Municipalities are the most citizen-facing part of government. They deal with the public constantly, and they run services that affect daily life: civil records, housing, permits, social services. When something breaks it is not an IT issue. It hits real people, quickly.

That makes their digital infrastructure more than technical. It makes it critical.

Municipal IT teams are often actively engaged with security. Even so, and despite good intentions and structured process, our data shows clear blind spots. They are not minor.

Why compare them at all

In cybersecurity, raw numbers mean little in isolation. A vulnerability may sound alarming, but how common is it, and how concerning?

Peer comparison answers that. It shows not just what exists but how typical it is across similar organizations. It surfaces systemic weakness, identifies outliers in both directions, and gives security decisions real-world context. In government, where maturity and budget vary widely, that context is essential.

What we measured

Most external scans stop at domains and open ports. Our platform assessed ten critical elements of each municipality’s internet-facing infrastructure, all from the perspective of an outside attacker.

Exposed domains, subdomains and services, certainly. The basics. But also shadow assets, meaning forgotten systems that still respond online while sitting outside most inventories. Infrastructure geolocation. Leaked credentials. Phishing infrastructure. Hardcoded secrets. And live vulnerability assessment.

In our experience most organizations monitor a handful of these, and usually only for their primary domain. Other assets, additional domains like a jobs site or a parking portal, and third-party integrations, go unwatched. That leaves major parts of the attack surface unseen.

Early findings

The full report follows at the end of the month. A few of the early results:

  • Large attack surfaces, at every size. Even small municipalities show multiple domains, dozens of subdomains, IP ranges and exposed applications. The volume is not negligible, and every asset needs some degree of security.
  • High-value targets exposed without justification. Public admin portals, CMS backends, network management panels, online with no clear business reason. Not inherently wrong, but high-signal.
  • Outdated assets carry real weight. One example showed 32 high-to-critical vulnerabilities on a single exposed system, most likely forgotten. This is not about blame. It is about visibility.
  • Phishing infrastructure is real. One municipality had 24 suspected phishing domains targeting it. Same name, slightly altered spelling. These do not exist in your organizational reality. They exist in ours.

Disclosure of all of the above follows our responsible disclosure policy.

How you would find out where you stand

We do not just scan. We monitor continuously, because a point-in-time scan describes a state that has already changed. If you are serious about managing exposure, automation is not optional.

Written by Sander Rurup, GRC & IT architecture

Cybersecurity consultant with close to a decade of consulting experience in enterprise architecture, information security management and security auditing across regulated European industry. Sander translates exposure into business requirement, governance and ownership.

TOGAF · ISO 27001 · CISM