Public entities deliver essential services communities rely on every day, from municipalities and school districts to utilities, transit authorities, and state agencies. As these organizations expand their use of online payment systems, cloud platforms, digital records, and third-party software, they also increase their cyber exposure.
For public entities, a cyber incident can disrupt critical services, strain budgets, create regulatory and reporting obligations, and weaken public trust. That is why cyber readiness must go beyond prevention and focus on response, continuity, and recovery.
Recent data reflects the scale of the threat. Verizon's 2025 Data Breach Investigations Report Public Sector Snapshot found 2,101 incidents affecting state, local, territorial, and tribal entities (SLTT), including 1,341 with confirmed data disclosure. The report also found that 79% of SLTT breaches fell into just three patterns, miscellaneous errors, system intrusion, and basic web application attacks, while personal data was involved in 83% of breaches. These findings underscore how cyber events can quickly become operational, financial, and public-trust crises for public entities.
For public entities, the priority is reducing the likelihood of an incident and recovering quickly when one occurs.
Public Entities Face Unique Cyber Challenges
While cyber incidents affect organizations of all types, public entities operate in a uniquely complex environment.
Unlike many private-sector organizations, public entities are responsible for services that residents, businesses, and communities rely on every day. Even a temporary disruption can affect public operations, delay critical services, and increase scrutiny from stakeholders.
At the same time, public entities often manage large volumes of sensitive information, including:
- Constituent and customer records
- Financial and payment information
- Employee data
- Utility and service account data
- Public safety and operational records
Many organizations are also navigating modernization initiatives while balancing budget constraints, evolving regulatory requirements, and aging infrastructure. These realities can make cyber preparedness and recovery especially challenging.
A Common Cyber Risk for Public Entities: Business Email Compromise (BEC)
While ransomware often draws the most attention, BEC remains one of the most common and costly cyber risks facing organizations, including public entities.
A typical scenario begins with an email that appears to come from a trusted vendor or internal leader, requesting a change to payment instructions or urgent approval of a transaction. If the request is accepted without verification, funds can be sent directly to a criminal-controlled account.
These incidents often succeed because threat actors exploit trust and urgency.
For public entities, the impact can extend beyond the initial financial loss. A BEC event may require transaction tracing, internal review, coordination with financial institutions, stakeholder communication, and evaluation of potential recovery or claims-related issues. It can also divert time and resources away from core public services.
In the FBI's 2024 Internet Crime Report, Business Email Compromise ranked among the most financially damaging cybercrimes, second only to investment fraud by reported losses, underscoring why it remains a major cyber concern for public entities.
The Incident Is Often Only the Beginning
One of the most overlooked aspects of cyber risk is what happens after the event itself.
Organizations naturally focus on identifying and containing the incident. However, many public entities discover that the broader operational and financial consequences become the more complex challenge.
Depending on the circumstances, organizations may need to manage:
- Service disruptions
- Funds transfer fraud losses
- Business interruption concerns
- Vendor disputes
- Regulatory reporting requirements
- Data privacy obligations
- Recovery expenses
- Liability concerns
- Claims management activities
Understanding these broader implications is a critical component of cyber resilience.
Third-Party Risk: An Expanding Exposure
Public entities depend on a growing network of third-party vendors such as software and data hosting partners. While these services are essential to modern operations, they can also expand cyber exposure.
When a third-party provider experiences a cyber incident, the disruption can spread quickly, affecting system access, service delivery, payment processing, and recovery costs. As digital ecosystems continue to expand, organizations must consider not only their own cyber posture, but also the resilience of the vendors and providers they depend upon.
Recovery Becomes the Real Challenge
For public entities, cyber incidents rarely end when systems are restored. A ransomware event may create business interruption concerns, a Business Email Compromise loss may require extensive recovery efforts, and a third-party cyber incident may introduce questions around liability, regulatory obligations, and financial impact.
That's why cyber resilience extends beyond prevention. Public entities must also prepare for the operational, financial, and claims-related challenges that can follow an incident. Organizations that invest in incident response planning, employee awareness, vendor risk management, and business continuity strategies are often better positioned to maintain essential services, support recovery efforts, and reduce disruption when cyber events occur.
How Gallagher Bassett Can Help
After a cyber, public entities may need to address service disruptions, financial losses, regulatory obligations, stakeholder communications, and cyber liability exposures, all while continuing to deliver essential services and demonstrate responsible stewardship of public resources.
Gallagher Bassett provides comprehensive cyber claims and risk management solutions designed to help organizations respond effectively when cyber-related events occur. Our cyber claims professionals help clients manage exposures ranging from unauthorized access and phishing scams to business interruption, funds transfer fraud, and data breach events. Through established claims processes, specialized vendor partnerships, and dedicated claims expertise, we help organizations contain costs, support regulatory compliance, and coordinate an effective response.
That means having a partner that understands the importance of maintaining service continuity, protecting public resources and managing the broader impacts that can follow a cyber event. From cyber liability claims management to recovery support, Gallagher Bassett helps organizations work toward effective outcomes while continuing to serve the communities that depend on them.
Learn more about Gallagher Bassett's cyber claims and risk management capabilities.
Authors
Christa Johnson
Make Gallagher Bassett your dependable partner
When making the right decision at the right time is critical to minimize risk for your business, count on Gallagher Bassett's extensive experience and global network to deliver.