Government agencies face a complex web of interconnected challenges
State and local governments must overcome considerable pressures. Leaders have to confront shifting federal regulations, financial strain and a rapidly evolving technology landscape, all while continuing to deliver for the constituents they serve.
Regulations, reporting requirements and oversight demands continue to increase for state and local governments. Maintaining compliance while managing day-to-day operations can strain limited resources and create risk across your organization. With more than 750 government clients, Wipfli brings deep experience in audit, compliance and risk management to help you strengthen transparency and controls.
Legacy systems, manual processes and growing cybersecurity threats can make it difficult to meet constituent expectations and operate efficiently. Our comprehensive technology services help you modernize and build capacity with support for solutions including cybersecurity, data and analytics, enterprise solutions and AI.
Recruiting and retaining skilled employees has become increasingly difficult for government organizations, impacting service delivery and long-term strategic goals. Wipfli helps strengthen your organization through workforce strategy, leadership development, training and outsourced support for key functions, giving you access to the people and knowledge needed to move forward.
Government leaders are under increasing pressure to do more with less while maintaining accountability and delivering quality services. We take a comprehensive approach to performance, helping you optimize processes, align strategy, improve operations and identify opportunities for greater efficiency across your organization.
Explore our government services
We advise state and local government leaders on how to meet the moment. Ask us for help navigating uncertainty, improving operational performance, strengthening outcomes and impact, implementing tailored technology solutions, maintaining compliance and more.
Insights for government leaders
EVENT | October 6, 2026
Real-world federal grants compliance: SEFA, journal entries, and 2 CFR 200 practice plus in-kind regulations and building your plan
Join us for a focused three-day workshop designed to help strengthen your organization’s compliance with the Uniform Guidance 2 CFR Part 200. This hands-on session will guide participants through building an audit-ready Schedule of Expenditures of Federal Awards (SEFA), identifying (and correcting) commonly improperly recorded fixed asset transactions, and developing well-documented in-kind contribution plans. In days one and two, participants will tackle real-world journal entry recording scenarios while gaining access to practical, audit-ready tools, including a capital asset template, SEFA roll-forward templates and guidance for efficiently rolling forward audit footnotes. By applying these techniques, participants will improve reporting accuracy, reduce year-end preparation time and strengthen their organization’s readiness for audits and financial reviews. Through practical examples and real-world scenarios, attendees will leave with the tools and growing confidence around improving financial reporting, strengthening asset management practices and meeting federal requirements for cost sharing and documentation. Stay for day three to review non-federal share in-kind regulations and take time to begin building your plan.
ARTICLE
Water system cyberattacks: How municipalities can protect critical infrastructure
Municipal water systems have become a prime target for cyberattacks. In July, the FBI and the EPA warned that attackers targeted water and wastewater utilities in at least seven states. In Minnesota , more than 30 community water systems were targeted. In these incidents, internet-exposed industrial control devices that operate critical infrastructure were targeted. By accessing these devices remotely, attackers were able to change passwords and network settings, disrupting visibility and control of critical equipment. The attacks have resulted in some flooding and a loss of water pressure. The water system cyberattacks are a reminder that municipalities and the critical infrastructure they manage are common targets for malicious actors. Keep reading to learn more about the threats facing local governments and for cybersecurity best practices that can mitigate the risk of an attack. Why are municipalities vulnerable to cyberattacks? Like any organization, municipalities face a constant threat of cyber incidents. But they often have to manage that risk with fewer resources. Several factors make local governments vulnerable to attacks, including: Limited budgets and staffing: Municipal IT teams are often asked to manage complex environments with constrained funding and limited cybersecurity experience. Lack of regulatory requirements: Many industries, including some utilities like the electric grid, must comply with stringent federal cybersecurity requirements. But there are no federal standards municipalities must meet. This lack of regulatory oversight can result in cybersecurity being underprioritized. Aging infrastructure: Critical systems may rely on decades-old technology that was designed for operational efficiency rather than cybersecurity. In many cases, outdated software may no longer be able to be patched, creating additional vulnerabilities. Growing connectivity: Water treatment plants, power systems and traffic management systems increasingly use internet-connected tools for monitoring and remote management, creating more potential entry points for attackers. Disjointed operations: Municipal departments often manage technology independently, making consistent cybersecurity governance more difficult. What makes water systems especially vulnerable? Water systems are particularly susceptible to cyberattacks for several reasons, including: Water utility personnel often lack the cybersecurity knowledge needed to secure increasingly complex operational technology environments. Many water systems rely on outdated software and hardware that may no longer be supported by manufacturers. These systems often cannot be easily upgraded because newer operating systems may not be compatible with critical control equipment. Water infrastructure is often spread across large geographic areas, making it harder to maintain consistent security practices and oversight. Remote management tools may lack security controls, leaving weaknesses that attackers can exploit. Why are municipalities common targets? Cybercriminals, especially those from adversarial nations, target municipalities because successful attacks can create immediate and highly visible disruptions. Interrupting water service, electricity, transportation systems or public communications can affect thousands of residents at once. Beyond disruptions to daily life, politically motivated attackers are looking to sow discontent within our communities and nation. If water isn’t running or is unsafe to drink, or if other utilities aren’t functioning as expected, it can cause political unrest. Who is behind attacks on municipalities? Two common perpetrators of cyberattacks directed at local governments are: Nation-states: Public infrastructure often attracts interest from foreign adversaries looking to gather intelligence, disrupt services or test capabilities against critical infrastructure. Multiple federal agencies have warned that foreign cyber actors continue to target U.S. infrastructure. Ransomware groups: These are organized cybercriminal syndicates that lock or encrypt a victim’s computer systems and data, then demand large payments to restore access. Many ransomware groups are fronted by national adversaries. What methods are used to attack municipalities? Common attack methods that municipalities need to be aware of and prepared to defend against include: Exposed internet-facing systems A common attack path is to exploit known vulnerabilities in systems directly accessible from the public internet. This can include remote access portals, industrial control systems, servers, firewalls or other devices that are accessible from outside the municipal network. Cybercriminals continuously scan the internet for systems running outdated software or misconfigured services. A vulnerable device left exposed is an easy target for an attacker. Once inside, they may steal data, move laterally through the network, deploy ransomware or attempt to gain access to critical infrastructure systems. Social engineering Social engineering attacks trick employees into revealing sensitive information, sharing credentials or bypassing security controls. Phishing emails remain one of the most common examples. An attacker may pose as a trusted vendor, coworker or government agency to convince an employee to click a malicious link, open an infected attachment or enter login credentials into a fraudulent website. With valid credentials, attackers can often access the same systems and data that employees do. If additional security weaknesses exist within the network, they may be able to escalate privileges and gain access to more sensitive systems. Physical attacks Physical access remains a serious cybersecurity risk, especially for municipalities that manage numerous facilities and remote infrastructure locations. Attackers can attempt to connect unauthorized devices directly to the network. Methods include plugging specialized hacking tools into a computer or an unused network port, installing a rogue wireless access point or leaving infected USB drives where employees are likely to find them. Once a malicious device is connected behind the municipal firewall, attackers may be able to establish remote access, monitor network activity or steal credentials without immediately being detected. What steps should municipalities take to improve cybersecurity? There are many elements to a strong cybersecurity posture. Actions your municipality can take to improve its defenses against cyberattacks include: Segment industrial control systems from office networks Your industrial control system (ICS) environments need to be separated from your office networks. Network segmentation prevents attackers who gain access to an employee workstation or email account from moving laterally into critical infrastructure systems. Implement continuous security monitoring Real-time monitoring can help identify and alert you to any suspicious behavior and potential attacks, so you can investigate and respond before a security event escalates into a major disruption. Security monitoring can be handled internally with a dedicated security operations team, or through a third-party vendor. Review and secure remote access Remote access is often a necessity for municipal operations, but it can also become a major vulnerability if not properly managed. Municipalities should regularly review all remote access pathways, remove unnecessary connections and enforce strong controls over systems accessible from outside the organization’s facilities. Access should be limited to approved users and approved devices, with ongoing monitoring of remote connections to identify unusual activity. Penetration testing Penetration testing provides a proactive way to identify vulnerabilities by simulating real-world attack scenarios before they are exploited. These assessments can reveal exposed systems, weak configurations, inadequate access controls and other issues that may not surface during routine IT operations. Regular testing helps municipalities validate whether security controls are working as intended. Strong authentication controls Multi-factor authentication (MFA) and strong password requirements remain foundational defenses against credential theft and unauthorized access. Adopt a cybersecurity framework A formal framework provides structure for building and maintaining a cybersecurity program. NIST CSF can be an effective starting point because it focuses on core cybersecurity outcomes and risk management. For more detailed technical guidance, municipalities can use the CIS Critical Security Controls or DISA Security Technical Implementation Guides (STIGs). Using an established framework helps organizations prioritize efforts, measure progress and ensure security initiatives align with industry best practices. Patch and update systems Establish a process for regularly updating operating systems, applications, network devices and security tools. Legacy systems that cannot be patched should be identified, documented and protected through compensating controls such as network isolation, restricted access or enhanced monitoring. Invest in employee training Human error is the biggest cybersecurity vulnerability. It’s essential to provide your staff with regular training on how to recognize suspicious emails, verify unusual requests and report potential incidents. Promoting skepticism can help employees pause and validate requests before taking actions that could compromise security. Maintain secure backups Backups remain one of the most effective defenses against ransomware. Municipalities should maintain secure, regularly tested backups of critical systems and data. Backups should be immutable, meaning they cannot be modified. This helps ensure clean recovery options remain available even if production systems become compromised. Develop and test incident response plans If a cyber incident occurs, there needs to be a plan in place to prevent confusion and further mistakes that compound the issue. Municipalities should have a documented incident response plan that clearly outlines roles, responsibilities, communication procedures and escalation paths. Regular tabletop exercises help staff practice their response, identify gaps and build confidence so they can act quickly during an actual event. Create a disaster recovery strategy An incident response plan focuses on managing the attack itself, but you also need a roadmap for restoring operations afterward. A disaster recovery plan should define recovery priorities, acceptable downtime, backup restoration procedures and contingency operations. For critical services like water and wastewater treatment, planning for operational continuity needs to be a priority. Hire outside help Many cities and towns lack the budget to hire a cybersecurity professional. External advisors can help assess security posture, identify vulnerabilities, validate compliance with security frameworks, implement monitoring solutions and support remediation efforts. Third-party services can provide municipalities with capabilities that are difficult or costly to maintain internally, allowing them to strengthen security without significantly expanding staff. Read more Physical penetration testing is the missing layer for stronger cybersecurity Nation-state actors are increasingly launching cyberattacks on businesses and critical infrastructure. How should your organization prepare? Smarter cybersecurity program management starts with these 3 pillars
Reach out to our team
Let’s talk about making your government agency stronger and more effective. Connect with our experienced industry advisors to share your top challenges and develop a plan to solve them.






