Calling on Cyber Pros to Help Defend City Hall
A local housing authority suffered a significant financial loss – nearly a million dollars – due to attackers targeting staff email accounts to intercept wire transfers intended for an affordable housing project. The agency didn't detect the breach until after the money was stolen, but the incident spurred them to establish a robust security program. The author emphasizes a pragmatic approach to security for smaller agencies, focusing on tailored solutions and ongoing support rather than attempting to implement enterprise-level security practices.
A local housing authority experienced a substantial financial loss, losing nearly a million dollars, without triggering any alerts. Attackers gained access to a handful of staff email accounts and meticulously observed the agency's money transfer procedures over a period of two months, ultimately rerouting a wire intended for an affordable housing project. The breach went undetected until after the funds were successfully stolen. This incident highlights a critical gap in security practices among local government agencies.
The author notes that this wasn't a case of negligence, but rather a consequence of resource constraints. Many state and local organizations, including housing authorities, hold sensitive data – Social Security numbers, medical records, criminal-justice files – with a significantly smaller team dedicated to protecting it compared to larger entities. The author stresses that smaller agencies need security solutions tailored to their budgets and operational realities, rather than trying to force-fit enterprise-level security tools.
They advocate for a phased approach, starting with a risk assessment and implementing basic controls like multi-factor authentication (MFA) and incident response retainers, rather than attempting to purchase a complete, complex security package. Crucially, the author emphasizes the importance of ongoing support and maintenance – someone staying involved to retrain new hires and adjust security practices as threats evolve. They also suggest a collaborative approach, sharing anonymized findings with regional government-IT associations to benefit multiple agencies.
