SMALL CITIES, BIG RISKS

Executive Summary

America's cities with populations under roughly 100,000 residents now sit at the center of the ransomware economy — not as an afterthought, but as a preferred target. Large metros like Atlanta and Baltimore made headlines when ransomware crippled their systems, but the more consequential story is happening in places most Americans have never heard of: Riviera Beach, Florida (pop. 35,000); Newburgh, New York (pop. 30,000); Traverse City, Michigan (pop. 30,000); and thousands of similarly sized cities and counties that run essential services — water billing, 911 dispatch, courts, payroll, permitting — on IT departments of one to three people and cybersecurity budgets that are often an afterthought in the general fund.

Between 2018 and 2024, 525 documented ransomware campaigns hit U.S. government bodies, producing more than $1.09 billion in downtime costs alone — separate from ransom payments, recovery contracts, and lost revenue. [1] The first half of 2025 saw a 65% year-over-year increase in ransomware incidents against government bodies, and — as Section 1.4 details — ransomware is only one of several cyber risks municipal leaders now have to manage. [2]

This paper establishes a baseline view of what cyberattacks actually cost small and mid-sized cities, drawing on documented incidents, independent breach-cost research, and public-sector survey data. It then examines what industry data suggests about the value of a tested incident response capability, the governance structures that determine whether that capability holds up under pressure, and a practical, evidence-grounded framework for closing the gap — sized to the budget and staffing realities of local government.


Next
Next

Establishing a Baseline Estimate of Municipal Tax Burden