04.03.2026

Cyber on the Front Line: Is Your Nunicipality Ready?

Author: MIC Team


Category:

In the previous part of this article, we covered the fundamentals of the cyber and information security world and gained insight into the mindset of a hacker. In this section, we will explore how to defend against these threats and examine the current state of local authorities in Israel.

Defense Strategies

The world of cyber, much like any other field focused on crime prevention, requires a deep understanding of the motives and capabilities of the perpetrators. In the previous part of the article, we defined this as a “counter-adversarial” field—one that arises as a reaction to an existing phenomenon. We also saw how complex this landscape is, which naturally makes defense a significant challenge.

Indeed, just as there are numerous tools to launch a cyberattack, there are just as many tools to defend against one. Despite this variety, cyber defense can be categorized into three primary strategies: Post-Event Defense (Reactive) – Dealing with a cyberattack that has already occurred in order to minimize its damage and terminate the event; Infrastructure Defense (Pre-emptive/Routine) – Providing ongoing, baseline protection against the most common types of attacks that may occur in the future; Targeted Defense (Proactive) – Specialized protection implemented ahead of a specific, anticipated event. For example, while many systems in Israel have sufficient infrastructure protection for routine times, if a conflict with a state actor like Iran is anticipated, it is wise to prepare for high-intensity cyberattacks likely to occur during the upcoming wartime and bolster cybersecurity beyond the standard level.

It is crucial to note that these strategies must operate on both levels mentioned previously: the technological level and, just as importantly, the awareness and training level for the organization’s end-users. Ultimately, we must remember that no matter how sophisticated our cyber defense system is, if an employee falls victim to a phishing attack and unintentionally hands over credentials to a hacker, that hacker can enter and cause damage long before anyone realizes they aren’t just a regular office worker.

All of this sounds like a great deal of effort—and it indeed is. As with any system, the big question here is cost vs. benefit: How much do we stand to lose in the event of an attack, and is it “worth it” compared to the resources and funding required for preparation?

Local Authorities and Cyber

Despite the weight of the cost-benefit question, for local authorities, it seems the answer is clear from the start. While investing in a cybersecurity array is no small feat—involving not only new technology but also employee training and system implementation—these costs pale in comparison to the potential damage of a cyberattack. The data held by local authorities is highly sensitive, including residents’ identity details – all the while, the shutdown of critical systems often means an inability to provide essential and immediate services. Moreover, cyberattacks against local authorities are no longer a “dystopian fantasy”: they are events that have been occurring with increasing frequency in recent years.

For example, a report from Haaretz (May 20, 2024) described a major Israeli municipality that suffered a month-long cyberattack, during which it was unable to provide services via its resident call center for an almost entire week(!). Similarly, at a July 2024 People & Computers panel, the Israel National Cyber Directorate (INCD) reported 40 targeted cyberattack alerts per quarter in local authorities, identifying a 300% increase in attacks during that period. INCD also noted that since the start of the Swords of Iron war of October 7th 2023 and to that time, the INCD had managed 10 significant attack incidents in municipalities. It is important to establish that the current working assumption is that all local authorities in Israel are targets—including smaller, seemingly “negligible” ones. The goal of such attacks is not just to block services or cause damage, but also to gain a psychological “victory” over the institutional systems that represent the State of Israel.

Despite these facts, there is currently no legal requirement in Israel for a local authority to protect its data and systems from cyberattacks. Furthermore, the National Cybersecurity Bill memorandum released for public comment last January (intended to regulate this issue) specifies in its current draft that the obligation to provide cybersecurity will only apply to authorities with 90,000 residents or more. It is unclear whether this threshold was set because smaller authorities cannot afford proper defense or under the assumption that they are less attractive targets. However, it is worth noting that 237 out of 257 local authorities in Israel have fewer than 90,000 residents. If the bill passes in its current form, the vast majority of authorities will remain unregulated in this field.

What’s Happening on the Ground?

Defending against cyberattacks is not just expensive; it is complicated—requiring specialized knowledge, manpower, and technology. Consequently, many organizations now turn to external providers for SIEM-SOC services. Simply put, this refers to a physical or virtual center staffed by cyber analysts whose sole job is the continuous monitoring of the local authority’s systems. Management systems are installed within the authority to collect data and search for suspicious patterns indicating a possible attack. If detected, analysts in the control center manage the event and block the threat in real-time.

Local authorities can obtain such solutions independently or through the MASHCAL (Local Government Economic Services) cyber tender, which provides services from Ness company for SIEM-SOC operations. This includes guidance during installation and implementation—even for the smallest authorities—along with funding for those in need. Additionally, we recommend that all local government employees educate themselves using accessible online resources, primarily the Israel National Cyber Directorate (INCD) website, which also offers free introductory courses. Of course, one of the best ways to determine the right path is to learn from peers in other authorities or professionals in the field, to whom we would be happy to refer you.

Our unique national reality, combined with rapid internet advancements and the AI revolution, presents challenges we did not necessarily anticipate. One of the roles of MiC is to increase awareness among local authorities and assist in choosing the right solutions. We hope this article has clarified the landscape for you and will serve as a gateway to understanding the complexities of the cyber world.