.
For State and Local Governments, Cyber Resilience is the New Foundation of Public Trust
WS Studio 1985 - stock.adobe.com