Nineteen and a half days. That’s the average.
That's how long the average U.S. government office is down after a ransomware attack — not a worst case, the average. Small counties, towns, and special districts don't have the IT bench a state agency does, and attackers know it.
It isn’t a big-city problem anymore.
Ransomware against U.S. government organizations has been tracked since 2018 — and the smaller offices without a dedicated security team are consistently the ones that stay down longest. The cost isn't hypothetical; it's payroll, permitting, courts, and utility billing offline for weeks.
Government ransomware attacks, cumulative 2018–2024
Comparitech, updated Mar 2025Between 2018 and the end of 2024, Comparitech tracked 525 individual ransomware attacks against U.S. government organizations, with downtime costs estimated at $1.09 billion. Average downtime per attack: 19.5 days.
average downtime per government ransomware attack, 2018–2024. The longest recorded outage ran 343 days — nearly a year offline.
individual records compromised across tracked government ransomware incidents. 2024 alone accounted for 44% of all records breached since 2018.
in estimated downtime expense across 525 attacks — funds and staff time diverted from services to recovery instead.
The entry point is almost always a person.
Ransomware doesn't start with a sophisticated exploit in most small-office breaches. It starts with a phished credential, a shared password, or a vendor account nobody deprovisioned — and it spreads because nobody was watching for the behavior that came before it.
What a ransomware year costs a small office
Small offices, not just big cities
Counties, small municipalities, and special districts show up as often as major cities — they just make fewer headlines.
Downtime is the real cost, not the ransom
The $1.09B figure is downtime and recovery, not payouts. Most of it is staff time and services offline, not money paid to attackers.
The next front is unmanaged AI use
Staff pasting resident data into free AI tools to draft letters or summarize records creates a new, ungoverned exposure on top of the old one.
Public trust and public records, with a small IT budget and no security staff.
Counties, towns, and special districts
Clerks, treasurers, permitting and utility offices, small police and fire departments, and special districts handling resident records, payments, and public funds. You carry the same exposure as a larger jurisdiction — without a CISO, a security team, or a budget line for either.
Three ways to work together.
Same arc every time: find the gaps, train the eyes, build the program that holds.
Before the Breach
A half-day session for clerks, department heads, and IT staff — what phishing and credential-based attacks actually look like locally, and a one-page escalation path for a concern that isn't yet an incident.
Program Readiness & Gap Assessment
2–3 weeks: review of access controls, vendor accounts, backup posture, and public-records handling, benchmarked against what's driving the outages above, with a prioritized roadmap your budget can actually fund.
Program Advisory
A monthly advisor for department heads and IT — tabletop exercises, policy updates, and a second set of eyes before the next budget cycle or audit.
Wondering what a ransomware event would actually cost your office?
A 20-minute call, no pitch. Tell us where you're exposed and what your next insurance renewal requires — we'll tell you honestly where we'd start.
Book a 20-minute call