1. Introduction
Local governments in the United States have increasingly adopted internet-enabled technology to enhance public service delivery, offering more efficient and accessible solutions for constituents. However, this shift toward digital operations has also made these governments more vulnerable to cyberattacks. Cybercriminals frequently target local governments—often through ransomware and other malicious strategies—making cybersecurity a critical issue (Neshenko et al., 2020). Despite the growing threat landscape, research on how local governments respond to these incidents, particularly in terms of budgetary adjustments, remains limited (Norris et al., 2019). Cybersecurity preparedness within the public sector has lagged behind, and there is little understanding of the financial measures taken by local governments to mitigate the effects of cyberattacks.
This study seeks to address this gap by investigating how local governments respond financially to cyberattacks, introducing the concept of a Cyber-Incident Budget Response (CIBR). CIBR refers to the adjustments made to IT and cybersecurity budgets following a cyber incident, representing a reactive financial response to a disruptive event. While much of the existing literature focuses on the technical aspects of cyberattacks, the financial and decision-making processes remain underexplored. Understanding these budgetary responses is crucial for developing more strategic and effective approaches to local government cybersecurity.
Threat Rigidity Theory (TRT) serves as the theoretical foundation for this study. According to TRT, organizations under threat often exhibit rigid decision-making, reinforcing existing practices and focusing on short-term, defensive responses rather than embracing innovative or flexible solutions (Staw, Sandelands, & Dutton, 1981). In the context of local governments, a cyberattack can trigger such rigid financial decision-making, leading to an immediate but reactive increase in IT budgets as leaders seek to regain control and restore stability. However, this response may not always be sufficient—or even appropriate—for long-term cybersecurity improvement.
In some cases, the rigid, reactive increase in IT budgets may not represent the most strategic or effective allocation of cybersecurity resources. Public leaders, under pressure to act, may implement budgetary changes that have not been fully assessed against actual organizational needs, potentially resulting in a response that addresses the appearance of action more than the underlying cybersecurity issues. This raises questions about how public resources are evaluated and allocated following a cyberattack. As budgets are reflexively increased without a thorough assessment of actual needs or strategic goals, such actions may reflect reactionary behavior rather than a thoughtful, measured response to the incident (Wirtz & Weyerer, 2017; Norris et al., 2019). Research supports this, as many organizations have been found to recover from cyberattacks without the need for substantial financial outlays due to proactive measures such as robust incident response strategies and cyber resilience (Catota et al., 2018; Choi et al., 2023; Perrett & Wilson, 2023). Moreover, studies have shown that financial responses to cyber incidents are not always correlated with the severity of the attack, and increased spending may not result in meaningful improvements in cybersecurity (Lagazio et al., 2014; Soikkeli et al., 2023). This further emphasizes that reflexive financial actions, taken without strategic planning, can lead to inefficient use of public resources.
Statement of the Problem
Cybersecurity research is significantly lacking in the field of Public Affairs, particularly in understanding how local governments manage cybersecurity issues and respond to cyberattacks. Despite the growing frequency of cyberattacks targeting local governments, very little is known about the budgetary and strategic responses of these entities in the wake of such incidents. To address this gap, the following two research questions are proposed:
Is there evidence of a Cyber-Incident Budget Response as a result of a cyberattack against a local government?
What does the analysis of the data suggest about the necessity of the CIBR for each local government victim?
This study aims to answer these questions by analyzing the financial behavior of local governments following cyberattacks and exploring whether these responses reflect strategic, proactive measures or reactionary, inefficient uses of public funds.
Review of Relevant Literature
This literature review focuses on local government responses to cyber incidents, with particular emphasis on budgetary and financial aspects. It synthesizes current research on cybersecurity finance and budgeting in local governments, drawing from social sciences, computer sciences, and Business Computer Information Systems (BCIS) literature. A striking observation is the paucity of research on local government cybersecurity in the public affairs field, particularly regarding budgetary responses to cyber incidents (Norris et al., 2019). This gap is concerning given the increasing frequency and sophistication of cyberattacks targeting local governments. The limited existing research has primarily focused on the general status of cybersecurity operations and funding issues (Kesan & Zhang, 2019; Norris et al., 2021; Wolff & Lehr, 2018). This scarcity of research presents significant challenges for policymakers and public administrators seeking to develop effective cybersecurity strategies and allocate resources efficiently. The lack of research also hampers local governments’ ability to learn from each other’s experiences and adapt successful budgetary strategies in response to cyber incidents. As Norris et al. (2021) point out, this knowledge gap is particularly problematic given the unique challenges faced by local governments, which often have limited resources and expertise compared to their state and federal counterparts. Adding to these challenges, local governments face the unique task of balancing the protection of sensitive information with the transparency demands of public service (MacManus et al., 2012). This balancing act requires not only technical solutions but also careful policy considerations and public communication strategies, further complicating cybersecurity efforts in the public sector. The need to maintain public trust while safeguarding against cyber threats adds another layer of complexity to local government cybersecurity budgeting and strategy.
Another prominent theme in the literature is the issue of insufficient funding for cybersecurity improvements in local governments. The United States Multi-State Information Sharing and Analysis Center (MS-ISAC) survey reported that local governments struggle with a lack of resources and support, encompassing not only funding but also expertise and technological capabilities (Wolff & Lehr, 2018). This multifaceted nature of resource constraints suggests that addressing cybersecurity challenges requires a holistic approach beyond simply increasing budget allocations. The relationship between funding and cybersecurity readiness is complex and often counterintuitive. Herath et al. (2020) found that spending and cost had an insignificant association with organizational cybersecurity readiness, suggesting that merely increasing financial resources may not suffice to improve cybersecurity posture. This finding challenges the common assumption that more spending automatically leads to better security outcomes. It raises important questions about the efficacy of current spending patterns and the need for more strategic allocation of resources in local government cybersecurity efforts.
Conversely, Kesan and Zhang (2019) demonstrated a negative correlation between IT spending and cyber-attack losses in local governments, supporting the notion that increased investment can lead to reduced damages. Their study suggests that while the relationship between spending and outcomes isn’t straightforward, there is evidence that strategic investments can yield positive results in terms of mitigating cyber risks. This discrepancy highlights the complexity of the relationship between funding and cybersecurity outcomes, suggesting that the effectiveness of financial investments may depend on various contextual factors and how the resources are utilized. It underscores the need for local governments to not only secure adequate funding but also to develop strategies for optimal resource allocation and utilization. The issue of resource allocation is further complicated by competing priorities in local governments, where cybersecurity often vies for funding against other critical municipal services such as infrastructure maintenance, public safety, and education. This competition can lead to underinvestment in cybersecurity, potentially leaving local governments vulnerable to attacks and unprepared for the financial implications of cyber incidents. Balancing these competing needs require careful consideration and strategic planning from local government leaders and policymakers. Research has shown that the financial implications of cyber-attacks extend beyond immediate recovery costs, encompassing a range of direct and indirect expenses. Choi (2023) found that organizations with well-prepared incident response capabilities can often recover from cyber incidents without incurring significant additional costs. This finding highlights the potential return on investment for proactive cybersecurity measures and incident response planning. However, local governments may face long-term financial consequences that are not immediately apparent. These can include increased insurance premiums, potential legal liabilities, and costs associated with rebuilding public trust. Additionally, the opportunity costs associated with diverting resources to cybersecurity recovery efforts can be substantial, potentially impacting other critical government functions and services.
Choi et al. (2023) research implies that even when organizations do incur costs in responding to cyberattacks, their expenditures are typically only marginally higher than what comparable organizations spend in the absence of an attack. This finding underscores the importance of proactive investments in cybersecurity infrastructure, which not only enhance an organization’s resilience but also lead to more efficient recovery processes and reduced overall costs in the event of an incident. The financial impact of cyber incidents can also vary significantly based on the size and resources of the local government. Smaller municipalities and rural governments often face disproportionate challenges in absorbing the costs of cyber incidents, given their more limited budgets and resources. This disparity in impact and recovery capability among different types of local governments is an area that warrants further research and consideration in policymaking.
Emerging research suggests that strategic approaches to cybersecurity budgeting can significantly influence outcomes and cost-effectiveness. Lagazio et al. (2014) found that in the financial sector, costs incurred by organizations are often influenced more by their strategic responses to cyber threats than by the frequency or severity of attacks. This suggests that adopting a proactive and strategic approach to cybersecurity budgeting may lead to lower financial impacts from incidents. For local governments, this finding underscores the importance of developing comprehensive cybersecurity strategies that go beyond reactive measures. Such strategies might include regular risk assessments, threat intelligence gathering, and the development of scenario-based response plans. By anticipating potential threats and preparing for various contingencies, local governments can potentially reduce the impact of cyber attacks and minimize the need for large, unexpected expenditures in the aftermath of incidents.
Soikkeli et al. (2023) demonstrated that implementing redundancy planning can enhance resilience against cyber-attacks without necessitating significant financial expenditures. This might involve maintaining offline backups, establishing alternative communication channels, and cross-training staff. These measures can help ensure continuity of government operations even in the face of significant cyber disruptions, potentially reducing the financial impact of such incidents.
Resource optimization plays a crucial role in enhancing cybersecurity without substantial spending increases. Strategies might include leveraging cloud services, implementing automation tools, and participating in information-sharing networks to benefit from collective threat intelligence. These approaches can help local governments maximize the impact of their cybersecurity budgets, which is particularly crucial given the often-limited resources available.
Qasaimeh et al. (2022) highlighted the importance of advanced security testing and cyber-attack forecasting models in helping organizations identify vulnerabilities and respond to threats proactively. For local governments, implementing such practices could involve regular penetration testing, vulnerability assessments, and red team exercises. Additionally, the use of predictive analytics and machine learning algorithms to forecast potential cyber threats could enable local governments to allocate resources more efficiently and prepare for emerging risks.
The concept of cyber resilience, as discussed by Perrett and Wilson (2023), emphasizes not only protection against attacks but also the ability to recover swiftly and effectively. This holistic approach to cybersecurity can help organizations minimize financial impacts and operational disruptions in the face of cyber incidents. For local governments, building cyber resilience may involve developing redundant systems, implementing robust data backup and recovery processes, and fostering a culture of continuous improvement and adaptation in the face of evolving threats.
While much of the literature focuses on technical and financial aspects of cybersecurity, the role of human factors and organizational culture in shaping cybersecurity outcomes is increasingly recognized. Hirshfield et al. (2015) emphasized the importance of human operators’ suspicion in detecting cyber-attacks, highlighting the critical role that employee training and awareness programs play in enhancing an organization’s defensive posture against cyber threats.
Developing a strong organizational culture around cybersecurity can often be achieved through non-financial strategies such as employee training and awareness programs. These initiatives can significantly contribute to an organization’s cyber resilience without necessitating substantial financial investments (Papuashvili, 2023). For local governments, fostering a culture of cybersecurity awareness could involve regular training sessions, simulated phishing exercises, and clear communication of security policies and best practices. The human element in cybersecurity also extends to leadership and decision-making processes. Research has shown that the commitment of top management to cybersecurity initiatives can significantly influence an organization’s overall security posture. In the context of local governments, this suggests that elected officials and senior administrators play a crucial role in prioritizing cybersecurity and allocating necessary resources.
Despite a growing body of research in general government cybersecurity, significant gaps persist in the literature specific to local government cybersecurity, particularly regarding financial phenomena in response to cyber incidents. These gaps span several key areas, each contributing to our limited understanding of how local governments manage cybersecurity challenges from a financial perspective. A primary gap exists in studies focused on how local governments adjust their budgets in response to specific cyber-attacks. Most existing research concentrates on general cybersecurity spending rather than incident-specific responses. This lack of granular insight hinders the development of evidence-based strategies for financial response and recovery in the aftermath of cyber incidents. Understanding the immediate budgetary adjustments made by local governments during and after attacks is crucial for developing effective response protocols.
Compounding this issue is the scarcity of longitudinal studies examining the long-term financial implications of cyber incidents. This gap extends to research on the effectiveness of various budgetary strategies in local government contexts over time. Such studies could provide valuable insights into the sustainability of various cybersecurity approaches and their impact on organizational resilience. Without this long-term perspective, local governments may struggle to justify and allocate resources for cybersecurity in a way that balances immediate needs with long-term security goals.
The literature also reveals a significant gap in understanding the unique challenges faced by small and rural local governments in financing cybersecurity measures and responding to incidents. These entities often face more severe resource constraints and may lack access to specialized expertise, necessitating tailored approaches to cybersecurity. However, the current body of research has not sufficiently explored these specific contexts, potentially leaving smaller municipalities vulnerable and underserved in terms of cybersecurity strategies and resources.
Another understudied area is the effectiveness of inter-governmental collaboration and resource sharing in improving cybersecurity posture and reducing individual local government costs. While some collaborative initiatives exist, their impact and the best practices for implementing such efforts are not well documented in the academic literature. This gap is particularly significant given the potential for resource optimization and knowledge sharing that such collaborations could offer, especially for smaller or resource-constrained local governments.
While existing studies indicate that a proactive and strategic approach to cybersecurity budgeting, coupled with efficient resource utilization and comprehensive incident response planning, may be effective, there’s a lack of comprehensive research on how these strategies are implemented in local government contexts. The relationship between strategic planning, resource allocation, and cybersecurity outcomes in local governments remains poorly understood. This gap in knowledge makes it challenging for local governments to develop and implement effective, data-driven cybersecurity strategies.
These interconnected gaps in the literature significantly impact our understanding of local government budgetary responses to cyber incidents. The lack of comprehensive research in these areas leaves local governments without clear guidance on how to allocate resources effectively, respond to incidents efficiently, and plan for long-term cybersecurity resilience. Addressing these research gaps is crucial for developing more effective, tailored, and sustainable cybersecurity strategies for local governments of all sizes and resource levels. As cyber threats continue to evolve and target local governments, filling these knowledge gaps becomes increasingly urgent to ensure the security and stability of local government operations and services.
This study aims to contribute to the knowledge on local government cybersecurity by examining the existence and nature of budgetary responses to cyber incidents. To guide this investigation, two hypotheses have been formulated:
A Cyber-Incident Budget Response (CIBR) does occur as a result of a local government entity responding to and recovering from a cyber-incident.
The magnitude of CIBR varies systematically with income level rather than being uniformly explained by attack occurrence alone.
These hypotheses address both the existence of CIBR and its potential necessity. By testing them, this study aims to provide empirical evidence on the financial behavior of local governments facing cyber threats, contributing to the identified gaps in the literature and offering insights for policymakers and cybersecurity professionals.