The Containment Era is here. →Explore

Executive Summary

In August 2024, both the State of Nevada and the City of St. Paul, Minnesota, experienced disruptive ransomware attacks that resulted in significant outages and data theft. Attackers exploited gaps in cybersecurity readiness and funding reductions to compromise critical municipal systems, leading to the shutdown of public services and exfiltration of sensitive information. Incident response efforts included engagement with federal agencies like the FBI and CISA, although full recovery remained ongoing for several weeks and required costly investigations, with losses projected to reach $17 million for St. Paul alone.

These incidents illustrate the rising threat to smaller government entities, exacerbated by declining federal cybersecurity resources. The sophistication and operational impact of ransomware attacks continue to increase, underscoring urgent calls for improved resilience, incident response planning, and investment in cyber hygiene—especially amid tightening budgets and evolving threat tactics.

Why This Matters Now

The convergence of increasing ransomware sophistication and federal funding cuts is placing state and local agencies at heightened risk. As threat actors target government infrastructure with operationally disruptive attacks, the lack of resources and support elevates the urgency for municipalities to enhance their cyber defenses, continuity planning, and response capabilities before future crises arise.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attacks revealed weaknesses in segmentation, visibility, incident response, and the overall enforcement of cybersecurity policies, demonstrating gaps in adherence to frameworks like NIST, HIPAA, and PCI.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Robust application of Zero Trust segmentation, east-west traffic security, egress enforcement, inline threat detection, and visibility controls would have significantly constrained or detected ransomware activities at multiple kill chain stages. Enforcing workload isolation, policy-driven network segmentation, and proactive anomaly detection directly address lateral movement, data exfiltration, and impact.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Reduced initial attack surface and blocked malicious inbound connections.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Suspicious privilege changes or role abuse detected quickly with automated alerts.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Limited attacker's ability to move east-west across segments.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Blocked known C2 traffic and flagged abnormal remote connections.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Detected and blocked unauthorized data exfiltration and high-risk outbound traffic.

Impact (Mitigations)

Empowered rapid containment and threat investigation through unified network-state observability.

Impact at a Glance

Affected Business Functions

  • Public Services
  • Licensing
  • Background Checks
Operational Disruption

Estimated downtime: 28 days

Financial Impact

Estimated loss: $1,500,000

Data Exposure

Unauthorized access to sensitive directories and password vault server; extent of data exfiltration under investigation.

Recommended Actions

  • Enforce Zero Trust Segmentation and strict east-west controls between cloud and hybrid workloads to minimize lateral movement risk.
  • Deploy inline network threat detection and anomaly response to rapidly identify privilege abuse and suspicious behaviors.
  • Implement robust egress filtering policies to prevent unauthorized data transfers and detect ransomware exfiltration activity.
  • Strengthen cloud firewall configurations and continuously monitor for exposed surfaces or misconfigurations.
  • Centralize visibility and automate response processes across multicloud, on-prem, and hybrid environments to rapidly detect and contain future threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image