Funding Arrived. The Attackers Were Already There.
# Funding Arrived. The Attackers Were Already There.
There is a specific kind of optimism found only in the procurement office of a government agency. It is the belief that if one simply allocates enough capital toward a "security transformation project," the resulting suite of dashboards will somehow act as a physical barrier against intrusion. I have spent a career watching these projects unfold. They usually follow a predictable rhythm: a high-profile breach occurs, a panicked minister announces a funding package, and three years later, we discover that the money was spent on licenses for software that no one knows how to configure.
Looking at this week's numbers, the government sector is currently the second most targeted group, with 209 stories hitting the wire. It is an active, noisy environment. But the noise isn't coming from sophisticated statecraft; it's coming from the gap between what a policy paper claims and what the actual server room looks like.
Take the recent debut of ExfilSquad. The group didn't target a secret intelligence facility or a locked-down treasury vault. Instead, they hit a target that manages the personal data of roughly 100,000 UK police officers. There is something profoundly wry about law enforcement, the very people tasked with maintaining the chain of custody and securing evidence, having their own records hauled off by a ransomware gang.
The paperwork for such an event is an absolute nightmare. Under current reporting frameworks, the administrative burden shifts from fixing the hole to proving that you followed the process of noticing the hole. One can imagine the frantic filing of incident reports, each designed more to shield the department from liability than to protect the officers whose data is now on a leak site.
Then we have the situation in New York. The state has just awarded $9 million in grants to strengthen cybersecurity across 153 water systems. On paper, this looks like a victory for resilience. In practice, it is a reactive gesture. These grants are arriving after a coordinated campaign targeting operational technology (OT) was already identified.
If you do the math, that's just under $60,000 per system.
For those who have actually worked in OT, that figure is almost comical. It might cover a few new firewalls and a temporary consultant who will tell them their legacy PLC controllers are fundamentally insecure. But it won't replace the hardware that was designed in an era when "networked" meant something entirely different. The funding arrives after the risk has been realised, which is how government spending almost always works. It is a trailing indicator of failure.
The core problem here is that governments treat security as a procurement exercise rather than a governance one. They believe they can buy their way out of a structural deficit in talent and discipline. The argument usually goes like this: "We have invested millions in the latest EDR and XDR tools, so we are secure."
The objection, of course, is that tools are useless if the person managing them hasn't patched the gateway in eighteen months because they were afraid a reboot would crash a legacy database from 2004. The tool isn't the failure; the process is. We see this time and again. A vendor releases a patch, the government agency logs the advisory in a spreadsheet, and the actual implementation is deferred until the next quarterly maintenance window, which never arrives because someone forgot to schedule it.
The second-order effect of these failures is where things get truly uncomfortable. When 100,000 police officers have their data exposed, you aren't just looking at a privacy breach. You are looking at a goldmine for social engineering. Every officer on that list is now a high-value target for phishing, blackmail, or impersonation. The attackers don't need to hack the police network again; they already have the directory and the personal details needed to walk through the front door via a well-crafted email.
I remember a similar pattern in Oslo a few years back, where the focus was on "hardening" perimeters while the internal permissions were so loose that a junior clerk had administrative access to things that would make a CTO faint. The parallel holds here: the perimeter is a convenient thing to fund because it's easy to put in a press release. "We have installed 153 new firewalls" sounds better than "We are finally teaching our staff how to manage passwords."
Interestingly, we see what actual regulatory teeth look like when we look outside the public sector. Lotte Card in South Korea was ordered to suspend business operations for 1.5 months following a massive data breach. That is a concrete penalty. It is a financial and operational blow that forces a board of directors to actually care about security.
Government agencies, by contrast, rarely face such consequences. When a state agency loses the records of 100,000 people, there is no "business suspension." There is no fine that hits the budget in a way that hurts. Instead, there is a report, a modest increase in next year's budget for "security enhancements," and a cycle that repeats every few years.
The machinery of regulation is slow, often toothless, and obsessed with checklists. If you can check the box that says "Security Training Completed," the regulator is generally satisfied, even if the employees are just clicking 'Next' on a slide deck while checking their phones.
I suspect we will see more of this "funding after the fact" model. It allows politicians to look decisive without requiring them to oversee the tedious, unglamorous work of auditing every single legacy system in the water sector or the police force. They prefer the $9 million headline to the reality of a thousand small, boring fixes.
One has to wonder: if we continue to price security as a series of reactive grants, what happens when the attackers stop targeting the systems that are easy to fund and start targeting the ones that aren't? I’ll be watching to see how many of those 153 water systems actually spend their grant on something other than a fancy new dashboard.
◼