Room full of people participating in a cyber security exercise. Photo.
Participants work with an exercise at the Norwegian Cyber Range in 2021 involving the County Governor of Innlandet and students at NTNU in Gjøvik. Photo: Kenneth Nordahl Pedersen, NTNU

Why municipalities need to conduct more cybersecurity exercises

A cyberattack on local government authorities can result in disruption to critical services such as healthcare, water supply, schools and social services.

When employees in Østre Toten Municipality turned on their computers on 9 January 2021, they were met with a digital blackout. Systems were down, data were encrypted and the municipality was paralyzed.

A ransomware attack had crippled everything from health records to payroll to schools. The ensuing chaos revealed just how vulnerable the Norwegian municipal sector is when cyber attackers strike.

Many people gained a whole new understanding of how their own work affects security

The attack served as an important reminder that all municipal authorities must work actively on cybersecurity. Cybersecurity exercises make employees better prepared, expose vulnerabilities and help ensure that critical services can continue to operate if a crisis hits.

Half of Norway unprepared

In Norway, municipal authorities play a key role in many of the services Norwegians use every day. Schools, healthcare, snow clearing, street cleaning, kindergartens, water supply and elderly care are just a few examples.  At the same time, half of Norway’s municipalities report that they don’t have critical expertise in information security.

Researcher Guro Bråten Olsborg. Photo.

Researcher Guro Bråten Olsborg. Photo: Kai T. Dragland, NTNUcritical expertise in data security.

Researchers at NTNU have developed a new set of exercises to improve information security readiness among municipalities.

“A digital crisis is never just about systems going down. It is about culture, roles, responsibilities, communication and priorities,” said researcher Guro Bråten Olsborg.

Olsborg is one of the people behind a new study showing that municipalities learn the most from what researchers call ‘socio-technical exercises’ – meaning exercises that challenge not just IT systems, but the entire organization. Having one of the best firewalls is not much help if people do not know who is in charge of what when a crisis hits.

What happened during cybersecurity training?

The researchers interviewed employees from four municipalities one year after they had participated in a realistic cybersecurity exercise at the Norwegian Cyber Range. They wanted to find out what they gained over time, not just the day after.

The result was clear. The municipalities had improved their routines by identifying what was lacking and adjusting their plans accordingly. They also changed their work practices, and employees became more aware of who is responsible for what. Many people gained a whole new understanding of how their own work affects security. In addition, some structures were actually reorganized. Two of the municipalities introduced new roles to ensure better coordination between the teams responsible for IT and crisis management.

“We thought we knew what was important. But actually we didn’t,” said one of the participants in the study.

One of the most striking findings of the study is that the municipalities gained a more realistic picture of which systems are actually critical. Many people were surprised, because when they had to decide during an exercise which services should be restored first, the priorities became clear. Is education, healthcare, or water supply at the top of the list? It quickly becomes clear what the consequences will be for residents. This leads to better prioritization and more effective measures.

Six people sitting around a table in a small room during a cyber security exercise. Photo.

A small group exercise at the Norwegian Cyber Range in 2021 involving the County Governor and students at NTNU in Gjøvik. Photo: Kenneth Nordahl Pedersen, NTNU

Why the exercises work

The study highlights several reasons why these kinds of exercises foster lasting learning. The realistic pressure in a simulation forces the participants to act rather than simply discuss their way to solutions, and planned breaks along the way allow time for reflection and adjustment as the situation unfolds.

In addition, participants are completely removed from their daily routines, contributing to more impactful and memorable learning experiences.

“When everything is happening around you in real time and you feel the pressure, the learning experience becomes more authentic,” explained Olsborg.

The difference between control and chaos

Socio-technical exercises point to a clear direction for municipal authorities all over Norway. They provide a more realistic picture of how a digital crisis actually unfolds – not on paper, but in practice.

The municipalities practise coordination, communication and making tough decisions, while also experiencing the pace of cyber incidents, the repercussions of which can often last for weeks.

“The exercises not only lead to better procedures, but also to a shift in mindset and a clearer understanding of responsibilities and organization,” concluded Olsborg.

When cyber threats can force a municipality to revert to pen, paper and fax overnight – as Østre Toten experienced – it is this shared understanding that can make all the difference between control and chaos.

Reference: Guro B. Olsborg, Grethe Østby, Mohamed Abomhara and Sule Yildirim Yayilgan: An empirical study of socio-technical information security exercises as a tool to foster organizational learning and information security readiness development in Norwegian municipalities