Spring cleaning usually starts with closets.
But for a city office, township, library, utility district, school district, or public works department, the real risk is not what is stacked in the storage room.
It shows up in an inbox. Usually on a Tuesday morning.
An email that looks like it is from the mayor, county administrator, superintendent, executive director, department head, or board president. The name matches. The tone feels right. Even the signature looks familiar.
“Hey, can you help me with something quickly? I am tied up in meetings. Need you to handle a vendor payment for the infrastructure project. I will explain later.”
Most public agencies in Macomb, McDonough County, and western Illinois have seen something like this.
The difference is who receives it.
A new employee. Four days in. Still learning the office. Still figuring out who approves what. Still trying to make a good impression with the clerk, treasurer, director, chief, superintendent, or department supervisor.
So they do what most good public servants do.
They help.
And just like that, taxpayer dollars, citizen records, or access to a critical system may be at risk.
Why the First Week Is the Most Dangerous Week
Every spring and summer, local governments and public agencies bring in new people. Seasonal parks staff. Public works employees. Library assistants. Utility billing staff. Interns. New teachers and school office staff. New roles funded by grants. Economic development positions tied to projects. Emergency services personnel stepping into unfamiliar systems.
For you, it is onboarding season.
For attackers, it is opportunity.
According to a Keepnet study, CEO impersonation emails are 45 percent more likely to succeed with new hires than experienced employees.
That is not because new employees are careless.
It is because they are new.
They do not know how the city administrator normally communicates. They do not know whether the superintendent sends payment requests by email. They do not know if the library director approves purchases through Microsoft 365, a finance platform, or a paper process. They do not know whether a GIS file request from a contractor is routine or suspicious.
And they do not want to be the person who slows things down during their first week.
The most dangerous employee is not the one who ignores the rules.
It is the one who is trying to serve the public well.
The Real Problem Is Not Training
Think back to the last person your agency brought on.
Was everything ready on day one?
Or did things get pieced together as the week went on?
Maybe their laptop was not fully set up. Maybe Microsoft 365 access was still being configured. Maybe they had to borrow a login to check a shared mailbox. Maybe a file with citizen information was saved locally because they could not get into the right folder yet. Maybe a public works map, grant document, payroll file, utility account list, or board packet ended up somewhere it should not have been.
None of that feels risky in the moment.
It feels like keeping the office moving.
But those small workarounds create gaps.
Shared credentials create accounts nobody tracks. Files end up outside your backup and disaster recovery plan. Personal devices get used for public business. Email forwarding rules go unnoticed. Access to records management, GIS, utility billing, public safety systems, or school platforms gets granted without a clean process.
That is the environment the phishing email walks into.
The attack did not create the vulnerability.
The first week did.
What a Better First Day Looks Like
Fixing this does not require a long security presentation.
It requires a little preparation before the employee walks in the door.
First, their access should be ready. Laptop configured. Microsoft 365 account created. Multi-factor authentication enabled. Permissions set. Shared mailboxes assigned properly. No borrowing logins. No temporary fixes that become permanent.
Second, they should know what normal looks like. A simple conversation goes a long way. Does your municipality ever approve payments over email? Who can authorize ACH changes? How are public records requests handled? What is the process for GIS data, utility customer records, grant documentation, or public safety information? What should they do if something feels off?
Third, give them a place to ask questions.
Most first week mistakes happen quietly because new employees do not want to look inexperienced. That is true in a city hall in Macomb, a township office near Colchester, a library in Bushnell, a school district in western Illinois, or a public works shop serving a small community.
If they know exactly who to go to, they will use it.
Give them a person. Give them a process.
This Is About Public Trust
Cybersecurity issues in local government do not happen because people are trying to cause problems.
They happen because people are trying to help a resident, a board member, a vendor, a parent, a contractor, or another department.
New employees will click faster. They will respond quicker. They will try to solve problems on their own. In public service, that instinct is often what makes someone valuable.
But your systems need to account for it.
Good security is not about perfect behavior. It is about creating an environment where mistakes do not turn into incidents, records are protected, services continue, and public trust is not put on the line.
For municipalities, county governments, township governments, utility departments, public libraries, park districts, school districts, emergency services, and economic development organizations from Macomb to Monmouth, Galesburg, Canton, Carthage, and Quincy, this is also part of strategic technology planning.
You are not just setting up a user account.
You are protecting taxpayer resources, citizen data, infrastructure plans, grant funding, public records, and continuity of services.
If you are bringing on new employees, seasonal staff, interns, or new board-supported positions this season, it is worth getting this right before that Tuesday email shows up.
And if you want a second set of eyes on your onboarding, Microsoft 365 security, backup, disaster recovery, or public sector technology process, we are happy to help.
Just a quick conversation. No pressure. Book a 10-minute discovery call
A Few Questions Local Public Agencies Ask
How should a city government in Macomb or McDonough County onboard new staff securely?
Start before day one. Have the device configured, Microsoft 365 account ready, multi-factor authentication turned on, permissions documented, and role-specific access approved. Then explain what normal requests look like for payments, public records, citizen data, and vendor communication. A simple checklist helps smaller offices stay consistent without adding unnecessary paperwork.
Do public agencies need Microsoft 365 backup if Microsoft already hosts email and files?
Yes, in many cases they do. Microsoft keeps the service running, but that is not the same as a full backup strategy for accidental deletion, ransomware, account compromise, or retention mistakes. Municipalities, libraries, schools, and utility departments should review how email, Teams, SharePoint, OneDrive, and records are protected and recoverable.
What should a public works or utility department do if a new employee receives a suspicious payment or records request?
Pause and verify through a known phone number or established internal contact, not by replying to the email. Report it to the designated supervisor or IT contact right away. For requests involving utility accounts, GIS files, infrastructure plans, grant documents, or citizen records, follow the approved records and data release process before sharing anything.