Skip to content
StrikeCyberStrikeCyber
Research

Cyber Security for Federal, State and Local Government

July 4, 2026Β·3 min readComplianceIndustry Briefings

Government environments present a combination that is genuinely difficult: legacy systems that cannot simply be retired, adversaries who have time and funding, citizen data that cannot be reissued, and budgets set by a political process rather than by risk.

The obligations are also more specific than in most sectors, which helps.

Who Is Attacking

State-aligned actors target government for intelligence, and they are patient in a way that criminal actors are not. An adversary willing to spend months inside an environment is a different proposition from one looking for quick monetization, and it changes what detection needs to catch.

Ransomware crews target state and local government deliberately. Municipalities, counties, court systems and school districts deliver services whose disruption creates immediate public pressure, and their security budgets are typically a fraction of a comparably sized private organization.

Hacktivists and opportunists target public-facing systems for visibility, which is lower consequence but consumes response capacity.

The route in is usually unremarkable: phishing, an exposed remote access system, or a vendor. Sophistication tends to appear after initial access rather than during it.

The Obligation Landscape

Federal agencies operate under FISMA, implementing NIST SP 800-53 controls through the Risk Management Framework, with authorization to operate granted on the basis of assessed control effectiveness and maintained through continuous monitoring. CISA binding operational directives impose compulsory action on defined timelines, and the Known Exploited Vulnerabilities catalog functions as a prioritized remediation list.

State and local agencies vary widely. Many adopt NIST CSF or 800-53 as a basis. Some states have their own statutory requirements. Grant conditions, particularly for federal funding, frequently impose security obligations that agencies discover late.

StateRAMP applies to cloud services procured by state and local government, and recognizes FedRAMP authorization.

CJIS governs criminal justice information wherever it is handled, including by contractors and cloud providers, with specific requirements for personnel screening, advanced authentication, encryption and audit. It reaches any vendor serving law enforcement.

FedRAMP applies to cloud service providers serving federal agencies, with prescriptive annual penetration testing requirements.

Where Assessments Find Problems

Active Directory attack paths. Long-established directories that have survived reorganizations and consolidations accumulate permissions, and government directories are frequently among the oldest we assess. Multiple paths from ordinary user accounts to domain administrator are the norm rather than the exception, and they rely on accumulated grants rather than missing patches. We have covered the mechanics in Active Directory attack paths.

Vendor-operated systems. Agencies operate substantial amounts of infrastructure through contractors, and those systems are consistently among the weakest assessed: patched on a different schedule, monitored by a different team, and frequently reachable from the internet.

Legacy applications as pivot points. Systems retained because a statutory function depends on them hold credentials and trust relationships useful well beyond their own purpose.

Detection weighted to the perimeter. Boundary monitoring is generally reasonable, and internal lateral movement generates far less attention, which is precisely the phase where a patient adversary operates.

Shadow infrastructure. Systems created for a program, a grant or a campaign, running past the end of the initiative that funded them. Attack surface discovery in government environments routinely finds internet-facing assets nobody currently owns.

Testing in a Government Context

Three practical considerations shape how these engagements run.

Procurement. Testing usually arrives through a contract vehicle, and the scope written into that vehicle tends to persist. Scoping conversations therefore matter more than usual, because a scope written narrowly at procurement is difficult to widen later.

Continuity of service. Agencies deliver services that citizens depend on and frequently cannot defer. Testing windows, rules of engagement and escalation paths need the same care as a healthcare or industrial environment.

Evidence for oversight. Findings feed authorization decisions, oversight bodies and in many cases public accountability. A report that maps findings to the applicable control set, whether 800-53, CSF or CJIS, is substantially more useful than one organized only by technical severity.

For Vendors Serving Government

If you sell software or services to government, their obligations become your requirements through contract flow-down.

The pattern that causes difficulty is a company that wins a government contract and then discovers the security requirements attached to it: FedRAMP or StateRAMP authorization, CJIS compliance, CMMC certification for defense work, or specific control implementations. Each is a program rather than a document, and each takes quarters.

Establishing what will be required before bidding, rather than after winning, is straightforward and consistently skipped.

To discuss a government security assessment, get in touch.

Frequently asked questions

What frameworks apply to US government agencies?

Federal agencies operate under FISMA with NIST SP 800-53 controls and the Risk Management Framework, plus binding operational directives from CISA. State and local agencies vary considerably: many adopt NIST CSF or 800-53, StateRAMP applies to cloud procurement, and CJIS governs criminal justice information wherever it is handled. Grant conditions frequently impose requirements too.

What is a CISA binding operational directive?

A compulsory instruction issued by CISA to federal civilian executive branch agencies, requiring specific action within a defined timeline, such as remediating a known exploited vulnerability or removing a particular product. They are not advisory. The Known Exploited Vulnerabilities catalog they reference is also widely used voluntarily outside federal government as a practical prioritization list.

Does CJIS apply to contractors and vendors?

Yes. The CJIS Security Policy applies to any entity that accesses, processes or stores criminal justice information, including contractors and cloud providers, and includes specific requirements for personnel screening, advanced authentication, encryption and auditing. Vendors serving law enforcement customers carry these obligations directly through their agreements.

Why are state and local agencies targeted so often?

They deliver essential services with limited security budgets, hold large volumes of citizen data, and operate legacy systems that cannot easily be replaced. Ransomware crews have targeted municipalities, counties and school districts deliberately because service disruption creates immediate public pressure to resolve the situation quickly.

What is StateRAMP?

A program applying a FedRAMP-like model to cloud services procured by state and local government, providing a common security assessment so each agency does not conduct its own. It recognizes FedRAMP authorization, so providers authorized federally generally satisfy it. For vendors selling primarily to state and local government it is often the proportionate starting point.

Ready to take the offensive?

StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

(877) 657-8496Free Consultation