On the surface, everything can look calm.

That is what makes Shark Week interesting every year. The danger is not always what you see on top of the water. It is what is already moving underneath.

Cybercriminals work the same way.

The threats facing local governments and public agencies today are built to blend in. They look like normal emails, regular invoices, vendor requests, Microsoft 365 password alerts, grant paperwork, or quick approvals from someone your team already trusts.

Then money moves. Records are exposed. Systems lock up. Public works loses access to a shared file. A library account gets abused. A city department cannot reach the documents it needs. And by the time the problem is obvious, the damage may already be done.

For municipalities, county offices, township governments, public libraries, park districts, utility departments, emergency services, school districts, and economic development organizations around Macomb, McDonough County, and western Illinois, this is not just a technology problem.

It is a public trust problem.

Residents expect services to continue. Taxpayers expect resources to be protected. Boards and councils expect decisions to be made with accurate information. Staff expect the systems they rely on every day to work when they need them.

Summer can make this harder.

People are traveling. Schedules are lighter. Key staff are out. Approvals get handed off. Public works crews are busy with seasonal projects. Parks departments are in peak season. School districts are preparing for the fall. Attackers know this, and they use it.

Here are three risks circling public agencies right now.

1. Fake invoices, payment changes, and vendor impersonation

Attackers do not always need to hack your network.

Sometimes they only need to send one email that looks believable.

This is commonly called business email compromise, or BEC. In the public sector, it often shows up as a criminal pretending to be a contractor, engineering firm, utility vendor, software provider, grant partner, construction company, or other organization your staff already knows.

The email looks normal. The wording feels familiar. The request seems routine.

Someone updates banking information. An invoice gets approved. A wire request moves forward. A grant-related payment is treated as urgent. Later, the real vendor calls asking about payment, and the agency finds out taxpayer money went to the wrong place.

That is a bad day for any organization. For a public body, it can also create board questions, audit findings, insurance claims, public records requests, and a loss of confidence from residents.

These attacks increase when the normal approval process gets loose. The clerk, treasurer, business manager, director, superintendent, or department head who usually handles the request may be out. A backup may not know what normal looks like. An urgent message may be treated as a problem to solve instead of a risk to verify.

The fix is simple, but it has to be written down and followed.

Create a verification process for any financial request that comes through email. If vendor payment details change, if wire information is sent, if an invoice feels unusual, or if a request relates to grant funding or infrastructure work, confirm it using a known phone number. Not the phone number in the email.

For communities like Macomb, Bushnell, Colchester, Blandinsville, Industry, Good Hope, Prairie City, Avon, Tennessee, and Table Grove, many public agencies work with a small group of familiar vendors. That familiarity helps, but it can also be exactly what attackers imitate.

A two-minute call can stop a very expensive mistake.

2. Phishing attacks aimed at distracted public employees

Phishing works because people are busy.

That is the whole strategy.

An employee sees a Microsoft 365 password reset email and clicks the link. Someone gets a text that looks like it came from IT. A department head receives an urgent approval request right before a meeting. A school staff member opens a file because it appears to come from a name they recognize. A township or library employee gets a message about payroll, benefits, or document sharing.

The attacker is counting on speed.

They want your people to react before they think.

In local government, one compromised account can create a lot of problems. It can expose citizen records, personnel files, utility billing information, public safety communications, GIS data, board packets, grant documents, or internal planning files. It can also be used to send more phishing messages to other agencies in the region.

That matters in western Illinois because public agencies often work closely together. City governments, county departments, school districts, emergency services, economic development groups, and utility departments share information every week. Trust is part of how local government gets things done.

Attackers take advantage of that trust.

Software matters. Multifactor authentication, email filtering, endpoint protection, conditional access, and Microsoft 365 security settings all matter. But the best protection is not only a tool. It is a culture where employees know they are allowed to slow down when something feels off.

Your team should pause when they see:

  • An unexpected login request
  • A payment instruction that came out of nowhere
  • A link they were not expecting
  • A message that creates pressure or urgency
  • A request to bypass normal approval process
  • A file share that does not match the sender or the situation
  • A request involving citizen data, utility accounts, payroll, or public safety information

Speed is a weapon attackers use against public agencies.

Slowing down takes that weapon away.

This is where practical staff training helps. Not long, boring sessions that people forget. Short, consistent reminders tied to the work people actually do. Accounts payable. Records management. Public works. Utility billing. Police and fire administration. Parks registration. Library systems. School operations. Economic development projects.

Every department has its own version of risk.

3. Vendor and third-party access that is not being watched

Your agency may be doing the right things internally, while a connected vendor still creates exposure.

If a vendor has access to your systems, data, email, cloud tools, accounting platform, utility billing software, GIS platform, public safety system, library platform, student information system, or records repository, their problem can become your problem fast.

This is supply chain risk.

Most public agencies have more of it than they realize.

Think about all the software tools your organization uses. Think about outside service providers with credentials. Think about engineering firms, auditors, grant consultants, managed software vendors, payment processors, building automation contractors, website vendors, phone providers, and former project contractors. Think about old accounts that were never removed.

Each one can become a path into your environment if it is not managed.

Outsourcing a service does not outsource responsibility.

Public agencies need to know the basics:

  1. Which vendors can access agency data or systems?
  2. What exactly are they connected to?
  3. Who inside the agency owns that relationship?
  4. When was their access last reviewed?
  5. What happens to access when a project ends?
  6. Is their access protected by multifactor authentication?

If those answers are not clear, your risk is not clear either.

And unclear risk is where problems start.

This is also where strategic technology planning matters. Cybersecurity is not separate from infrastructure planning. It connects to Microsoft 365, backup and disaster recovery, records management, GIS, public safety systems, finance, payroll, utility operations, facilities, grant-funded projects, and the ability to keep serving residents when something goes wrong.

A good technology plan should help a board, council, commission, superintendent, director, or department head understand what is in place, what is aging, what is exposed, and what should be budgeted for next.

That does not mean everything has to be fixed at once.

It does mean decisions should be made on purpose.

Backup and disaster recovery are part of public service continuity

When ransomware hits, the first question is often simple.

How do we keep operating?

For a city, county, township, utility district, library, park district, school district, or public works department, downtime is not just inconvenient. It can delay permits, billing, payroll, public meetings, inspections, records access, emergency coordination, water and sewer operations, and communication with residents.

Backups are not exciting, but they are one of the most important pieces of public-sector cybersecurity.

The key is knowing what is backed up, how often it is backed up, where it is stored, and how quickly it can be restored. That includes servers, Microsoft 365 data, finance systems, shared files, GIS data, records, and other critical applications.

A backup that has never been tested is more of a hope than a plan.

Agencies in Macomb, McDonough County, Carthage, Monmouth, Galesburg, Canton, Quincy, and the surrounding region do not need a complicated strategy to start. They need a clear one. Identify critical systems. Protect them. Test recovery. Document the process. Review it before there is a crisis.

That is practical risk management.

By the time you see the threat, it may already be moving

Sharks do not announce themselves.

Neither do the cybercriminals targeting local governments and public agencies.

The organizations that get hit are not always ignoring obvious warning signs. Many believe everything is fine because nothing looks wrong on the surface.

That is the trap.

Invoices look normal. Vendor access looks routine. Employees are just trying to get work done. Microsoft 365 alerts look familiar. Summer schedules feel relaxed. Grant deadlines create pressure. Infrastructure projects create more vendor communication.

Meanwhile, attackers are looking for the gap.

At Tigerhawk, we help leaders get a clear picture of where they are exposed across people, vendors, email, devices, cloud systems, backups, and daily operations. Not with scare tactics. With practical steps that make sense for public organizations and the communities they serve.

If you are not sure where your agency stands, now is a good time to find out.

For more information, schedule time with Tigerhawk.

Questions local public agencies are asking

How can a Macomb, Illinois municipality protect citizen records in Microsoft 365?

Start with identity security. Require multifactor authentication, review administrator accounts, limit external sharing, and make sure former employees are removed quickly. Then confirm what Microsoft 365 data is backed up and how it would be restored. Citizen records, board documents, finance files, and public works information should not depend on password protection alone.

What should a McDonough County public works or utility department include in backup and disaster recovery planning?

Include the systems needed to keep essential services running. That may include utility billing, work orders, GIS data, shared files, SCADA-related documentation, vendor contacts, maps, and Microsoft 365 mailboxes. The plan should identify recovery priorities, who makes decisions during an outage, and how staff will communicate if normal systems are unavailable.

How often should western Illinois public agencies review vendor access to government systems?

At least once a year, and whenever a project ends, a contract changes, or staff turnover affects responsibility for that vendor. City governments, townships, libraries, park districts, school districts, and utility departments should know which vendors have access, what they can reach, and whether that access is still necessary and properly protected.