municipaltrade-pressNewsThe Broadside1 min read

Minnesota extends cybersecurity baseline to local governments

The state's whole-of-state plan layers assessments, enterprise tools, and cyber navigators onto municipalities and critical infrastructure, but adoption is voluntary, and the entities getting hit aren't using the capabilities.


TL;DR

Minnesota CISO John Israel's office is expanding a statewide cybersecurity baseline program to local governments and critical infrastructure. The effort, built on a 2023 plan and backed by DHS grant funding, runs on three pillars: baseline assessments to help entities build a security program, enterprise-class tools offered at no or low cost through the state's buying power, and a team of cyber navigators who build ongoing relationships with local governments. Israel said the data shows that entities hit by ransomware and other attacks are the ones that haven't adopted the capabilities. The plan doesn't mandate use of state services, the goal is baseline controls, however sourced.

Minnesota has been building toward a whole-of-state cybersecurity model for years. The state used DHS grant money and other funding to create MNet, an enterprise telecommunications network connecting state and local government and education offices. Now the CISO's office is layering on more.

The current plan, launched in 2023, was shaped by a 15-member advisory task force drawn from state, city, and county government. It targets three things: a cybersecurity baseline for local governments and critical infrastructure, assessments, controls, policies, standards; advanced security capabilities delivered through the state's procurement scale, aimed at local governments that may lack even an IT team; and a navigator program that embeds cyber advisors who get to know local entities and understand their specific needs, rather than sending one-off outreach.

"Hundreds of entities" are now participating across the programs, Israel told Federal News Network. The state isn't requiring anyone to use its tools. "I just want you to have some baseline control," he said. "That's really the focus of that plan, not to buy our stuff or to adopt our tools as much as it is to make sure you have some tools or you have a program that meets these capabilities."

The threat picture makes the stakes clear. Israel acknowledged that Minnesota still sees ransomware and other attacks hitting local governments. "The numbers are showing us that those who are being affected have not adopted these capabilities," he said.

The whole-of-state trend extends beyond Minnesota. A NASCIO-Deloitte survey found 73% of state CISOs favor a centralized cybersecurity model over a federated one. Before the current plan, Israel said his office watched adoption of shared services like MNet's firewalls and intrusion detection drop among local and education organizations, a pattern that helped motivate the task force approach and the navigator model.


Published ·Deep Fathom