Industries in Focus

Municipal utilities and local authorities: Why they are particularly vulnerable

Municipal utilities and local authorities: Why they are particularly vulnerable

Municipal utilities and local authorities: Why they are particularly vulnerable

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann

When a municipality is paralyzed, everyone notices: citizen portals fail, registration certificates cannot be issued, social benefits stall, and in the worst case, water supply or energy distribution come to a standstill. Municipal administrations and municipal utilities are among the most vulnerable targets in the German cyber space – and at the same time among the least protected. Teichmann has analyzed the structural causes of this vulnerability and the consequences of the NIS 2 Directive in several articles (Teichmann, Cyberangriffe auf kommunale IT-Infrastrukturen, CyberStR 2025, pp. 23–32; ibid., NIS-2 und die Anwendung auf kleine und mittlere Stadtwerke, EnWZ 2025, pp. 400–407).

Why municipalities are particularly at risk

Teichmann identifies several structural factors that make municipalities attractive and easily exploitable targets.

The first problem is the heterogeneous IT landscape. While small municipalities often outsource their IT to shared municipal data centers, larger cities operate their own infrastructures – and in many cases, there is a confusing mixed operation. This grown heterogeneity leads to very different security levels and a multitude of interfaces that are difficult to monitor (Teichmann, CyberStR 2025, pp. 23–32).

The second problem is legacy systems. Many municipalities work with outdated specialized procedures for which security updates are no longer available or whose updating is omitted due to budget constraints. These legacy systems are a preferred gateway for attackers.

The third and perhaps most serious problem is governance deficits. Cyber risks are often perceived by municipalities as isolated individual problems, and responsibilities remain diffuse. The federal government does not feel directly responsible, the states refer to municipal self-governance, and many municipalities simply lack sufficient personnel and financial resources to proactively address cybersecurity (Teichmann, CyberStR 2025, pp. 23–32).

The fragmented legal framework

A central problem is the confusing legal situation. Responsibility for municipal cybersecurity lies in a conflict area between EU requirements, federal law, and state law – a federal network in which clear responsibilities and uniform minimum standards are lacking. Notably, the IT Planning Council has decided to exempt municipalities from many NIS 2 obligations – a symptom of the federal confusion that Teichmann criticizes. The result is a patchwork of different standards in which no single body comprehensively ensures a uniform level of protection (Teichmann, Cybersicherheit in Kommunen – Regelungsdefizite und Reformbedarf, ZRP 2025, pp. 184–187).

Municipal utilities: Between public services and NIS 2

While core municipal administration remains exempt from NIS 2 in many federal states, the situation is different for municipal utilities. As operators of energy, water, and in some cases transport infrastructure, they provide critical public services – and thus often fall under the NIS 2 Directive (Teichmann, EnWZ 2025, pp. 400–407).

The self-classification is particularly challenging: multi-utility companies that simultaneously offer electricity, gas, water, and perhaps transport or telecommunications must carefully assess which of their activities fall under which category. And even sub-threshold but functionally critical actors can be covered: a small municipal utility supplying an entire region with energy can play a key role despite having few employees, the failure of which would have significant consequences (Teichmann, EnWZ 2025, pp. 400–407).

The resource problem

Teichmann addresses a problem that is often overlooked in practice: the requirements of NIS 2 can simply overwhelm small municipal utilities. A utility with a few dozen employees rarely has its own IT security department or a CISO. His proposed solution is pragmatic: cooperation models. Small municipal utilities can join forces, commission shared IT security service providers, or draw on the resources of municipal data centers. Important note: those who outsource IT security remain responsible for its standard and must audit the service providers accordingly (Teichmann, EnWZ 2025, pp. 400–407).

What municipalities and municipal utilities should do now

Municipal utilities must check whether and under which category they fall under NIS 2. Cybersecurity must be assigned a clear responsibility – as a leadership task with defined accountability. Small utilities should utilize cooperation agreements and shared service providers. The fundamental protective measures – network segmentation, backups, multi-factor authentication, patch management, employee training – can be implemented even with limited resources. And contingency plans for a minimal operation without IT are indispensable in public services (Teichmann, EnWZ 2025, pp. 400–407; ibid., CyberStR 2025, pp. 23–32).

Conclusion: Public services need cyber-resilience

Municipalities and municipal utilities face a double challenge: they are highly vulnerable and, at the same time, particularly worthy of protection because their failure threatens the basic supply of citizens. What is needed is a structural change in the cybersecurity culture of municipal public services – and that begins with cybersecurity being understood as a core task of public responsibility.

All sources refer to published scientific contributions by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the publication index (as of May 2026).

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.