The first flag is human · Local government offices

Nineteen and a half days. That’s the average.

That's how long the average U.S. government office is down after a ransomware attack — not a worst case, the average. Small counties, towns, and special districts don't have the IT bench a state agency does, and attackers know it.

The threat backdrop

It isn’t a big-city problem anymore.

Ransomware against U.S. government organizations has been tracked since 2018 — and the smaller offices without a dedicated security team are consistently the ones that stay down longest. The cost isn't hypothetical; it's payroll, permitting, courts, and utility billing offline for weeks.

Government ransomware attacks, cumulative 2018–2024

Comparitech, updated Mar 2025

Between 2018 and the end of 2024, Comparitech tracked 525 individual ransomware attacks against U.S. government organizations, with downtime costs estimated at $1.09 billion. Average downtime per attack: 19.5 days.

19.5 days

average downtime per government ransomware attack, 2018–2024. The longest recorded outage ran 343 days — nearly a year offline.

Comparitech, updated Mar 18, 2025
5.3M+

individual records compromised across tracked government ransomware incidents. 2024 alone accounted for 44% of all records breached since 2018.

Comparitech, updated Mar 18, 2025
$1.09B

in estimated downtime expense across 525 attacks — funds and staff time diverted from services to recovery instead.

Comparitech, updated Mar 18, 2025
What actually goes wrong

The entry point is almost always a person.

Ransomware doesn't start with a sophisticated exploit in most small-office breaches. It starts with a phished credential, a shared password, or a vendor account nobody deprovisioned — and it spreads because nobody was watching for the behavior that came before it.

What a ransomware year costs a small office

Comparitech, U.S. government ransomware tracker
Records compromised in 2024 alone (of 2018–24 total)44%
Attacks in the worst single year on record (2019)22%
Source: Comparitech, "US Government Ransomware Attack Statistics," updated March 18, 2025.

Small offices, not just big cities

Counties, small municipalities, and special districts show up as often as major cities — they just make fewer headlines.

Downtime is the real cost, not the ransom

The $1.09B figure is downtime and recovery, not payouts. Most of it is staff time and services offline, not money paid to attackers.

The next front is unmanaged AI use

Staff pasting resident data into free AI tools to draft letters or summarize records creates a new, ungoverned exposure on top of the old one.

Who this is for

Public trust and public records, with a small IT budget and no security staff.

Local government offices

Counties, towns, and special districts

Clerks, treasurers, permitting and utility offices, small police and fire departments, and special districts handling resident records, payments, and public funds. You carry the same exposure as a larger jurisdiction — without a CISO, a security team, or a budget line for either.

Services

Three ways to work together.

Same arc every time: find the gaps, train the eyes, build the program that holds.

Start here 01 · Workshop

Before the Breach

Train the eyes

A half-day session for clerks, department heads, and IT staff — what phishing and credential-based attacks actually look like locally, and a one-page escalation path for a concern that isn't yet an incident.

From $7,000Founding rate $5,000 for the first cohorts
02 · Assessment

Program Readiness & Gap Assessment

Find the gaps

2–3 weeks: review of access controls, vendor accounts, backup posture, and public-records handling, benchmarked against what's driving the outages above, with a prioritized roadmap your budget can actually fund.

From $11,000Fixed fee · scope set before we start
03 · Retainer

Program Advisory

Build it for real

A monthly advisor for department heads and IT — tabletop exercises, policy updates, and a second set of eyes before the next budget cycle or audit.

From $6,000/mo6-month minimum
Let's talk

Wondering what a ransomware event would actually cost your office?

A 20-minute call, no pitch. Tell us where you're exposed and what your next insurance renewal requires — we'll tell you honestly where we'd start.

Book a 20-minute call