Preprint
Article

This version is not peer-reviewed.

Budgetary Impact of Cyber Attacks on Local Governments

Submitted:

22 June 2026

Posted:

24 June 2026

You are already at the latest version

Abstract
Local governments increasingly rely on digital infrastructure to deliver public services, yet research on their financial response to cyberattacks remains limited. This study introduces the Cyber-Incident Budget Response (CIBR), capturing IT and cybersecurity budget adjustments following an attack, and examines whether such responses reflect strategic planning or reactive decision-making grounded in Threat Rigidity Theory. Budget data spanning fiscal years 2015–2022 were collected for 57 U.S. local governments victimized by ransomware in 2019 and 57 matched non-victim governments. A robust regression (MM-estimation) tested the relationship between attack occurrence and budgetary response, controlling for population, income, and racial diversity, with income as a moderator. Results show a significant positive relationship between cyberattack occurrence and budgetary response, confirming the existence of a CIBR. Racial diversity was independently associated with stronger responses, and the attack-income interaction was significant and negative, indicating the budgetary impact diminishes as income rises. Findings suggest local government cybersecurity spending is often reactive rather than strategically planned, with recovery costs falling disproportionately on lower-income jurisdictions. The study offers a novel framework for examining post-incident fiscal behavior and implications for equitable cybersecurity policy.
Keywords: 
;  ;  ;  ;  ;  ;  

1. Introduction

Local governments in the United States have increasingly adopted internet-enabled technology to enhance public service delivery, offering more efficient and accessible solutions for constituents. However, this shift toward digital operations has also made these governments more vulnerable to cyberattacks. Cybercriminals frequently target local governments—often through ransomware and other malicious strategies—making cybersecurity a critical issue (Neshenko et al., 2020). Despite the growing threat landscape, research on how local governments respond to these incidents, particularly in terms of budgetary adjustments, remains limited (Norris et al., 2019). Cybersecurity preparedness within the public sector has lagged behind, and there is little understanding of the financial measures taken by local governments to mitigate the effects of cyberattacks.
This study seeks to address this gap by investigating how local governments respond financially to cyberattacks, introducing the concept of a Cyber-Incident Budget Response (CIBR). CIBR refers to the adjustments made to IT and cybersecurity budgets following a cyber incident, representing a reactive financial response to a disruptive event. While much of the existing literature focuses on the technical aspects of cyberattacks, the financial and decision-making processes remain underexplored. Understanding these budgetary responses is crucial for developing more strategic and effective approaches to local government cybersecurity.
Threat Rigidity Theory (TRT) serves as the theoretical foundation for this study. According to TRT, organizations under threat often exhibit rigid decision-making, reinforcing existing practices and focusing on short-term, defensive responses rather than embracing innovative or flexible solutions (Staw, Sandelands, & Dutton, 1981). In the context of local governments, a cyberattack can trigger such rigid financial decision-making, leading to an immediate but reactive increase in IT budgets as leaders seek to regain control and restore stability. However, this response may not always be sufficient—or even appropriate—for long-term cybersecurity improvement.
In some cases, the rigid, reactive increase in IT budgets may not represent the most strategic or effective allocation of cybersecurity resources. Public leaders, under pressure to act, may implement budgetary changes that have not been fully assessed against actual organizational needs, potentially resulting in a response that addresses the appearance of action more than the underlying cybersecurity issues. This raises questions about how public resources are evaluated and allocated following a cyberattack. As budgets are reflexively increased without a thorough assessment of actual needs or strategic goals, such actions may reflect reactionary behavior rather than a thoughtful, measured response to the incident (Wirtz & Weyerer, 2017; Norris et al., 2019). Research supports this, as many organizations have been found to recover from cyberattacks without the need for substantial financial outlays due to proactive measures such as robust incident response strategies and cyber resilience (Catota et al., 2018; Choi et al., 2023; Perrett & Wilson, 2023). Moreover, studies have shown that financial responses to cyber incidents are not always correlated with the severity of the attack, and increased spending may not result in meaningful improvements in cybersecurity (Lagazio et al., 2014; Soikkeli et al., 2023). This further emphasizes that reflexive financial actions, taken without strategic planning, can lead to inefficient use of public resources.
Statement of the Problem
Cybersecurity research is significantly lacking in the field of Public Affairs, particularly in understanding how local governments manage cybersecurity issues and respond to cyberattacks. Despite the growing frequency of cyberattacks targeting local governments, very little is known about the budgetary and strategic responses of these entities in the wake of such incidents. To address this gap, the following two research questions are proposed:
Is there evidence of a Cyber-Incident Budget Response as a result of a cyberattack against a local government?
What does the analysis of the data suggest about the necessity of the CIBR for each local government victim?
This study aims to answer these questions by analyzing the financial behavior of local governments following cyberattacks and exploring whether these responses reflect strategic, proactive measures or reactionary, inefficient uses of public funds.
Review of Relevant Literature
This literature review focuses on local government responses to cyber incidents, with particular emphasis on budgetary and financial aspects. It synthesizes current research on cybersecurity finance and budgeting in local governments, drawing from social sciences, computer sciences, and Business Computer Information Systems (BCIS) literature. A striking observation is the paucity of research on local government cybersecurity in the public affairs field, particularly regarding budgetary responses to cyber incidents (Norris et al., 2019). This gap is concerning given the increasing frequency and sophistication of cyberattacks targeting local governments. The limited existing research has primarily focused on the general status of cybersecurity operations and funding issues (Kesan & Zhang, 2019; Norris et al., 2021; Wolff & Lehr, 2018). This scarcity of research presents significant challenges for policymakers and public administrators seeking to develop effective cybersecurity strategies and allocate resources efficiently. The lack of research also hampers local governments’ ability to learn from each other’s experiences and adapt successful budgetary strategies in response to cyber incidents. As Norris et al. (2021) point out, this knowledge gap is particularly problematic given the unique challenges faced by local governments, which often have limited resources and expertise compared to their state and federal counterparts. Adding to these challenges, local governments face the unique task of balancing the protection of sensitive information with the transparency demands of public service (MacManus et al., 2012). This balancing act requires not only technical solutions but also careful policy considerations and public communication strategies, further complicating cybersecurity efforts in the public sector. The need to maintain public trust while safeguarding against cyber threats adds another layer of complexity to local government cybersecurity budgeting and strategy.
Another prominent theme in the literature is the issue of insufficient funding for cybersecurity improvements in local governments. The United States Multi-State Information Sharing and Analysis Center (MS-ISAC) survey reported that local governments struggle with a lack of resources and support, encompassing not only funding but also expertise and technological capabilities (Wolff & Lehr, 2018). This multifaceted nature of resource constraints suggests that addressing cybersecurity challenges requires a holistic approach beyond simply increasing budget allocations. The relationship between funding and cybersecurity readiness is complex and often counterintuitive. Herath et al. (2020) found that spending and cost had an insignificant association with organizational cybersecurity readiness, suggesting that merely increasing financial resources may not suffice to improve cybersecurity posture. This finding challenges the common assumption that more spending automatically leads to better security outcomes. It raises important questions about the efficacy of current spending patterns and the need for more strategic allocation of resources in local government cybersecurity efforts.
Conversely, Kesan and Zhang (2019) demonstrated a negative correlation between IT spending and cyber-attack losses in local governments, supporting the notion that increased investment can lead to reduced damages. Their study suggests that while the relationship between spending and outcomes isn’t straightforward, there is evidence that strategic investments can yield positive results in terms of mitigating cyber risks. This discrepancy highlights the complexity of the relationship between funding and cybersecurity outcomes, suggesting that the effectiveness of financial investments may depend on various contextual factors and how the resources are utilized. It underscores the need for local governments to not only secure adequate funding but also to develop strategies for optimal resource allocation and utilization. The issue of resource allocation is further complicated by competing priorities in local governments, where cybersecurity often vies for funding against other critical municipal services such as infrastructure maintenance, public safety, and education. This competition can lead to underinvestment in cybersecurity, potentially leaving local governments vulnerable to attacks and unprepared for the financial implications of cyber incidents. Balancing these competing needs require careful consideration and strategic planning from local government leaders and policymakers. Research has shown that the financial implications of cyber-attacks extend beyond immediate recovery costs, encompassing a range of direct and indirect expenses. Choi (2023) found that organizations with well-prepared incident response capabilities can often recover from cyber incidents without incurring significant additional costs. This finding highlights the potential return on investment for proactive cybersecurity measures and incident response planning. However, local governments may face long-term financial consequences that are not immediately apparent. These can include increased insurance premiums, potential legal liabilities, and costs associated with rebuilding public trust. Additionally, the opportunity costs associated with diverting resources to cybersecurity recovery efforts can be substantial, potentially impacting other critical government functions and services.
Choi et al. (2023) research implies that even when organizations do incur costs in responding to cyberattacks, their expenditures are typically only marginally higher than what comparable organizations spend in the absence of an attack. This finding underscores the importance of proactive investments in cybersecurity infrastructure, which not only enhance an organization’s resilience but also lead to more efficient recovery processes and reduced overall costs in the event of an incident. The financial impact of cyber incidents can also vary significantly based on the size and resources of the local government. Smaller municipalities and rural governments often face disproportionate challenges in absorbing the costs of cyber incidents, given their more limited budgets and resources. This disparity in impact and recovery capability among different types of local governments is an area that warrants further research and consideration in policymaking.
Emerging research suggests that strategic approaches to cybersecurity budgeting can significantly influence outcomes and cost-effectiveness. Lagazio et al. (2014) found that in the financial sector, costs incurred by organizations are often influenced more by their strategic responses to cyber threats than by the frequency or severity of attacks. This suggests that adopting a proactive and strategic approach to cybersecurity budgeting may lead to lower financial impacts from incidents. For local governments, this finding underscores the importance of developing comprehensive cybersecurity strategies that go beyond reactive measures. Such strategies might include regular risk assessments, threat intelligence gathering, and the development of scenario-based response plans. By anticipating potential threats and preparing for various contingencies, local governments can potentially reduce the impact of cyber attacks and minimize the need for large, unexpected expenditures in the aftermath of incidents.
Soikkeli et al. (2023) demonstrated that implementing redundancy planning can enhance resilience against cyber-attacks without necessitating significant financial expenditures. This might involve maintaining offline backups, establishing alternative communication channels, and cross-training staff. These measures can help ensure continuity of government operations even in the face of significant cyber disruptions, potentially reducing the financial impact of such incidents.
Resource optimization plays a crucial role in enhancing cybersecurity without substantial spending increases. Strategies might include leveraging cloud services, implementing automation tools, and participating in information-sharing networks to benefit from collective threat intelligence. These approaches can help local governments maximize the impact of their cybersecurity budgets, which is particularly crucial given the often-limited resources available.
Qasaimeh et al. (2022) highlighted the importance of advanced security testing and cyber-attack forecasting models in helping organizations identify vulnerabilities and respond to threats proactively. For local governments, implementing such practices could involve regular penetration testing, vulnerability assessments, and red team exercises. Additionally, the use of predictive analytics and machine learning algorithms to forecast potential cyber threats could enable local governments to allocate resources more efficiently and prepare for emerging risks.
The concept of cyber resilience, as discussed by Perrett and Wilson (2023), emphasizes not only protection against attacks but also the ability to recover swiftly and effectively. This holistic approach to cybersecurity can help organizations minimize financial impacts and operational disruptions in the face of cyber incidents. For local governments, building cyber resilience may involve developing redundant systems, implementing robust data backup and recovery processes, and fostering a culture of continuous improvement and adaptation in the face of evolving threats.
While much of the literature focuses on technical and financial aspects of cybersecurity, the role of human factors and organizational culture in shaping cybersecurity outcomes is increasingly recognized. Hirshfield et al. (2015) emphasized the importance of human operators’ suspicion in detecting cyber-attacks, highlighting the critical role that employee training and awareness programs play in enhancing an organization’s defensive posture against cyber threats.
Developing a strong organizational culture around cybersecurity can often be achieved through non-financial strategies such as employee training and awareness programs. These initiatives can significantly contribute to an organization’s cyber resilience without necessitating substantial financial investments (Papuashvili, 2023). For local governments, fostering a culture of cybersecurity awareness could involve regular training sessions, simulated phishing exercises, and clear communication of security policies and best practices. The human element in cybersecurity also extends to leadership and decision-making processes. Research has shown that the commitment of top management to cybersecurity initiatives can significantly influence an organization’s overall security posture. In the context of local governments, this suggests that elected officials and senior administrators play a crucial role in prioritizing cybersecurity and allocating necessary resources.
Despite a growing body of research in general government cybersecurity, significant gaps persist in the literature specific to local government cybersecurity, particularly regarding financial phenomena in response to cyber incidents. These gaps span several key areas, each contributing to our limited understanding of how local governments manage cybersecurity challenges from a financial perspective. A primary gap exists in studies focused on how local governments adjust their budgets in response to specific cyber-attacks. Most existing research concentrates on general cybersecurity spending rather than incident-specific responses. This lack of granular insight hinders the development of evidence-based strategies for financial response and recovery in the aftermath of cyber incidents. Understanding the immediate budgetary adjustments made by local governments during and after attacks is crucial for developing effective response protocols.
Compounding this issue is the scarcity of longitudinal studies examining the long-term financial implications of cyber incidents. This gap extends to research on the effectiveness of various budgetary strategies in local government contexts over time. Such studies could provide valuable insights into the sustainability of various cybersecurity approaches and their impact on organizational resilience. Without this long-term perspective, local governments may struggle to justify and allocate resources for cybersecurity in a way that balances immediate needs with long-term security goals.
The literature also reveals a significant gap in understanding the unique challenges faced by small and rural local governments in financing cybersecurity measures and responding to incidents. These entities often face more severe resource constraints and may lack access to specialized expertise, necessitating tailored approaches to cybersecurity. However, the current body of research has not sufficiently explored these specific contexts, potentially leaving smaller municipalities vulnerable and underserved in terms of cybersecurity strategies and resources.
Another understudied area is the effectiveness of inter-governmental collaboration and resource sharing in improving cybersecurity posture and reducing individual local government costs. While some collaborative initiatives exist, their impact and the best practices for implementing such efforts are not well documented in the academic literature. This gap is particularly significant given the potential for resource optimization and knowledge sharing that such collaborations could offer, especially for smaller or resource-constrained local governments.
While existing studies indicate that a proactive and strategic approach to cybersecurity budgeting, coupled with efficient resource utilization and comprehensive incident response planning, may be effective, there’s a lack of comprehensive research on how these strategies are implemented in local government contexts. The relationship between strategic planning, resource allocation, and cybersecurity outcomes in local governments remains poorly understood. This gap in knowledge makes it challenging for local governments to develop and implement effective, data-driven cybersecurity strategies.
These interconnected gaps in the literature significantly impact our understanding of local government budgetary responses to cyber incidents. The lack of comprehensive research in these areas leaves local governments without clear guidance on how to allocate resources effectively, respond to incidents efficiently, and plan for long-term cybersecurity resilience. Addressing these research gaps is crucial for developing more effective, tailored, and sustainable cybersecurity strategies for local governments of all sizes and resource levels. As cyber threats continue to evolve and target local governments, filling these knowledge gaps becomes increasingly urgent to ensure the security and stability of local government operations and services.
This study aims to contribute to the knowledge on local government cybersecurity by examining the existence and nature of budgetary responses to cyber incidents. To guide this investigation, two hypotheses have been formulated:
A Cyber-Incident Budget Response (CIBR) does occur as a result of a local government entity responding to and recovering from a cyber-incident.
The magnitude of CIBR varies systematically with income level rather than being uniformly explained by attack occurrence alone.
These hypotheses address both the existence of CIBR and its potential necessity. By testing them, this study aims to provide empirical evidence on the financial behavior of local governments facing cyber threats, contributing to the identified gaps in the literature and offering insights for policymakers and cybersecurity professionals.

2. Materials and Methods

A quantitative approach was elected to guide the collection and interpretation of data related to this study. Seculore Solutions offers a publicly available online cyber attack archive that separates the attack targets by industry, with “government” listed separately from other types of organizations (Seculore, 2021). A total of five years of data is present for all 50 states and their respective local government entities (Seculore, 2021). It was decided that results would be collected for the most prolific year of cyber-attacks experienced by local governments in the United States to date. According to an article by Lohrmann (2019), the year 2019 has represented the highest number of cyber-attacks against local governments than any previous year. This same information is echoed by Bischoff (2021) and indicates that ransomware was the most used attack against local governments in 2019. A total of 65 local government “victims” were identified on the Seculore database.
Data Collection
To ensure a standardized process of data collection, definitions were determined for the term “local government” and the criteria for what qualified as a ransomware cyber-attack. Local government was defined as previously mentioned in the literature review as: municipal, county, district, parish, tribal, or other such governments below the state, regional, or federal level. A ransomware cyber-attack would be used to describe a computer exploit by a threat actor with the intent of making data or other local government critical resources inaccessible for use until the payment of a ransom was made in exchange for release. Regardless, if the threat actor was successful with their exploit, the mere attempt qualified as a cyber-attack to be examined for a response. This perspective of the definition of cyber-attack takes into account that cybersecurity in an organization of any type is a multi-layered effort of technology, people, and processes (Stambul & Razali, 2011). If any layer is able to prevent a cyber-attack from completing its intent, then the organization’s cybersecurity is effective but will still require maintenance to return to pre-attack level (Cotenescu, 2016).
As part of the initial data collection process, local government budgets for fiscal years 2015 through 2022 were collected. During this collection eight local government victims did not have their budget information available online. These local governments were contacted, but no response was received; thus, they were removed from further use for this study. These local governments are identified in Table 1. This left the number of local government victims to 57.
For comparison, information was collected on 57 local governments who were not attacked by ransomware during the year 2019. It was determined these local governments should be required to be comparable to the victims by having no more than a 10% variation in population and regionally located so as to share similarities in culture, geography, socio-economics, and education experience. A National Geographic regionally divided map of the United States was used, that appeared to meet the comparison criteria for this study. As can be seen in Figure 1, the map designed by the National Geographic Society divides the United States into distinct regions based on geographic, cultural, economic, historical and environmental factors (ASA, BEA, 2024; EPA, 2024; LOC, 2024; NCGE, 2024; NGS, 2024).
These regions are widely used in educational curricula and research to facilitate the understanding of the diverse characteristics and issues within the United States (NCGE, 2024; NGS, 2024).
Using the regional map as a guide, a process of nearest-neighbor matching was employed to identify non-victim comparison local governments that were similar in type (municipal, county, or parish), located within the same regional area, and deviated by no more than 10% in population size. This matching process continued until each of the 57 local government victims was paired with a comparable non-victim local government within the same regional area. To ensure uniformity and reliability, population data was sourced from the United States Census Bureau for the year 2020, the closest available data to the 2019 attack year. Additionally, demographic variables, including the racial diversity percentage and median income of the population, were also collected alongside population data. Research presented in the literature review highlighted how population size can influence a local government’s cybersecurity posture, as larger governments often have more resources to implement cybersecurity measures than smaller ones. Additionally, financial resources available to local governments, which can vary based on the wealth of the population, are another important factor. The population’s median income serves as an indirect indicator of the financial capacity of a local government, as local tax revenue often depends on the income levels of residents (Maria et al., 2021). Wealthier populations typically contribute more tax revenue, giving local governments greater financial flexibility to address cyber incidents and fund operations (Wu, 2023).
Racial diversity was also introduced as a control variable to examine whether the racial composition of the population had any influence on the financial or budgetary response to cyber incidents. The decision to include racial diversity as a control is based on economic research showing that racial and ethnic diversity can impact public spending and policy decisions (Hopkins, 2009). Racial diversity can affect consensus on public goods provision, which may, in turn, influence how resources are allocated (Trounstine, 2016). Additionally, racial segregation and diversity can lead to inequalities in public goods distribution, further supporting the hypothesis that racial diversity might affect local government responses to crises (Alesina et al., 1999; Hero & Tolbert, 1996; Moscou et al., 2023). Therefore, it was reasonable to assume that racial diversity could be a factor influencing the financial response to cyber incidents.
Data Set Creation and Analysis
Annual budget information for each local government in the dataset, including both victim and comparison groups, was collected from their respective official government websites where financial records are maintained. These local governments are listed in Appendix B for reference. The initial review of the budgets focused on identifying how changes in cybersecurity spending could be tracked. It was discovered that cybersecurity financing was typically found within the budget allocations for each entity’s IT department. In cases where a specific IT department did not exist, the entity’s budget contained a line item explicitly identified for IT expenditures.
This budget information was meticulously analyzed to identify trending changes across fiscal years. The analysis examined the amount budgeted for each fiscal year, the amount actually spent, and any increases or decreases in budget allocation throughout the fiscal year progression. Utilizing this trending data, the dataset was completed with the Cyber-Incident Budget Response (CIBR) calculated as its own category column for each year of each local government’s budget. Additionally, a new column called “Total CIBR” was created for each local government to provide a comprehensive measure of budgetary response over time.
The Total CIBR column combined three key percentage differences: the difference between allocated and actual spending in the 2019 fiscal year, the difference in budget allocation between the 2019 and 2020 fiscal years, and the difference between allocated and actual spending for the 2020 fiscal year. These three percentages were summed to calculate the final Total CIBR value for each local government, offering a holistic view of budgetary changes in response to cyber incidents across the studied period. This composite measure was constructed to capture two distinct dimensions of budgetary response: within-year execution variance (the gap between what was allocated and what was actually spent) and across-year planning shifts (the change in allocation from one fiscal year to the next). Summing these dimensions allows Total CIBR to reflect both immediate spending adjustments made during the attack year and the longer-term budgetary recalibration that followed, providing a more complete picture of fiscal response than either dimension alone.
The dataset was analyzed using RStudio, complemented by several specialized R packages to enhance analytical capabilities. These packages, detailed in Appendix A, encompass tools for data manipulation, visualization, robust statistical analysis, regression diagnostics and presentation, and data import. Notably, the analysis utilized dplyr for data manipulation, ggplot2 for visualization, car, lmtest, MASS, and robustbase for robust statistical analysis, jtools and stargazer for regression diagnostics and presentation, and readxl for data import. This comprehensive toolkit enabled efficient data handling and advanced modeling techniques, providing a robust foundation for our statistical analysis.
Next, the linear regression equation was formulated for this study, where the dependent variable (DV), identified as CIBR, is represented in the regression equation as BR. The primary independent variable (IV) was identified as ATTACK, a binary variable where 1 indicates the occurrence of a cyber-attack and 0 indicates no cyber-attack for each local government. Additional variables were included in the regression equation and adjusted for inherent skewness of the data. The moderator variable log_INCOME (log-transformed median income of the local government population) was included to examine whether the median income moderates the relationship between cyber-attacks and budgetary response. The interaction term ATTACK * log_INCOME was introduced to test whether the effect of a cyber-attack on the budgetary response depends on the level of income. This interaction term allows the model to determine if the impact of a cyber-attack on budgetary response varies depending on income levels, showing whether higher or lower income strengthens or weakens the effect of the attack on budgetary adjustments.
Two control variables were also included in the model: log_POP (log-transformed population size), which controls for differences in local government population size that could influence budgetary responses, and RacDivPct (racial diversity percentage of the population), which accounts for potential variations in responses due to the racial diversity of the local government’s population. Lastly, a robust regression algorithm (MM-estimation) was used to mitigate the influence of outliers on the regression results; thus the regression equation is:
Y(BR) = b0 + b1x(ATTACK) + b2X(log(INCOME)) + b3x(log(POP)) + b4x(RacDivPct) + b5x(ATTACK x log(INCOME))
This regression model integrates the effects of ATTACK, log_INCOME, log_POP, and RacDivPct, along with the interaction between ATTACK and log_INCOME to explore whether the relationship between cyber-attacks and budgetary response is moderated by income. By applying a robust regression approach, the model accounts for potential outliers, ensuring more accurate and reliable estimates of the variables’ effects on the budgetary response.

3. Results

The initial statistical analysis involved reviewing a summary of the dependent variable (DV) and independent variables (IV) of the local governments who had experienced a cyber attack and can be seen in Table 2. For comparison, another summary of the DV and IV of local governments was performed but concentrated on those who had not experienced a cyber attack and were used as a comparison with the victim local governments. Table 3 shows the output of this information. When comparing the data from the two tables, it can be noted that the average population (POP) data from both tables fall within the range of a medium-size urban area, as classified by the National Center for Education Statistics (2023). Also, when examining the percentage difference between the mean population totals for each table, a two percent difference is noted, keeping well within the 10% criteria established for comparison of victim versus non-victim local governments. Both of these determinants support the collective data as fairly comparable with one another for analysis.
Another fact that is also immediately noticeable is the difference in the mean values for the BR variable in both tables. This value indicates that the BR mean for those local governments that did experience a cyber-attack was 16 percentage points higher than the non-victim local governments used for comparison. This suggests a probable significant finding with regard to the BR variable in this study. The last finding to note from the comparative summary analysis is the difference in mean values for the variable INCOME. This information clearly shows a 7.6% difference in the mean value of INCOME, with the higher being associated with non-victim local governments. This finding suggests that socioeconomic factors, such as income, may influence the likelihood of a local government being targeted by cyberattacks.
Table 3 and Table 4 presents the robust regression results for the specified model examining the relationship between the dependent variable (BR) and selected independent variables. The analysis identifies statistically significant relationships for ATTACK, RacDivPct, and the interaction term ATTACK:log_INCOME, while log_INCOME and log_POP do not demonstrate significance, failing to reject the null hypothesis. The coefficient for ATTACK is positive and statistically significant at the 5% level, indicating that the occurrence of a cyber-attack is associated with an increase in budgetary response (BR). This supports the interpretation that local governments allocate additional financial resources in response to cyber incidents. Similarly, RacDivPct shows a positive and significant association with BR, suggesting that higher racial diversity in a jurisdiction may be linked to stronger fiscal responses, potentially reflecting policy or equity-driven considerations. Notably, the interaction term ATTACK:log_INCOME is negative and statistically significant. This suggests a moderating effect in which the budgetary impact of a cyber-attack decreases as the jurisdiction’s median income increases. Higher-income jurisdictions may have more resilient infrastructures or pre-established resources, reducing the need for reactive fiscal adjustments. The coefficient of determination (R2) is 0.210, and the adjusted R2 is 0.174. Although not a direct measure of explained variance, adjusted R2 provides an approximation of model fit. In social science research, where models often contend with unobserved heterogeneity, an adjusted R2 above 0.3 is generally considered strong, but values around 0.2–0.3 are still acceptable for models explaining complex phenomena. Table 4 integrates both the robust regression coefficients and their 95% confidence intervals. Confidence intervals that do not include zero reinforce the significance of the corresponding coefficients and the stability of these findings.

4. Discussion

The findings of this study provide a comprehensive view of how local governments respond financially to cyberattacks, offering new insights into the complex dynamics of public administration and cybersecurity management. By focusing on the Cyber-Incident Budget Response (CIBR), the study identifies clear evidence of financial adjustments that local governments make following cyberattacks. These results underscore the significant role of financial decision-making in mitigating the impact of cyber incidents and highlight several nuanced relationships between socio-demographic factors and budgetary responses. The robust regression analysis revealed a statistically significant relationship between the occurrence of a cyberattack (ATTACK) and the budgetary response (BR), validating the existence of a CIBR. This finding demonstrates that local governments often respond to cyber incidents by increasing budgetary allocations to their IT and cybersecurity functions. These reactive adjustments, while necessary to address immediate vulnerabilities, suggest that local governments are primarily engaging in crisis management rather than proactive planning. The data further show that the interaction between ATTACK and log-transformed income (ATTACK:log_INCOME) is negative and significant, indicating that higher-income jurisdictions experience a less pronounced budgetary response to cyberattacks. This moderating effect points to an unequal burden of financial strain, where lower-income local governments are forced to reallocate limited resources in response to cybersecurity threats. The relationship between racial diversity (RacDivPct) and budgetary response emerged as a significant and unexpected finding. The positive correlation between RacDivPct and BR suggests that communities with higher racial diversity tend to allocate greater financial resources in response to cyberattacks. The mechanism underlying this relationship cannot be determined from the present data and warrants dedicated future research. Understanding this pattern is nonetheless relevant for developing equitable and effective cybersecurity policies.
The validation of the regression results through confidence interval analysis further strengthens the study’s conclusions. Confidence intervals for significant variables, such as ATTACK, RacDivPct, and the interaction term ATTACK:log_INCOME, excluded zero, confirming the robustness of the findings. This validation adds to the credibility of the model and its ability to capture meaningful relationships between cyber incidents, demographic factors, and financial responses. The methodological rigor employed in this study ensures that the findings are not only statistically significant but also reliable and replicable, providing a solid foundation for future research and practical applications.
The implications of these findings extend beyond the immediate context of cybersecurity management. They highlight the challenges faced by local governments in balancing reactive and proactive approaches to cybersecurity. While increased budgetary allocations in response to cyberattacks are necessary to address vulnerabilities, they often come at the expense of other priorities, particularly in resource-constrained jurisdictions. This reactive approach underscores the need for local governments to adopt more strategic planning frameworks that emphasize prevention and resilience. By investing in robust cybersecurity infrastructures and protocols before attacks occur, local governments can reduce the need for crisis-driven financial adjustments and enhance their long-term security posture. At the same time, the study’s findings highlight significant disparities in the capacity of local governments to respond to cyber incidents. The moderating effect of income on the CIBR underscores the unequal financial burden faced by lower-income jurisdictions, which may lack the resources to implement comprehensive cybersecurity measures. Addressing these disparities requires targeted support from higher levels of government, including federal funding initiatives and regional collaborations that provide financial and technical assistance to resource-constrained local governments. Such efforts are essential to ensure that all jurisdictions, regardless of income level, are equipped to manage the growing threat of cyberattacks effectively.
The significant relationship between racial diversity and budgetary response adds a new dimension to the discourse on cybersecurity management in public administration. This finding suggests that socio-demographic factors play an important role in shaping financial priorities and decision-making processes. Understanding these dynamics is critical for developing policies that are responsive to the needs of diverse communities. Further research is needed to explore whether similar patterns are observed in other contexts and to identify the underlying mechanisms driving this relationship. By integrating socio-demographic considerations into cybersecurity strategies, policymakers can create more inclusive and equitable approaches to managing cyber risks.

5. Conclusions

This study provides compelling evidence of the Cyber-Incident Budget Response in local governments, demonstrating the significant financial adjustments made in response to cyberattacks. The findings highlight the reactive nature of many local government responses, with increased budgetary allocations serving as a primary strategy for addressing immediate vulnerabilities. While these adjustments are necessary to recover from cyber incidents and prevent future attacks, they also reflect the challenges of managing cybersecurity in a resource-constrained environment. The study’s results have important implications for public administration and cybersecurity management. The evidence of a CIBR underscores the need for local governments to move beyond reactive approaches and adopt more proactive strategies that emphasize prevention, resilience, and long-term planning. At the same time, the moderating effect of income on the CIBR highlights significant disparities in the capacity of local governments to respond to cyberattacks. Addressing these disparities requires targeted support and investment to ensure that all jurisdictions are adequately equipped to manage cybersecurity risks. The relationship between racial diversity and budgetary response offers new insights into the socio-demographic dynamics of public administration. This finding raises important questions about how community composition influences financial decision-making and resource allocation. Understanding these dynamics is critical for developing policies that are responsive to the needs of diverse populations and for ensuring that cybersecurity strategies are equitable and effective.
While this study provides valuable insights, it also underscores the need for further research. Longitudinal studies could examine the long-term impacts of budgetary adjustments on cybersecurity outcomes, providing a more comprehensive understanding of how local governments adapt to evolving threats. Qualitative research exploring the decision-making processes behind budgetary responses would complement these quantitative findings, offering deeper insights into the cognitive and organizational factors driving financial decisions.
Additionally, the significant and unexpected relationship between racial diversity and budgetary response deserves focused future research. This association, though statistically robust, remains conceptually unclear. Future studies should explore whether this pattern holds across different policy areas or regions, and what underlying social, institutional, or political mechanisms might explain the connection. This topic offers a promising foundation for a standalone study that investigates how demographic diversity influences public resource allocation, particularly in the context of cybersecurity and crisis response.
As cyber threats continue to grow in frequency and sophistication, the insights gained from this study will be essential for guiding policy development and enhancing the resilience of local governments. By bridging the gap between academic research and practical application, this study contributes to the ongoing efforts to create more secure, equitable, and effective public administration practices in the digital age.

Supplementary Materials

None.

Author Contributions

Sole Authored paper.

Funding

This research received no external funding.

Data Availability Statement

RStudio Dataset located at: DOI: 10.13140/RG.2.2.23866.35526.

References

  1. Neshenko, N.; Nader, C.; Bou-Harb, E.; Furht, B. A survey of methods supporting cyber situational awareness in the context of smart cities. J. Big Data 2020, 7(92), 1–41. [Google Scholar] [CrossRef]
  2. Norris, D.; Mateczun, L.; Joshi, A. Cyberattacks at the grass roots: American local governments and the need for high levels of cybersecurity. Public Adm. Rev. 2019, 79(6), 895–904. [Google Scholar] [CrossRef]
  3. Staw, B.; Sandelands, L.; Dutton, J. Threat rigidity effects in organizational behavior: A multilevel analysis. Adm. Sci. Q. 1981, 26(4), 501–524. [Google Scholar] [CrossRef]
  4. Wirtz, B.; Weyerer, J. Cyberterrorism and cyber attacks in the public sector: How public administration copes with digital threats. Int. J. Public Adm. 2017, 40(13), 1085–1100. [Google Scholar] [CrossRef]
  5. Lagazio, M.; Sherif, N.; Cushman, M. A multi-level approach to understanding the impact of cyber crime on the financial sector. Comput. Secur. 2014, 45, 58–74. [Google Scholar] [CrossRef]
  6. Soikkeli, J.; Casale, G.; Munoz-Gonzalez, L.; Lupu, E. Redundancy planning for cost efficient resilience to cyber attacks. IEEE Trans. Dependable Secur. Comput. 2023, 20(2), 1154–1168. [Google Scholar] [CrossRef]
  7. Kesan, J.; Zhang, L. An empirical investigation of the relationship between local government budgets, IT expenditures, and cyber losses. IEEE Trans. Emerg. Top. Comput. 2019, 9(2), 582–596. [Google Scholar] [CrossRef]
  8. Norris, D.; Mateczun, L.; Joshi, A.; Finin, T. Managing cybersecurity at the grassroots: Evidence from the first nationwide survey of local government cybersecurity. J. Urban Aff. 2021, 43(8), 1173–1195. [Google Scholar] [CrossRef]
  9. Wolff, J.; Lehr, W. When cyber threats loom, what can state and local governments do? Georget. J. Int. Aff. 2018, 19, 67–75. Available online: https://www.jstor.org/stable/26567528. [CrossRef]
  10. MacManus, S.; Caruson, K.; McPhee, B. Cybersecurity at the local government level: Balancing demands for transparency and privacy rights. J. Urban Aff. 2012, 35(4), 451–470. [Google Scholar] [CrossRef]
  11. Papuashvili, D. Cyber Resilience Implications for the Financial System. Bus. Adm. Res. Pap. 2023, 8(a). [Google Scholar] [CrossRef]
  12. Lohrmann, D. 2019: The year ransomware targeted state & local governments. Government Technol. Govtech.com 2019. [Google Scholar] [CrossRef]
  13. Bischoff, P. Ransomware attacks on US government organizations cost $18.9bn in 2020. Comparitech. 2021. Available online: https://www.comparitech.com/blog/information-security/government-ransomware-attacks/.
  14. Seculore Solutions; Seculore. Cyber attack archive. SECULORE SOLUTIONS. 2021. Available online: https://www.seculore.com/resources/cyber-attack-archive.
  15. Stambul, M.; Razali, R. An assessment model of information security implementation levels. In Proceedings of the 2011 International Conference on Electrical Engineering and Informatics, Bandung, 2011; pp. 1–6. [Google Scholar] [CrossRef]
  16. Cotenescu, V. People, process, and technology; A blend to increase an organization security posture. “Mircea Cel. Batran” Nav. Acad. Sci. Bull. 2016, 19(2), 394–396. [Google Scholar] [CrossRef]
  17. American Sociological Association [ASA. Cultural Sociology. 2024. Available online: https://www.asanet.org/research-and-publications/research-and-advocacy/cultural-sociology.
  18. U.S. Bureau of Economic Analysis [BEA]. Regional Economic Accounts. 2024. Available online: https://www.bea.gov/data/economic-accounts/regional.
  19. Environmental Protection Agency [EPA. Ecosystem Research. 2024. Available online: https://www.epa.gov/eco-research.
  20. Library of Congress [LOC. United States History: Primary Source Timeline. 2024. Available online: https://www.loc.gov/classroom-materials/united-states-history-primary-source-timeline/.
  21. National Council for Geographic Education [NCGE. Geography Standards. 2024. Available online: https://www.ncge.org/.
  22. National Geographic Society [NGS. United States Regions. 2024. Available online: https://education.nationalgeographic.org/resource/united-states-regions/.
  23. National Center for Education Statistics. Locale boundaries. U.S. Department of Education, Institute of Education Sciences. 2023. Available online: https://nces.ed.gov/programs/edge/Geographic/.
  24. Maria, E.; Halim, A.; Suwardi, E. Financial distress, regional independence and corruption: An empirical study in Indonesian local governments. J. Account. Strateg. Financ. 2021, 4(1), 54–70. [Google Scholar] [CrossRef]
  25. Wu, Y.; Tian, C.; Li, L. Local government debt and labor income share: evidence from china. PLoS ONE 2023, 18(10), e0293494. [Google Scholar] [CrossRef] [PubMed]
  26. Hopkins, D. The diversity discount: When increasing ethnic and racial diversity prevents tax increases. J. Politics 2009, 71(1), 160–177. [Google Scholar] [CrossRef]
  27. Trounstine, J. Segregation and inequality in public goods. Am. J. Political Sci. 2016, 60(3), 709–725. [Google Scholar] [CrossRef]
  28. Alesina, A.; Baqir, R.; Easterly, W. Public goods and ethnic divisions. Q. J. Econ. 1999, 114(4), 1243–1284. [Google Scholar] [CrossRef]
  29. Hero, R.; Tolbert, C. A racial/ethnic diversity interpretation of politics and policy in the states of the U.S. Am. J. Political Sci. 1996, 40(3), 851–871. [Google Scholar] [CrossRef]
  30. Moscou, K.; Bhagaloo, A.; Onilude, Y.; Zaman, I.; Said, A. Broken promises: Racism and access to medicines in Canada. J. Racial Ethn. Health Disparities 2023, 11(3), 1182–1198. [Google Scholar] [CrossRef] [PubMed]
Figure 1. National Geographic Society Regional Map.
Figure 1. National Geographic Society Regional Map.
Preprints 219720 g001
Table 1. Local Governments without any accessible budget information.
Table 1. Local Governments without any accessible budget information.
Village of Palm Springs, Florida.
City of Mexico Beach, Florida
New Iberia, Louisiana
Yerington Paiute Tribal government, Nevada
Edcouch, Texas
An undisclosed city, Texas (as requested by city government to public news)
Brooke County, West Virginia
Harrison County, West Virginia
(Norcross, 2023).
Table 2. Summary of Data with Variable ATTACK==1.
Table 2. Summary of Data with Variable ATTACK==1.
Variable Obs Mean Std. dev. Min Max
BR 57 20.25 52.32 -182.73 204.79
ATTACK 57 1 0 1 1
POP 57 235,116.9 386,682 4,823 2,110,640
RacDivPct 57 43.72 23.56 2 98
INCOME 57 72,677.05 29,902.86 42,000 195,648
Table 3. Summary of Data with Variable ATTACK==0.
Table 3. Summary of Data with Variable ATTACK==0.
Variable Obs Mean Std. dev. Min Max
BR 57 4.23 25.04 -54.57 94.69
ATTACK 57 0 0 0 0
POP 57 230,551.5 372,338.5 4,679 2,009,324
RacDivPct 57 37.49 21.89 2 97
INCOME 57 78,226.56 33,720.59 43,025 249,923
Table 4. Robust Regression Coefficients and 95% Confidence Intervals.
Table 4. Robust Regression Coefficients and 95% Confidence Intervals.
Predictor Coefficient (β) 95% CI p-Value
(Intercept) -30.752 [ -173.200, 111.696 ] 0.680
ATTACK 480.101 [ 100.722, 859.480 ] 0.018**
log_INCOME 2.178 [ -9.931, 14.287 ] 0.728
log_POP -0.163 [ -3.524, 3.198 ] 0.923
RacDivPct 0.287 [ 0.087, 0.487 ] 0.004***
ATTACK : log_INCOME -42.013 [ -75.504, -8.522 ] 0.015**
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.
Prerpints.org logo

Preprints.org is a free preprint server supported by MDPI in Basel, Switzerland.

Subscribe

© 2026 MDPI (Basel, Switzerland) unless otherwise stated

Accessibility

Disclaimer

Terms of Use

Privacy Policy

Privacy Settings