New KnowBe4 Report Reveals Local Governments Face Surge in Ransomware Attacks with Minimal Resources

TAMPA BAY, FL | May 27, 2025

Security awareness training significantly lowers phishing vulnerability as understaffed state and local governments seek low-resource risk management

KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today released new research highlighting the critical cybersecurity challenges facing state, local, tribal, and territorial (SLTT) governments. The report details how government organizations have become prime targets for cybercriminals while simultaneously facing severe resource constraints.Cover Municipalities_Cybersecurity_Report

The data reveals that despite being the third most-targeted sector by ransomware in 2023, over 80% of SLTT organizations operate with fewer than five employees dedicated to cybersecurity. This staffing shortage coincides with a dramatic increase in cyberattacks, as evidenced by a 313% rise in security incidents reported in the MS-ISAC’s 2022 survey. The situation is worsened by the recent cut of $10 million in federal funding for the Center for Internet Security (CIS), which supports crucial information sharing networks for government agencies.

Human error, often exploited through social engineering, remains the most common entry point for cyberattacks in 70-90% of cases. The limited staffing and resources highlight the need for cost-effective and low-maintenance tools to support government entities. KnowBe4's 2025 Phishing by Industry Benchmarking Report found that a year of security awareness training can reduce an organization’s phishing susceptibility from approximately 33.1% to just 4.1% after one year of implementation. These findings underscore that effective human risk management offers resource-constrained organizations a powerful and affordable defense against the rising tide of cyberthreats.

Key findings from the report:

  • 70% of surveyed SLTT organizations cite lack of sufficient funding as their top security concern
  • More than 80% of government organizations operate with fewer than five dedicated cybersecurity employees.
  • Average ransom per attack reached $872,656 between 2018 and December 2024, with total costs exceeding $1.09 billion.
  • Security awareness training reduced phishing susceptibility from approximately 33.1% to just 4.1% after one year.

"The data tells an alarming story about state and local government cybersecurity readiness,” said Erich Kron,  Security Awareness Advocate at KnowBe4. “As these organizations grapple with constrained budgets and outdated infrastructure, they remain prime targets for cybercriminals. The surge in ransomware attacks underscores the need to build a more resilient security culture. It’s crucial to prioritize human risk management, which has proven to be a powerful tool to counteract these rising challenges.” 

About KnowBe4

KnowBe4 empowers workforces to make smarter security decisions every day. Trusted by over 70,000 organizations worldwide, KnowBe4 helps to strengthen security culture and manage human risk. KnowBe4 offers a comprehensive AI-driven ‘best-of-suite’ platform for Human Risk Management, creating an adaptive defense layer that fortifies user behavior against the latest cybersecurity threats. The HRM+ platform includes modules for awareness & compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, and more. As the only global security platform of its kind, KnowBe4 utilizes personalized and relevant cybersecurity protection content, tools and techniques to mobilize workforces to transform from the largest attack surface to an organization’s biggest asset.

About KnowBe4

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.

More info at www.knowbe4.com. Follow KnowBe4 on LinkedIn and X.