handling cyber crisis in the public sector

Public Sector Cyber Crisis: How Agencies Should Prepare

A ransomware notification on a county server at two in the morning waits for nothing. Not business hours, not staffing approvals, not a chain of command still being worked out.

Agencies in that situation usually find the hard part is organizational rather than technical. Who decides what. Who talks to whom. Which systems come back first.

The window for settling any of that has narrowed. ReliaQuest’s Annual Cyber-Threat Report 2026 puts average breakout time at 34 minutes, down 29% from the previous year, with a fastest recorded move from access to lateral movement of four minutes and a fastest exfiltration of six minutes against four and a half hours in 2024. The firm attributes the shift to automation and AI, noting 80% of ransomware groups use one or both.

That reading is contested. Black Kite’s analysis argues AI has not accelerated ransomware incidents so much as lowered the barrier for less capable actors. Unit 42 reports a median time to exfiltration of two days while warning defenders to prepare for intrusions that run from compromise to exfiltration in minutes as well as ones unfolding methodically over days.

The disagreement is real, and figures in this area often measure different things. The operational conclusion survives it. A response structure that takes three hours to assemble does not function inside the fast tail of that distribution, whatever the median says. Pre-assignment stops being good practice and becomes the only thing that works.

Who Should Own Which Decisions?

A small set of named roles, written down, with named backups.

Most breakdowns during a public sector incident trace to the same cause. Nobody assigned ownership of specific decisions beforehand, so staff spends the first hours establishing authority instead of exercising it.

A workable structure assigns four:

  • Technical leadership, usually a CISO or IT director, runs containment and system recovery.
  • Agency leadership holds decisions carrying legal, financial, or policy weight, including whether to engage with attackers demanding payment.
  • Legal counsel joins early, given the reporting obligations agencies carry under state and federal breach notification rules.
  • A designated spokesperson handles public statements, coordinating with technical staff so nothing disclosed publicly tips off an attacker still inside the network.

Named backups matter as much as the primary assignments. A key person is unreachable at precisely the hours these incidents tend to begin.

Approaches to handling cyber crisis in the public sector that hold up under pressure share this trait: the authority question was answered on a calm Tuesday, not at two in the morning.

How Does Information Actually Move?

Through a standing group that meets several times daily during the acute phase.

Assigning roles solves half the problem. The quieter failure is information that exists somewhere in the organization and never reaches whoever needs it. A technical detail stalls three layers below leadership. A policy decision never reaches the team executing it.

Every core role belongs in that room or on that call. Public statements flow through a separate but connected channel, drawing on what the coordination group has confirmed rather than on partial updates passed secondhand.

Agencies that build the habit into routine operations, not only crisis response, generally find it holds when real pressure arrives. A structure used once a year under stress is a structure nobody knows how to use.

What Happens to the Agency’s Own Automated Systems?

A question most plans have not answered yet.

Public agencies increasingly run autonomous tooling. Agentic AI now handles workflows inside government agencies, and those systems hold credentials, reach across services, and keep acting while humans coordinate.

That creates two decisions worth settling in advance. What happens to agent activity during containment, and who has authority to stop it. An agent continuing to authenticate and move data through a compromised environment extends the incident while the response team is still assembling.

Recovery raises the harder version. Bringing dependent systems back while agent credentials remain unverified risks restoring the attacker’s path alongside the service. Agent traffic also breaks assumptions that older network monitoring was built around, so a quiet dashboard during recovery proves less than it once did.

Attackers have moved in the same direction. Trend Micro’s Q1 2026 public sector reporting describes agentic AI entering attack chains, with groups automating reconnaissance, vulnerability scanning, and victim prioritization, while AI-enabled government services simultaneously widen the surface being attacked.

Which Decisions Deserve Rehearsal?

The ones costly enough that making them cold invites mistakes.

Recurring decision points worth walking through in advance:

  • Taking systems offline proactively, weighing containment against disruption to services residents depend on
  • Handling a ransom demand, including who approves and under what conditions payment enters consideration at all
  • Notifying affected residents within mandated timelines while investigation details remain incomplete
  • Deciding which restored systems need executive sign-off and which technical staff can return independently
  • Engaging law enforcement and federal partners without slowing internal response
  • Suspending or restoring automated and agent-driven processes during containment

Agencies that work through these in a tabletop exercise reach a real incident with reference points established. The alternative is debating first principles while residents wait on services that remain dark.

How Should Recovery Be Sequenced?

Around public impact, decided long before an incident.

Restoring in whatever order proves technically easiest ignores what agencies owe residents. A private company might reasonably prioritize its most profitable systems. A public agency weighs which systems protect safety, which carry legal deadlines, and which serve people with the fewest alternatives when the service stays offline.

Emergency dispatch and public safety communications sit at the top. Benefits processing, court filings, and other legally time-bound systems follow closely.

Identity and access management deserves particular weight, because nearly everything else depends on it working correctly. Restoring a dependent application while the identity layer beneath it remains unverified risks handing an attacker a second entry through the very system meant to represent recovery.

Two January 2026 incidents illustrate why that layer carries so much weight. Illinois and Minnesota Departments of Human Services both suffered exposures traced to configuration failures and inadequate access controls, with the Minnesota case involving excessive internal permissions and affecting close to a million people in combined total.

Neither was a sophisticated intrusion. Both were access control problems that existed before anything went wrong, which is the argument for treating identity verification as non-negotiable during restoration rather than a step to compress when residents are pressing.

How Do You Bring in Outside Partners Without Losing Hours?

By establishing the relationships before the incident.

Few agencies manage a serious event alone. Federal cybersecurity agencies, state coordination offices, specialist incident response vendors, and sometimes neighboring jurisdictions all contribute, and each works better as an existing relationship than a cold call.

Keep current contacts for federal partners alongside a clear picture of what assistance they actually provide. Vendors familiar with public sector compliance obligations integrate faster than generalist firms meeting government reporting requirements for the first time.

Document these as a standing part of the plan and review them on a schedule. Searching for the right contact while a system is down burns exactly the hours that matter most.

How Do You Know the Structure Works?

By putting it under realistic pressure before an attacker does.

None of this survives if it lives in a binder nobody has opened. Regular tabletop exercises involving every defined role expose weaknesses cheaply, during a simulation, rather than expensively, during an incident affecting residents.

Useful exercises include the friction real incidents bring: incomplete information, competing priorities, and decisions demanding answers faster than anyone wants to give them. Run one with a compressed timeline specifically, since a plan that works over six hours may not work over forty minutes.

Black Kite’s analysis offers a useful prompt for these sessions. More than 90% of ransomware victims showed a meaningful spike in externally visible exposure shortly before being hit, and organizations with high exposure scores were dramatically more likely to suffer an incident than those with low ones. Exposure is largely knowable in advance, which makes it a reasonable thing to check between exercises rather than after an event.

One more discovery task belongs on the list. Agencies frequently run tooling nobody catalogued, since purpose-built AI tools now cover narrow tasks the general platforms handled poorly and a department can connect one without involving IT. An exercise that assumes the known inventory is complete tests the wrong environment.

FAQs

Q. What causes most coordination failures during a public sector cyber incident?

Unassigned decision authority. Staff spends early hours determining who can act rather than acting.

Q. Has AI made ransomware attacks faster?

Sources disagree. Some report sharply compressed breakout and exfiltration times attributed to automation and AI, while others argue AI mainly widened the pool of attackers. Planning for the fast case costs little either way.

Q. Which systems should come back first?

Public safety and emergency communications, then legally time-bound services, with identity and access verified before dependent systems return.

Q. Why does identity restoration come before other systems?

Nearly everything authenticates through it. Restoring an application over an unverified identity layer can hand an attacker a route back in.

Q. What should agencies do about their own AI systems during an incident?

Decide in advance who can suspend automated activity, and verify agent credentials before those processes resume.

Q. How often should tabletop exercises run?

On a consistent schedule, with the plan updated from what each one reveals. Include at least one compressed-timeline scenario.

The Bottom Line

Handling a cyber crisis well depends less on any security product than on whether roles, communication paths, decision authority, and recovery order were settled before the event.

What changed is the margin. Whether or not AI is compressing attack timelines across the board, the fast end of the range now runs in minutes, and agency environments contain autonomous systems that keep operating while people coordinate.

Agencies that define the structure early, rehearse it against realistic friction, and build outside relationships ahead of need protect the services communities rely on. The alternative is learning where the gaps are while residents wait.

Related: 5 AI Cyber Threats Most People Still Underestimate

Tags: