Security awareness training significantly lowers phishing vulnerability as understaffed state and local governments seek low-resource risk management
KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today released new research highlighting the critical cybersecurity challenges facing state, local, tribal, and territorial (SLTT) governments. The report details how government organizations have become prime targets for cybercriminals while simultaneously facing severe resource constraints.
The data reveals that despite being the third most-targeted sector by ransomware in 2023, over 80% of SLTT organizations operate with fewer than five employees dedicated to cybersecurity. This staffing shortage coincides with a dramatic increase in cyberattacks, as evidenced by a 313% rise in security incidents reported in the MS-ISAC’s 2022 survey. The situation is worsened by the recent cut of $10 million in federal funding for the Center for Internet Security (CIS), which supports crucial information sharing networks for government agencies.
Human error, often exploited through social engineering, remains the most common entry point for cyberattacks in 70-90% of cases. The limited staffing and resources highlight the need for cost-effective and low-maintenance tools to support government entities. KnowBe4's 2025 Phishing by Industry Benchmarking Report found that a year of security awareness training can reduce an organization’s phishing susceptibility from approximately 33.1% to just 4.1% after one year of implementation. These findings underscore that effective human risk management offers resource-constrained organizations a powerful and affordable defense against the rising tide of cyberthreats.
Key findings from the report:
- 70% of surveyed SLTT organizations cite lack of sufficient funding as their top security concern
- More than 80% of government organizations operate with fewer than five dedicated cybersecurity employees.
- Average ransom per attack reached $872,656 between 2018 and December 2024, with total costs exceeding $1.09 billion.
- Security awareness training reduced phishing susceptibility from approximately 33.1% to just 4.1% after one year.
"The data tells an alarming story about state and local government cybersecurity readiness,” said Erich Kron, Security Awareness Advocate at KnowBe4. “As these organizations grapple with constrained budgets and outdated infrastructure, they remain prime targets for cybercriminals. The surge in ransomware attacks underscores the need to build a more resilient security culture. It’s crucial to prioritize human risk management, which has proven to be a powerful tool to counteract these rising challenges.”
To download the "State and Local Cybersecurity: Facing New Burdens Amid Rising Threats" report, visit here.
About KnowBe4
KnowBe4 empowers workforces to make smarter security decisions every day. Trusted by over 70,000 organizations worldwide, KnowBe4 helps to strengthen security culture and manage human risk. KnowBe4 offers a comprehensive AI-driven ‘best-of-suite’ platform for Human Risk Management, creating an adaptive defense layer that fortifies user behavior against the latest cybersecurity threats. The HRM+ platform includes modules for awareness & compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, and more. As the only global security platform of its kind, KnowBe4 utilizes personalized and relevant cybersecurity protection content, tools and techniques to mobilize workforces to transform from the largest attack surface to an organization’s biggest asset.