Start with essential services and dependencies
Courts, dispatch, property records, payroll, and other county services create consequences that extend beyond an IT outage. The precise staffing and recovery capability vary widely by jurisdiction; it is misleading to describe every county as a one-person technology shop. Where a small team carries both routine support and security responsibilities, however, incident response competes directly with keeping daily services running.
The exposure is not limited to separate county networks. A case-management supplier, managed service provider, payroll service, or identity platform can connect many public entities. CISA's StopRansomware guidance identifies managed service providers as an infection vector affecting multiple clients and recommends reviewing provider practices and limiting third-party access. That supports the shared-dependency concern; it does not establish that all major local-government incidents are supply-chain events.
The first planning artifact should therefore be a service dependency map. For each essential service, identify the systems, people, vendors, credentials, communications, and records it requires. A county cannot prioritize recovery well if its list stops at the server inventory.
Aggregate expertise without concentrating unchecked access
A state-run or state-brokered security service can offer monitoring, identity support, shared tooling, and coordinated response that a small jurisdiction would struggle to staff alone. Those are potential advantages, not proof that every centralized model produces better outcomes. The model needs service commitments, local participation, durable funding, and clear authority during an incident.
Before joining or expanding a shared service, establish:
- Coverage: which assets and hours are monitored, and which systems remain the county's responsibility.
- Authority: who can isolate a device, disable an account, contact a vendor, and authorize restoration.
- Separation: how one customer's compromise is prevented from becoming access to another customer.
- Evidence: what logs, findings, and incident records participants can obtain.
- Continuity: what happens if the shared provider itself is disrupted or its agreement ends.
Treat grant funding as one possible funding source, not a permanent operating model. Review the actual award terms, available appropriations, and local budget commitments rather than assuming that an earlier federal allocation guarantees next year's coverage.
Recovery is a service design problem
Three needs deserve particular attention: usable backups, recoverable identity infrastructure, and agreed restoration priorities. They do not guarantee that an organization will avoid paying a ransom or that restoring files will resolve data theft.
CISA's guide calls for offline encrypted backups, restoration testing, and prepared system images. Our additional operational recommendation is to exercise those controls as a public-service recovery sequence, including the dependencies that may be missing during a real incident.
- Name the minimum service. Decide what the public and frontline staff must be able to do during disruption, and how long reduced operation is tolerable.
- Test independent access. Establish how the recovery team obtains approved credentials, communications, documentation, and vendor support if the usual environment is compromised.
- Restore a representative service. Include configuration, applications, data, interfaces, and identity—not just a sample file.
- Measure the result. Record elapsed time, data loss, unavailable dependencies, manual work, and the difference from the agreed objective.
- Resolve and repeat. Assign owners to failures and retest the affected steps before claiming readiness.
A backup status light reports that a job ran. A recovery exercise shows whether the organization can use the result under realistic conditions. Keep those two forms of evidence distinct.
Make provider compromise part of the contract discussion
Shared platforms are both an opportunity for pooled defense and a source of correlated risk. Counties should ask providers to explain how privileged access is controlled, how tenants are separated, how changes are reviewed, and how incident information reaches affected customers.
Contract terms should identify notification responsibilities, evidence preservation, investigation cooperation, restoration support, and access to county data during transition. Establish the contacts and escalation path before a service interruption. A sales assurance that the provider is secure does not answer who will help a county restore a critical workflow at two in the morning.
These questions also apply to a state-operated shared service. Public ownership does not remove technical dependencies or the need to rehearse recovery.
The decision for county and state leaders
The useful next investment may be a shared capability, a local control, or a recovery dependency that neither party currently owns. Start with the dependency map and exercise results, then fund the gap that most directly affects essential service continuity.
Aggregated defense is valuable when it gives jurisdictions expertise and coordinated action they can actually use. Its success should be judged by coverage, containment, response, and demonstrated recovery—not participation totals alone.
Sources and further reading
Spartan X brings security assessment, monitoring, incident-response planning, and infrastructure engineering to this problem. Used together, those disciplines can help a county turn a shared-service agreement into recovery arrangements its staff can actually exercise.



