Digital services for government
The right tech helps you make smarter decisions, deploy automation, clarify your financials and connect with the people you serve. We help you develop and implement an effective digital strategy to strengthen your operations and boost your impact.
Explore our digital services
Wipfli doesn’t just offer digital solutions. We offer digital clarity, cutting through complex software selection, implementation and optimization to make the future work for you. Our digital services for governments include:
Let Wipfli help you leverage data for better decision-making and greater efficiency. We work as an extension of your team to build a high-quality data foundation and implement full data integration so that you can leverage insights and deliver on what matters most to your community.
From optimizing your current systems to adopting cloud-based solutions, Wipfli can help you leverage technology for greater operational insights and efficiency. We focus on streamlining implementation to deliver a faster impact from your tech investments. We also foster ongoing connections, working closely with your team on training, adoption, updates and maintenance so that your staff can take full advantage of solutions.
Wipfli’s digital strategy services go beyond software selection to help you create your road map for becoming a tech-enabled, more effective organization. We combine our extensive experience in aiding digital transformation with a deep understanding of your organization’s goals to help you create an achievable, measurable and actionable technology plan.
Move beyond on-premises servers and legacy applications to unlock the full value of your data with Wipfli’s iPaaS support. We can help you build an iPaaS strategy, implement your solution and train your teams in a way that’s efficient and aligned with your mission.
Proactively protect your organization from evolving risks with Wipfli’s cybersecurity services. We can help you fortify your digital defenses against both human and AI threats so that you can meet regulations, maintain trust and keep your constituents’ sensitive data secure.
Wipfli can help your government entity harness the power of AI to improve operations and transform service delivery. We bring an integrated view of AI, going beyond data management to help you understand the impact on your people, risk and mission. Whether you need to build an AI strategy, train and educate staff, improve data quality or navigate compliance, Wipfli’s team can support your AI adoption.
Don’t let IT problems drain your resources and damage trust with constituents. Wipfli’s managed services team helps you build efficient, secure and agile technology operations that can increase your effectiveness.
Reach out to our team
Let’s talk about how we can help you implement a modern digital strategy and targeted tech tools to help your government agency operate more effectively and better serve your constituents.
Perspective changes everything.
Receive timely industry developments, regulatory changes and other news impacting your success.
Insights & resources
Learn MoreARTICLE
Water system cyberattacks: How municipalities can protect critical infrastructure
Municipal water systems have become a prime target for cyberattacks. In July, the FBI and the EPA warned that attackers targeted water and wastewater utilities in at least seven states. In Minnesota , more than 30 community water systems were targeted. In these incidents, internet-exposed industrial control devices that operate critical infrastructure were targeted. By accessing these devices remotely, attackers were able to change passwords and network settings, disrupting visibility and control of critical equipment. The attacks have resulted in some flooding and a loss of water pressure. The water system cyberattacks are a reminder that municipalities and the critical infrastructure they manage are common targets for malicious actors. Keep reading to learn more about the threats facing local governments and for cybersecurity best practices that can mitigate the risk of an attack. Why are municipalities vulnerable to cyberattacks? Like any organization, municipalities face a constant threat of cyber incidents. But they often have to manage that risk with fewer resources. Several factors make local governments vulnerable to attacks, including: Limited budgets and staffing: Municipal IT teams are often asked to manage complex environments with constrained funding and limited cybersecurity experience. Lack of regulatory requirements: Many industries, including some utilities like the electric grid, must comply with stringent federal cybersecurity requirements. But there are no federal standards municipalities must meet. This lack of regulatory oversight can result in cybersecurity being underprioritized. Aging infrastructure: Critical systems may rely on decades-old technology that was designed for operational efficiency rather than cybersecurity. In many cases, outdated software may no longer be able to be patched, creating additional vulnerabilities. Growing connectivity: Water treatment plants, power systems and traffic management systems increasingly use internet-connected tools for monitoring and remote management, creating more potential entry points for attackers. Disjointed operations: Municipal departments often manage technology independently, making consistent cybersecurity governance more difficult. What makes water systems especially vulnerable? Water systems are particularly susceptible to cyberattacks for several reasons, including: Water utility personnel often lack the cybersecurity knowledge needed to secure increasingly complex operational technology environments. Many water systems rely on outdated software and hardware that may no longer be supported by manufacturers. These systems often cannot be easily upgraded because newer operating systems may not be compatible with critical control equipment. Water infrastructure is often spread across large geographic areas, making it harder to maintain consistent security practices and oversight. Remote management tools may lack security controls, leaving weaknesses that attackers can exploit. Why are municipalities common targets? Cybercriminals, especially those from adversarial nations, target municipalities because successful attacks can create immediate and highly visible disruptions. Interrupting water service, electricity, transportation systems or public communications can affect thousands of residents at once. Beyond disruptions to daily life, politically motivated attackers are looking to sow discontent within our communities and nation. If water isn’t running or is unsafe to drink, or if other utilities aren’t functioning as expected, it can cause political unrest. Who is behind attacks on municipalities? Two common perpetrators of cyberattacks directed at local governments are: Nation-states: Public infrastructure often attracts interest from foreign adversaries looking to gather intelligence, disrupt services or test capabilities against critical infrastructure. Multiple federal agencies have warned that foreign cyber actors continue to target U.S. infrastructure. Ransomware groups: These are organized cybercriminal syndicates that lock or encrypt a victim’s computer systems and data, then demand large payments to restore access. Many ransomware groups are fronted by national adversaries. What methods are used to attack municipalities? Common attack methods that municipalities need to be aware of and prepared to defend against include: Exposed internet-facing systems A common attack path is to exploit known vulnerabilities in systems directly accessible from the public internet. This can include remote access portals, industrial control systems, servers, firewalls or other devices that are accessible from outside the municipal network. Cybercriminals continuously scan the internet for systems running outdated software or misconfigured services. A vulnerable device left exposed is an easy target for an attacker. Once inside, they may steal data, move laterally through the network, deploy ransomware or attempt to gain access to critical infrastructure systems. Social engineering Social engineering attacks trick employees into revealing sensitive information, sharing credentials or bypassing security controls. Phishing emails remain one of the most common examples. An attacker may pose as a trusted vendor, coworker or government agency to convince an employee to click a malicious link, open an infected attachment or enter login credentials into a fraudulent website. With valid credentials, attackers can often access the same systems and data that employees do. If additional security weaknesses exist within the network, they may be able to escalate privileges and gain access to more sensitive systems. Physical attacks Physical access remains a serious cybersecurity risk, especially for municipalities that manage numerous facilities and remote infrastructure locations. Attackers can attempt to connect unauthorized devices directly to the network. Methods include plugging specialized hacking tools into a computer or an unused network port, installing a rogue wireless access point or leaving infected USB drives where employees are likely to find them. Once a malicious device is connected behind the municipal firewall, attackers may be able to establish remote access, monitor network activity or steal credentials without immediately being detected. What steps should municipalities take to improve cybersecurity? There are many elements to a strong cybersecurity posture. Actions your municipality can take to improve its defenses against cyberattacks include: Segment industrial control systems from office networks Your industrial control system (ICS) environments need to be separated from your office networks. Network segmentation prevents attackers who gain access to an employee workstation or email account from moving laterally into critical infrastructure systems. Implement continuous security monitoring Real-time monitoring can help identify and alert you to any suspicious behavior and potential attacks, so you can investigate and respond before a security event escalates into a major disruption. Security monitoring can be handled internally with a dedicated security operations team, or through a third-party vendor. Review and secure remote access Remote access is often a necessity for municipal operations, but it can also become a major vulnerability if not properly managed. Municipalities should regularly review all remote access pathways, remove unnecessary connections and enforce strong controls over systems accessible from outside the organization’s facilities. Access should be limited to approved users and approved devices, with ongoing monitoring of remote connections to identify unusual activity. Penetration testing Penetration testing provides a proactive way to identify vulnerabilities by simulating real-world attack scenarios before they are exploited. These assessments can reveal exposed systems, weak configurations, inadequate access controls and other issues that may not surface during routine IT operations. Regular testing helps municipalities validate whether security controls are working as intended. Strong authentication controls Multi-factor authentication (MFA) and strong password requirements remain foundational defenses against credential theft and unauthorized access. Adopt a cybersecurity framework A formal framework provides structure for building and maintaining a cybersecurity program. NIST CSF can be an effective starting point because it focuses on core cybersecurity outcomes and risk management. For more detailed technical guidance, municipalities can use the CIS Critical Security Controls or DISA Security Technical Implementation Guides (STIGs). Using an established framework helps organizations prioritize efforts, measure progress and ensure security initiatives align with industry best practices. Patch and update systems Establish a process for regularly updating operating systems, applications, network devices and security tools. Legacy systems that cannot be patched should be identified, documented and protected through compensating controls such as network isolation, restricted access or enhanced monitoring. Invest in employee training Human error is the biggest cybersecurity vulnerability. It’s essential to provide your staff with regular training on how to recognize suspicious emails, verify unusual requests and report potential incidents. Promoting skepticism can help employees pause and validate requests before taking actions that could compromise security. Maintain secure backups Backups remain one of the most effective defenses against ransomware. Municipalities should maintain secure, regularly tested backups of critical systems and data. Backups should be immutable, meaning they cannot be modified. This helps ensure clean recovery options remain available even if production systems become compromised. Develop and test incident response plans If a cyber incident occurs, there needs to be a plan in place to prevent confusion and further mistakes that compound the issue. Municipalities should have a documented incident response plan that clearly outlines roles, responsibilities, communication procedures and escalation paths. Regular tabletop exercises help staff practice their response, identify gaps and build confidence so they can act quickly during an actual event. Create a disaster recovery strategy An incident response plan focuses on managing the attack itself, but you also need a roadmap for restoring operations afterward. A disaster recovery plan should define recovery priorities, acceptable downtime, backup restoration procedures and contingency operations. For critical services like water and wastewater treatment, planning for operational continuity needs to be a priority. Hire outside help Many cities and towns lack the budget to hire a cybersecurity professional. External advisors can help assess security posture, identify vulnerabilities, validate compliance with security frameworks, implement monitoring solutions and support remediation efforts. Third-party services can provide municipalities with capabilities that are difficult or costly to maintain internally, allowing them to strengthen security without significantly expanding staff. Read more Physical penetration testing is the missing layer for stronger cybersecurity Nation-state actors are increasingly launching cyberattacks on businesses and critical infrastructure. How should your organization prepare? Smarter cybersecurity program management starts with these 3 pillars
Learn MoreARTICLE
To help your state align with ACF’s A Home for Every Child initiative, embrace innovation
In late 2025, the U.S. Department of Health and Human Services kicked off a new initiative aimed at revamping foster care in America. Known as A Home for Every Child and overseen by the Administration for Children and Families (ACF), the initiative has a stated goal of ensuring that there are enough foster homes available to serve every child who needs one right away. Leaders at state health and human services departments are now moving to improve their systems or processes to align with A Home for Every Child. Keep reading to learn innovative ideas for how your team can get started. What is A Home for Every Child? A Home for Every Child (AHFEC) is a set of grant funding guidelines intended to expand available foster homes while also moving fewer children into the system. To achieve a goal of reducing home-to-child ratios to 1:1 or better, AHFEC recommends systems and process updates that range from implementing a modern current child welfare information system (CCWIS) to speeding up licensing procedures for foster parents. Key pillars of AHFEC include preventing more children from entering foster care, creating a larger pool of available foster homes, emphasizing placement urgency, prioritizing kinship care and retaining more caregivers. Dozens of states are currently working to align with the AHFEC initiative. The initiative doesn’t require that states use any particular platforms or technology products but does set broad guidelines for how states should change their systems and processes. AHFEC is focused on not just compliance, but on achieving specific operational outcomes. How can state human services departments improve their systems or processes to align with A Home for Every Child? State human services departments or agencies looking to align with AHFEC guidelines will typically need to adjust at least some of their systems and processes to do so. But this is not a one-size-fits-all prescription, as your agency’s specific needs may differ from those of peer agencies in other states. Here are six innovative ways that states are moving to align with AHFEC: Creating efficiencies and streamlining foster parent licensing In addition to speeding up licensing requirements for caregivers who are related to the child they will be fostering, some states are speeding up foster home licensing more broadly. To do this, states may focus on making process improvements that reduce the number of days needed to approve a license while also providing a better customer experience for foster parents. This kind of move can be relatively simple to implement but delivers a big impact with clear ROI. Embrace low-hanging tech efficiencies While AHFEC does encourage modernizing your CCWIS, a huge investment like that is not the only technology-focused move you can make. To start, consider embracing ancillary tech improvements like finding efficiencies in certification or background checks and experimenting with more effective assessment tools or new AI solutions . These lower-hanging fruits can be faster and less costly to implement, while still delivering notable results. Prevent or reduce entries into the foster system A key aspect of AHFEC is not just expanding foster home supply but reducing demand. This typically involves both measures to help stabilize a child’s birth family so the child can avoid entering the foster care system in the first place, and to place children already in foster care in a permanent home more quickly. This strategy can help lower the overall number of children needing foster care at any one time, which means there’s more room for each child who does end up in a foster home. Data-driven targeting and performance analysis As you begin to modernize your tech tools, you gain access to the analytics you need to make smarter, more data-driven decisions. For example, you can build predictive models to help you improve placement matching or boost your rates of caregiver retention. You’ll also be able to track your KPIs in real time, allowing you to better understand where your efforts are succeeding and where you may need to devote more resources. Kinship-first placement AHFEC puts a major emphasis on kinship placement, prioritizing fostering a child with relatives over other alternatives. To facilitate this, states are streamlining licensing for caregivers who are also kin and implementing dedicated kinship placement strategies. This approach can help reduce the demand for traditional foster homes, as relatives can provide a child in need with a permanent housing solution. New foster parent recruitment strategies States are exploring network-driven and community-based recruitment strategies to encourage more people to become foster parents. A network-driven approach might involve asking existing foster parents to talk to their friends, while a community-based strategy could mean focusing on trying to reach members of local civic organizations or faith-based groups rather than relying on mass marketing campaigns. Here, targeted campaigns reflecting child demographics may also be useful (for example, some states have tried campaigns focused on recruiting foster parents specifically from within tribal communities). What are your next steps to align with A Home for Every Child? Here’s how to get started with aligning your foster care system more closely with AHFEC guidelines: 1. Consult your peers Talk with your peers at child welfare agencies in other states to learn how they are tackling AHFEC. These conversations can help you identify potential quick wins or learn how to achieve meaningful incremental progress. 2. Attend conferences and look to thought leaders To get a broader perspective on how states are aligning with AHFEC, you should also attend conferences and look for content on the subject put out by relevant thought leaders. You don’t have to reinvent the wheel here; just find out what works elsewhere and adapt it to fit your state’s needs. 3. Work with an advisor Seek additional guidance from an advisory firm that understands foster care and AHFEC, preferably one that leads with human-centered design workshops and solution ideation. An advisor can help you learn the nuances of AHFEC guidelines, assess your specific needs and develop a plan to bring your department into closer alignment so you qualify for grant funding. Read more For government agencies, agentic AI doesn’t mean job loss What is a single audit and when do you trigger one? AI governance checklist: A basic framework for your organization
Learn MoreARTICLE
More government agencies are embracing advanced AI. Here’s how to do it while keeping humans at the center of your work.
As AI technology evolves beyond conversational AI to offer more task-oriented or even autonomous AI tools, government agencies are moving to take advantage. But does this mean that humans will be pushed aside ? It doesn’t have to. In fact, state and county government agencies are increasingly demonstrating how AI can be used to enhance jobs, delivering both efficiency and a better work experience. Keep reading to learn more about how you can implement AI to not just keep a human in the loop, but help them thrive. New tools like agentic AI are more powerful than generative AI chatbots You’re probably familiar with AI chatbots like ChatGPT or Microsoft Copilot. These were the first wave of AI technology that really broke into the public consciousness and will generate an answer or other output in response to an input from a human user. But over the last six months or so, leveraging agentic AI has pushed the boundaries of AI technology well beyond this basic framework. Agentic AI is capable of autonomously taking on assignments rather than just responding to prompts, which allows you to not just quickly create a document or a slide show, but also fully automate certain workflows. And chatbots themselves are increasingly being used as tools to create AI agents — simpler versions of agentic AI that can automate basic tasks. Why should state and local government agencies explore AI tools like agentic AI? Newer AI concepts, like agentic AI or headless AI, can help government agencies operate more efficiently and effectively. Used correctly, these tools don’t eliminate jobs at all but allow your team to do more — and focus on more interesting work. Key benefits include: Augment processes rather than replace roles: Data entry, intake paperwork and ground-level analysis are unappealing parts of many state or county government jobs. These processes can be augmented with or even handed entirely over to AI, allowing your team members to focus on the more energizing, engaging aspects of their work. Radically simplify data sharing: Headless AI is a type of AI that has no user interface at all but operates in the background to share data between different systems via APIs. For example, headless AI can make it vastly simpler to pull together details about a constituent from several different systems to instantly create a full case history — or to automatically update each of those systems based on a Microsoft Teams chat you have with a colleague. Automate repetitive tasks: AI agents and agentic AI can really shine by automating certain repetitive tasks that don’t involve qualitative human judgment. For any given role, consider automating the 30% of responsibilities that are the most dull and repetitive, freeing up the team member to give more attention to the 70% of the job that demands more flexibility, creativity and humanity. Support a human-in-the-loop (HITL) oversight process: AI retains human oversight, from governance policies to tool choices to a human review of AI outputs, helping to ensure that your team’s needs and expertise remain at the center of your work. Serve your community more effectively: Automating aspects of your work allows you to broaden your impact. For example, by using agentic AI to handle background check approvals in the foster care system, you could significantly speed up the approvals process. Reduce employee burnout: By automating the least appealing parts of many jobs, you can also help reduce employee burnout. This can improve morale for not just individual team members but your team as a whole. What are some top AI use cases for government agencies? Government agencies are increasingly moving beyond AI pilots to actively integrating the technology into their daily workflows. For example, agencies are using AI to: Create an internal AI assistant: An internal team at one major state-level department built an AI assistant that draws on an internal knowledge base to save the department’s team from spending countless hours navigating dense government regulations to answer questions or guide decisions. (This is another area where headless AI could help you quickly integrate data from multiple systems.) Complex scheduling: One county-level human services agency needs to create monthly schedules for hundreds of employees who make home visits to thousands of clients. This was a massive undertaking — until the agency began using an AI agent to do it. Develop policies and SOPs: Government departments are now leaning on AI to create SOPs, internal policy documents, templates and other technical writing that nobody is eager to take on but are essential to the smooth functioning of your organization. Rapid prototyping and development: New standards such as Model Context Protocol (MCP) integrate AI models with external data sources, allowing secure ways to access LLMs and APIs to begin to rapidly build, design and maintain large enterprise systems. Faster permitting: Certain agencies have begun using AI agents to speed up building permit applications, as the agents can quickly review thousands of pages of building code regulations to check for compliance issues. Complex, multistep workflows: Agentic AI is even able to oversee certain complicated processes like grant funding compliance, managing public records or onboarding new vendors. Code enforcement: Cities and counties are adding AI-powered cameras to maintenance trucks or other government vehicles. As these vehicles drive around, the cameras can spot code violations on buildings or properties, triggering an automated enforcement letter to the property owner. Cybersecurity: Agentic AI can monitor your networks 24/7 to watch for potential threats and respond immediately if an incident is detected, including by taking basic defensive actions and alerting key individuals within your organization. How can program or department heads at government agencies make better use of AI? If you’re a departmental head or program lead at a state or local government agency, here’s how you can start making more effective use of AI: 1. Understand relevant state or county regulations Your state or county may have specific AI regulations or policies in place that your agency will need to abide by. Review all relevant rules before moving forward. 2. Use what you have on hand AI doesn’t have to mean expensive new investments. Many government agencies already have active Microsoft Copilot licenses, for example. This means you already have the ability to build AI agents to automate certain routine tasks. 3. Consult an advisor Work with a third-party advisory firm to explore specific AI use cases that would allow your team to work more effectively without eliminating jobs. An advisor can help you create an overall AI roadmap to guide your long-term adoption efforts, develop governance policies and conduct a rapid analysis on potential use cases to assess which use cases are most ripe for AI and automation to deliver impact. 4. Implement in stages Don’t try to rebuild all your workflows overnight. Implement AI agents and agentic AI in phases, starting with one or two use cases at a time, focusing on what makes the most sense based on your rapid analysis. This will help with change management by giving your team time to adapt. Read more AI governance checklist: A basic framework for your organization How to prepare your data for generative AI Salesforce failed to replace thousands of workers with AI. What can you learn?


LET'S CONNECT
Wipfli is ready to help your organization overcome disruption, navigate uncertainty and serve more effectively.


