
State governments
From funding uncertainty to shifting community expectations, state governments have more challenges than ever in serving their communities. Get the strategy and support your organization needs to adapt.
Why Wipfli?
Wipfli’s comprehensive services can help you address critical areas across your organization, whether you need support for navigating federal regulations and technology or creating a more collaborative culture.
Our team brings relationship-focused support to each of our engagements. We seek to understand your organization as deeply as you do so that we can provide tailored solutions for helping you drive real change.
Wipfli’s audit and assurance support goes beyond compliance, helping you foster financial transparency and smarter resource allocation. We offer a full range of audit services, including financial statement audit, TIF audit, uniform guidance and state single audit support that can provide practical insights to transform your organization.
Maximize tax opportunities on your energy project with Wipfli’s energy incentives services. Our dedicated team of CPA tax professionals, architects and engineers can support you at all stages of your project to help ensure you see the full benefit of your potential incentives.
Wipfli offers government digital services to help you become a modern, data-driven organization. From leveraging and securing data to adopting cloud-based solutions and AI, we can help you implement faster and see a greater return on your technology investments.
Build a more effective organization with Wipfli’s support for your people, processes and technology. Whether you need assistance in process documentation, strategic planning or creating a technology road map, we can help you find new ways to work efficiently and adopt the right solutions. We can also help transform your people with leadership development and government-specific training services.
Access knowledgeable, experienced talent to help your organization navigate finance, HR, operations and IT challenges. With full back-office support and C-suite services, we can help you increase efficiency, direct strategy and manage the areas that cause you unnecessary stress.
Wipfli’s multidisciplinary risk advisory team provides experienced guidance to help you manage your most complex risk and regulatory challenges. We can assist you with the full spectrum of internal controls and compliance, helping you stay resilient and effective even in an uncertain regulatory environment.
Reach out to our team
We advise state governments on how to operate more effectively, meet regulatory and compliance requirements, claim energy incentives, implement technology and more. Let’s talk about the specific challenges you face and how we can help you solve them.
Perspective changes everything.
Receive timely industry developments, regulatory changes and other news impacting your success.
- Learn More
EVENT | January 19, 2027
January 2027 Uniform Guidance regulation training
Join us for a practical and engaging virtual training of the Office of Management and Budget’s (OMB) Uniform Guidance (2 CFR Part 200) — the cornerstone of federal grant compliance. This training is designed to help nonprofit and government professionals understand federal grant regulations and how to apply them effectively and avoid common pitfalls in managing federal awards. Led by experienced trainers with years of auditing and consulting expertise, this session blends regulatory review with real-world examples and actionable insights. Whether you’re new to federal
Learn MoreARTICLE
Water system cyberattacks: How municipalities can protect critical infrastructure
Municipal water systems have become a prime target for cyberattacks. In July, the FBI and the EPA warned that attackers targeted water and wastewater utilities in at least seven states. In Minnesota , more than 30 community water systems were targeted. In these incidents, internet-exposed industrial control devices that operate critical infrastructure were targeted. By accessing these devices remotely, attackers were able to change passwords and network settings, disrupting visibility and control of critical equipment. The attacks have resulted in some flooding and a loss of water pressure. The water system cyberattacks are a reminder that municipalities and the critical infrastructure they manage are common targets for malicious actors. Keep reading to learn more about the threats facing local governments and for cybersecurity best practices that can mitigate the risk of an attack. Why are municipalities vulnerable to cyberattacks? Like any organization, municipalities face a constant threat of cyber incidents. But they often have to manage that risk with fewer resources. Several factors make local governments vulnerable to attacks, including: Limited budgets and staffing: Municipal IT teams are often asked to manage complex environments with constrained funding and limited cybersecurity experience. Lack of regulatory requirements: Many industries, including some utilities like the electric grid, must comply with stringent federal cybersecurity requirements. But there are no federal standards municipalities must meet. This lack of regulatory oversight can result in cybersecurity being underprioritized. Aging infrastructure: Critical systems may rely on decades-old technology that was designed for operational efficiency rather than cybersecurity. In many cases, outdated software may no longer be able to be patched, creating additional vulnerabilities. Growing connectivity: Water treatment plants, power systems and traffic management systems increasingly use internet-connected tools for monitoring and remote management, creating more potential entry points for attackers. Disjointed operations: Municipal departments often manage technology independently, making consistent cybersecurity governance more difficult. What makes water systems especially vulnerable? Water systems are particularly susceptible to cyberattacks for several reasons, including: Water utility personnel often lack the cybersecurity knowledge needed to secure increasingly complex operational technology environments. Many water systems rely on outdated software and hardware that may no longer be supported by manufacturers. These systems often cannot be easily upgraded because newer operating systems may not be compatible with critical control equipment. Water infrastructure is often spread across large geographic areas, making it harder to maintain consistent security practices and oversight. Remote management tools may lack security controls, leaving weaknesses that attackers can exploit. Why are municipalities common targets? Cybercriminals, especially those from adversarial nations, target municipalities because successful attacks can create immediate and highly visible disruptions. Interrupting water service, electricity, transportation systems or public communications can affect thousands of residents at once. Beyond disruptions to daily life, politically motivated attackers are looking to sow discontent within our communities and nation. If water isn’t running or is unsafe to drink, or if other utilities aren’t functioning as expected, it can cause political unrest. Who is behind attacks on municipalities? Two common perpetrators of cyberattacks directed at local governments are: Nation-states: Public infrastructure often attracts interest from foreign adversaries looking to gather intelligence, disrupt services or test capabilities against critical infrastructure. Multiple federal agencies have warned that foreign cyber actors continue to target U.S. infrastructure. Ransomware groups: These are organized cybercriminal syndicates that lock or encrypt a victim’s computer systems and data, then demand large payments to restore access. Many ransomware groups are fronted by national adversaries. What methods are used to attack municipalities? Common attack methods that municipalities need to be aware of and prepared to defend against include: Exposed internet-facing systems A common attack path is to exploit known vulnerabilities in systems directly accessible from the public internet. This can include remote access portals, industrial control systems, servers, firewalls or other devices that are accessible from outside the municipal network. Cybercriminals continuously scan the internet for systems running outdated software or misconfigured services. A vulnerable device left exposed is an easy target for an attacker. Once inside, they may steal data, move laterally through the network, deploy ransomware or attempt to gain access to critical infrastructure systems. Social engineering Social engineering attacks trick employees into revealing sensitive information, sharing credentials or bypassing security controls. Phishing emails remain one of the most common examples. An attacker may pose as a trusted vendor, coworker or government agency to convince an employee to click a malicious link, open an infected attachment or enter login credentials into a fraudulent website. With valid credentials, attackers can often access the same systems and data that employees do. If additional security weaknesses exist within the network, they may be able to escalate privileges and gain access to more sensitive systems. Physical attacks Physical access remains a serious cybersecurity risk, especially for municipalities that manage numerous facilities and remote infrastructure locations. Attackers can attempt to connect unauthorized devices directly to the network. Methods include plugging specialized hacking tools into a computer or an unused network port, installing a rogue wireless access point or leaving infected USB drives where employees are likely to find them. Once a malicious device is connected behind the municipal firewall, attackers may be able to establish remote access, monitor network activity or steal credentials without immediately being detected. What steps should municipalities take to improve cybersecurity? There are many elements to a strong cybersecurity posture. Actions your municipality can take to improve its defenses against cyberattacks include: Segment industrial control systems from office networks Your industrial control system (ICS) environments need to be separated from your office networks. Network segmentation prevents attackers who gain access to an employee workstation or email account from moving laterally into critical infrastructure systems. Implement continuous security monitoring Real-time monitoring can help identify and alert you to any suspicious behavior and potential attacks, so you can investigate and respond before a security event escalates into a major disruption. Security monitoring can be handled internally with a dedicated security operations team, or through a third-party vendor. Review and secure remote access Remote access is often a necessity for municipal operations, but it can also become a major vulnerability if not properly managed. Municipalities should regularly review all remote access pathways, remove unnecessary connections and enforce strong controls over systems accessible from outside the organization’s facilities. Access should be limited to approved users and approved devices, with ongoing monitoring of remote connections to identify unusual activity. Penetration testing Penetration testing provides a proactive way to identify vulnerabilities by simulating real-world attack scenarios before they are exploited. These assessments can reveal exposed systems, weak configurations, inadequate access controls and other issues that may not surface during routine IT operations. Regular testing helps municipalities validate whether security controls are working as intended. Strong authentication controls Multi-factor authentication (MFA) and strong password requirements remain foundational defenses against credential theft and unauthorized access. Adopt a cybersecurity framework A formal framework provides structure for building and maintaining a cybersecurity program. NIST CSF can be an effective starting point because it focuses on core cybersecurity outcomes and risk management. For more detailed technical guidance, municipalities can use the CIS Critical Security Controls or DISA Security Technical Implementation Guides (STIGs). Using an established framework helps organizations prioritize efforts, measure progress and ensure security initiatives align with industry best practices. Patch and update systems Establish a process for regularly updating operating systems, applications, network devices and security tools. Legacy systems that cannot be patched should be identified, documented and protected through compensating controls such as network isolation, restricted access or enhanced monitoring. Invest in employee training Human error is the biggest cybersecurity vulnerability. It’s essential to provide your staff with regular training on how to recognize suspicious emails, verify unusual requests and report potential incidents. Promoting skepticism can help employees pause and validate requests before taking actions that could compromise security. Maintain secure backups Backups remain one of the most effective defenses against ransomware. Municipalities should maintain secure, regularly tested backups of critical systems and data. Backups should be immutable, meaning they cannot be modified. This helps ensure clean recovery options remain available even if production systems become compromised. Develop and test incident response plans If a cyber incident occurs, there needs to be a plan in place to prevent confusion and further mistakes that compound the issue. Municipalities should have a documented incident response plan that clearly outlines roles, responsibilities, communication procedures and escalation paths. Regular tabletop exercises help staff practice their response, identify gaps and build confidence so they can act quickly during an actual event. Create a disaster recovery strategy An incident response plan focuses on managing the attack itself, but you also need a roadmap for restoring operations afterward. A disaster recovery plan should define recovery priorities, acceptable downtime, backup restoration procedures and contingency operations. For critical services like water and wastewater treatment, planning for operational continuity needs to be a priority. Hire outside help Many cities and towns lack the budget to hire a cybersecurity professional. External advisors can help assess security posture, identify vulnerabilities, validate compliance with security frameworks, implement monitoring solutions and support remediation efforts. Third-party services can provide municipalities with capabilities that are difficult or costly to maintain internally, allowing them to strengthen security without significantly expanding staff. Read more Physical penetration testing is the missing layer for stronger cybersecurity Nation-state actors are increasingly launching cyberattacks on businesses and critical infrastructure. How should your organization prepare? Smarter cybersecurity program management starts with these 3 pillars
Learn MoreARTICLE
To help your state align with ACF’s A Home for Every Child initiative, embrace innovation
In late 2025, the U.S. Department of Health and Human Services kicked off a new initiative aimed at revamping foster care in America. Known as A Home for Every Child and overseen by the Administration for Children and Families (ACF), the initiative has a stated goal of ensuring that there are enough foster homes available to serve every child who needs one right away. Leaders at state health and human services departments are now moving to improve their systems or processes to align with A Home for Every Child. Keep reading to learn innovative ideas for how your team can get started. What is A Home for Every Child? A Home for Every Child (AHFEC) is a set of grant funding guidelines intended to expand available foster homes while also moving fewer children into the system. To achieve a goal of reducing home-to-child ratios to 1:1 or better, AHFEC recommends systems and process updates that range from implementing a modern current child welfare information system (CCWIS) to speeding up licensing procedures for foster parents. Key pillars of AHFEC include preventing more children from entering foster care, creating a larger pool of available foster homes, emphasizing placement urgency, prioritizing kinship care and retaining more caregivers. Dozens of states are currently working to align with the AHFEC initiative. The initiative doesn’t require that states use any particular platforms or technology products but does set broad guidelines for how states should change their systems and processes. AHFEC is focused on not just compliance, but on achieving specific operational outcomes. How can state human services departments improve their systems or processes to align with A Home for Every Child? State human services departments or agencies looking to align with AHFEC guidelines will typically need to adjust at least some of their systems and processes to do so. But this is not a one-size-fits-all prescription, as your agency’s specific needs may differ from those of peer agencies in other states. Here are six innovative ways that states are moving to align with AHFEC: Creating efficiencies and streamlining foster parent licensing In addition to speeding up licensing requirements for caregivers who are related to the child they will be fostering, some states are speeding up foster home licensing more broadly. To do this, states may focus on making process improvements that reduce the number of days needed to approve a license while also providing a better customer experience for foster parents. This kind of move can be relatively simple to implement but delivers a big impact with clear ROI. Embrace low-hanging tech efficiencies While AHFEC does encourage modernizing your CCWIS, a huge investment like that is not the only technology-focused move you can make. To start, consider embracing ancillary tech improvements like finding efficiencies in certification or background checks and experimenting with more effective assessment tools or new AI solutions . These lower-hanging fruits can be faster and less costly to implement, while still delivering notable results. Prevent or reduce entries into the foster system A key aspect of AHFEC is not just expanding foster home supply but reducing demand. This typically involves both measures to help stabilize a child’s birth family so the child can avoid entering the foster care system in the first place, and to place children already in foster care in a permanent home more quickly. This strategy can help lower the overall number of children needing foster care at any one time, which means there’s more room for each child who does end up in a foster home. Data-driven targeting and performance analysis As you begin to modernize your tech tools, you gain access to the analytics you need to make smarter, more data-driven decisions. For example, you can build predictive models to help you improve placement matching or boost your rates of caregiver retention. You’ll also be able to track your KPIs in real time, allowing you to better understand where your efforts are succeeding and where you may need to devote more resources. Kinship-first placement AHFEC puts a major emphasis on kinship placement, prioritizing fostering a child with relatives over other alternatives. To facilitate this, states are streamlining licensing for caregivers who are also kin and implementing dedicated kinship placement strategies. This approach can help reduce the demand for traditional foster homes, as relatives can provide a child in need with a permanent housing solution. New foster parent recruitment strategies States are exploring network-driven and community-based recruitment strategies to encourage more people to become foster parents. A network-driven approach might involve asking existing foster parents to talk to their friends, while a community-based strategy could mean focusing on trying to reach members of local civic organizations or faith-based groups rather than relying on mass marketing campaigns. Here, targeted campaigns reflecting child demographics may also be useful (for example, some states have tried campaigns focused on recruiting foster parents specifically from within tribal communities). What are your next steps to align with A Home for Every Child? Here’s how to get started with aligning your foster care system more closely with AHFEC guidelines: 1. Consult your peers Talk with your peers at child welfare agencies in other states to learn how they are tackling AHFEC. These conversations can help you identify potential quick wins or learn how to achieve meaningful incremental progress. 2. Attend conferences and look to thought leaders To get a broader perspective on how states are aligning with AHFEC, you should also attend conferences and look for content on the subject put out by relevant thought leaders. You don’t have to reinvent the wheel here; just find out what works elsewhere and adapt it to fit your state’s needs. 3. Work with an advisor Seek additional guidance from an advisory firm that understands foster care and AHFEC, preferably one that leads with human-centered design workshops and solution ideation. An advisor can help you learn the nuances of AHFEC guidelines, assess your specific needs and develop a plan to bring your department into closer alignment so you qualify for grant funding. Read more For government agencies, agentic AI doesn’t mean job loss What is a single audit and when do you trigger one? AI governance checklist: A basic framework for your organization


LET'S CONNECT
Wipfli is ready to help your organization overcome disruption, navigate uncertainty and serve more effectively.


