Ransomware Is Forcing Governments to Treat IT Like Critical Infrastructure

· · Views: 2,543 · 6 min time to read

Government IT has traditionally been treated as administrative machinery: databases for permits, systems for tax processing, employee accounts, procurement portals and networks connecting public agencies. Ransomware is exposing why that distinction is becoming obsolete.

Berlin provided a recent example. Reuters reported that the German capital activated a central crisis response after the Rhysida ransomware group published 5.79 terabytes of data stolen from two government departments. The attackers had offered the data at a starting price of 30 bitcoin, worth $77,622, while Berlin said it would not submit to extortion.

The incident occurred less than a month before Berlin’s September 20 election. Authorities described the breach as an attack on the state itself and created a central crisis unit to review, verify and assess the leaked information while informing affected citizens and businesses.

That response illustrates a broader shift. When compromised IT can interrupt government services, expose citizen records or damage institutional trust, protecting it starts to resemble protecting electricity, telecommunications or transport infrastructure.

Public administration has become a major cyber target

The scale of the problem is measurable.

ENISA’s 2025 threat landscape found that public administration accounted for 38.2% of reported cybersecurity incidents in the EU, making it the most targeted sector in its analysis. The agency also described ransomware as the most impactful cyber threat in the EU, even though distributed denial-of-service attacks occurred more frequently.

A dedicated ENISA analysis of public administration found that ransomware represented about 10% of the sector’s recorded incidents in 2024, while data breaches accounted for 17.4%. Ransomware-as-a-service operations including RansomHub and LockBit 3.0 were among the strains observed targeting government organizations.

The significance is not simply that government networks contain valuable files. Public-sector systems deliver functions citizens cannot easily replace with another provider.

If a retailer goes offline, consumers may shop elsewhere. A municipality, tax authority or public-benefits system often has no equivalent substitute.

Legacy systems create structural security debt

One reason government environments can be difficult to defend is that modernization competes with the requirement to keep essential systems continuously available.

The U.S. Government Accountability Office examined 69 federal legacy systems and identified 11 among the most critical candidates for modernization. Of those, eight used outdated programming languages, four relied on unsupported hardware or software and seven contained known cybersecurity vulnerabilities.

Those systems support functions including health care, critical infrastructure, tax processing and national security.

The financial structure reinforces the problem. GAO found that the U.S. government spends more than $100 billion annually on IT and cyber-related investments, with roughly 80% historically directed toward operating and maintaining existing technology.

That creates technical debt at institutional scale. An old application may still perform its original function reliably, yet depend on unsupported components, specialist knowledge or architectures that were never designed around modern identity controls and network isolation.

Replacing it can take years. Leaving it untouched can preserve vulnerabilities indefinitely.

Procurement expands the attack surface

Government technology is also rarely built and operated by a single organization.

Public agencies depend on contractors, software vendors, managed-service providers and systems integrators. That expands the number of trusted connections capable of becoming entry points.

OECD research on digital public procurement says the involvement of multiple contractors, suppliers and government agencies creates potential cybersecurity weak points, particularly because participants can have significantly different levels of security maturity.

The same report describes public-sector systems as frequently suffering from outdated infrastructure, fragmented platforms and inconsistent data formats. In the UK, it cited estimates that legacy technology accounted for around 28% of central-government departmental systems in 2024.

That fragmentation affects security architecture. Every connection between an old internal system, a cloud service and an external supplier creates another trust relationship engineers must understand and monitor.

Ransomware resilience depends on architecture before an attack

Modern ransomware also makes simple backup strategies insufficient.

NIST’s updated 2026 ransomware risk-management profile describes attacks that may both encrypt organizational data and steal information for additional extortion. Its framework therefore covers governance, identification, protection, detection, response and recovery rather than treating ransomware as only a malware-removal problem.

CISA similarly recommends segmenting departmental IT resources and limiting lateral movement, including separating IT from operational technology where relevant. It also recommends maintaining detailed network diagrams showing interdependencies, cloud connections and access granted to third parties.

ENISA recommends controls including multifactor authentication, privileged-access management, endpoint detection and response, and network segmentation for public administrations strengthening ransomware resilience.

These are architectural controls because they assume a breach may eventually happen.

The objective is not merely preventing an attacker from entering. It is making sure one compromised identity or endpoint cannot automatically become a compromise of an entire public institution.

Government identity is part of the critical layer

This also changes how public agencies need to think about identity.

Government environments can contain ordinary employees, privileged administrators, contractors, service accounts and connections shared among departments. Once those identities span multiple generations of infrastructure, authentication becomes an architecture problem rather than simply a password-policy problem.

Privileged-access management matters because attackers do not need to encrypt every machine themselves. They need credentials powerful enough to make existing infrastructure work on their behalf.

Network segmentation, least privilege and strong authentication therefore perform the same role as physical containment systems in other forms of critical infrastructure: they prevent a localized failure from cascading through the entire environment.

Resilience matters more than perfect prevention

Berlin’s incident shows why the definition of critical infrastructure needs to expand.

Government networks increasingly sit underneath elections, transport administration, construction permits, healthcare, taxation and interactions between citizens and the state. The servers may live in ordinary offices or data centers, but the services they enable have become essential infrastructure.

ENISA now classifies public administration as a high-criticality sector under the NIS2 Directive, while also placing it in a cybersecurity “risk zone” because its maturity does not yet match its importance.

That mismatch is the real ransomware problem.

Governments cannot patch their way out of decades of technical debt overnight. Nor can they replace every legacy platform or supplier relationship immediately.

But they can design systems around the assumption that components will fail: isolating networks, controlling privileged identities, mapping dependencies, maintaining recoverable data and modernizing the systems whose failure would produce the largest public consequences.

Critical infrastructure is ultimately defined by what happens when it stops working.

By that standard, much of government IT is already there.

Share
f 𝕏 in
Copied