Skip to main content
  • MassTech
  • Broadband
  • Cyber
  • eHealth
  • Innovation
  • Manufacturing
  • NEMC
Home
  • About
    • Overview
    • Strategy Council
    • Team
    • Newsletters
    • News
    • Events
    • 2024 Cyber Month
    • Add an Event
    • Past Events
    • Contact
  • Ecosystem
    • Ecosystem
    • Cybersecurity Training and Education Working Group
    • Cybersecurity Mentorship Program
    • Commonwealth SOC Range Initiative
    • Jobs Board
    • Workforce Development Resources
    • Business Assistance
  • Resiliency
    • Cyber Resilient Massachusetts
    • Working Group
    • Critical Infrastructure Toolkit
    • Resources
    • Municipalities
    • Minimum Baseline of Cybersecurity
    • Secure Our Data. Secure Our Future.
    • Healthcare
  • Get Involved!
    • Get Involved
  • MassTech
  • Broadband
  • Cyber
  • eHealth
  • Innovation
  • Manufacturing
  • NEMC

Search

Breadcrumb

  1. Home
  2. Municipal Cybersecurity Toolkit

Municipal Cybersecurity Toolkit

Response Plan Materials
Toolkit
Conversations Operations & Finance
Public Safety Schools

Resources to Support Municipal Cyber Resiliency

For National Cybersecurity Awareness Month 2019, the Cyber Resilient Massachusetts Municipality Sub-working Group has developed a toolkit to help municipal leaders begin to understand the cybersecurity posture of their municipality and figure out next steps for protecting municipal infrastructure against cyber threats.

The intent is to provide guidance and action steps necessary to get the conversation started around cybersecurity preparedness and ultimately protect municipal infrastructure against cyber threats before they occur.

Getting Started

1. Why Cybersecurity?

Municipal Operations & Finance

Public Safety

Schools

2. What is Cybersecurity?

Ransomware

3. How Do I Prepare?

Achieve a Minimum Baseline of Cybersecurity

​
Business Planning

Getting Started: Conversations to have with Business Process Owners and IT Staff

Sets of questions for municipal leaders for conversation with Business Process Owners, IT Staff, and Service Providers to assess cybersecurity preparedness and to consider next steps in developing a plan.

Learn More

Cyberplanner Tool for Creating a Custom Cybersecurity Plan

Tool for creating a custom cybersecurity plan with expert advice to address specific business needs and concerns.

https://www.fcc.gov/cyberplanner

Considerations for Business Impact Analysis

This article outlines the steps and considerations of a Business Impact Analysis, including the consequences of a business function disruption and the information needed to develop recovery strategies. 

https://www.ready.gov/business-impact-analysis

Business Impact Analysis - Guide and Template

Guide for Agencies to conduct Business Impact Analysis with Step-by-Step guidance and a template.

https://www.oregon.gov/das/Procurement/Guiddoc/BusImpAnalysQs.doc

Contingency Planning Guide and Process Template (NIST SP 800-34)

Guide with instructions, recommendations, and considerations for IT contingency planning - interim measures to recover IT services after an emergency or system disruption. 

https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

FEMA Business Impact Analysis Worksheet

Business Impact Analysis - FEMA Quick Reference Template.

https://www.fema.gov/sites/default/files/2020-07/fema_BIA-Risk-Management-Worksheet.pdf


Ransomware

CISA Insights - Ransomware Outbreak

This CISA bulletin lays out three sets of straightforward steps any organization can take to protect themselves or recover from a ransomware attack.

https://www.us-cert.gov/sites/default/files/2019-08/CISA_Insights-Ransomware_Outbreak_S508C.pdf

CISA Security Tip - Protecting Against Ransomware

Tip Sheet with recommendations for protecting against ransomware.

https://www.us-cert.gov/ncas/tips/ST19-001

Incidents of Ransomware on the Rise - Protect Yourself and Your Organization 

Article about ransomware with Tips for Dealing with Ransomware Threat.

https://www.fbi.gov/news/stories/incidents-of-ransomware-on-the-rise/incidents-of-ransomware-on-the-rise

MS-ISAC Security Primer on Ransomware https://www.cisecurity.org/white-papers/security-primer-ransomware/
NASCIO Cyber Disruption Planning Guide https://www.nascio.org/wp-content/uploads/2019/11/NASCIO_CyberDisruption_072016.pdf
Ransomware explained: How it works and how to remove it

Despite a recent decline, ransomware is still a serious threat. Here's everything you need to know about the file-encrypting malware and how it works.

https://www.csoonline.com/article/3236183/what-is-ransomware-how-it-works-and-how-to-remove-it.html

STOP RANSOMEWARE

The U.S. Government's official one-stop location for resources to tackle ransomware more effectively.

https://www.cisa.gov/stopransomware  

U.S. Small Business Association RANSOMWARE FACTS & TIPS

As technology evolves, the prevalence of ransomware attacks is growing among businesses and consumers alike. It’s important for digital citizens to be vigilant about basic digital hygiene in an increasingly connected world. This fact sheet explains what ransomware is and what you can do about it.

https://staysafeonline.org/wp-content/uploads/2017/09/STOP.-THINK.-CONNECT.-Ransomware-Facts-Tips.pdf

 

General Resources

Cybersecurity is Everyone's Job

Everyone in a local government has an important role to play in helping to minimize cybersecurity risks.

https://www.sao.wa.gov/becybersmart/

Online Cybersecurity Safety Basics

Free online security tips and resources.

https://staysafeonline.org/stay-safe-online/online-safety-basics/

Center for Internet Security (CIS) https://www.cisecurity.org/
Cybersecurity and Infrastructure Security Agency (CISA) https://www.cisa.gov/
Department of Homeland Security (DHS) https://www.dhs.gov/
Federal Bureau of Investigations (FBI) https://www.fbi.gov/investigate/cyber
Federal Communications Commission (FCC)

Helps organizations create and save a custom cybersecurity plan quickly to address specific business needs and concerns.

https://transition.fcc.gov/cyber/cyberplanner.pdf

Federal Trade Commission (FTC) https://www.ftc.gov/tips-advice/business-center/small-businesses/cyberse...
How to Recognize and Avoid Phishing Scams

FTC Tip Sheet on how to recognize and avoid phishing scams.

https://www.consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams

MIIA - Cyber Risk Management Best Practices for Cybersecurity

The Cyber Risk Management Team of the Massachusetts Interlocal Insurance Association (MIIA), a membership service of the Massachusetts Municipal Association, produced this Tip Sheet of the 10 Cybersecurity "best practices" for municipalities to address cybersecurity in their communities and distributed it at the January 2020 MMA Annual Conference in Boston, MA.

Form
Get MassCyberCenter news from the Massachusetts Technology Collaborative in your inbox.
CAPTCHA
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
By submitting this form, you are consenting to receive marketing emails from: Massachusetts Technology Collaborative, 75 North Drive, Westborough, MA, 01581, US, https://www.masstech.org.

No thanks, please take me to the website. 

MassCyberCenter Logo

Sign Up for Our Newsletter

  • Contact
  • Procurement
  • Public Notices
  • Privacy Policy
  • Accessibility

Main Campus:
75 North Drive
Westborough, MA 01581
(508) 870-0312

Boston Office:
2 Center Plaza, Suite 200
Boston, MA 02108
(617) 371-3999

  • Visit our page (opens in new tab)
  • Visit our page (opens in new tab)
  • Visit our page (opens in new tab)
  • Visit our page (opens in new tab)
  • Visit our page (opens in new tab)

Privacy Policy Accessibility © 2024 Massachusetts Technology Collaborative