When cyber incidents stop services: a practical uplift pathway

Risk Matters - Winter 2026

Keeping essential services running is a core priority for local governments – even with stretched teams, tight budgets and ageing systems to manage. At the same time, cyber threats are increasing, and communities, regulators and auditors expect strong prevention, preparedness and fast recovery. Because cyber resources are limited and many councils rely on third-party providers, uplift needs to be realistic and targeted.

The LGIS Cyber Uplift Program supports members to take practical, measurable steps over time through targeted check-ups and improvement activities. The program has recently expanded to focus on areas members commonly want more clarity on:

  • How effective core safeguards are in practice
  • Readiness to respond to incidents
  • Supplier and third-party risk management

Delivered through a co-funded arrangement, the expanded services help members access uplift activities in a cost-effective way. The value is not just identifying gaps, but helping members prioritise the actions that make the biggest difference – improving response readiness, strengthening supplier oversight and building confidence in recovery planning – year on year as threats evolve.

Other sections in this season's Risk Matters

Where we’ve been – Winter 2026

Congratulations to the Shire of Kellerberrin on receiving the Tier 2 Diligence in Safety Award. CEO James Sheridan visited the Shire earlier this month to meet the team and present the award. The award recognises strong results through LGIS’s ‘3 Steps to Safety’ program.

Read More »

Hiring third-party equipment?

From marquees, stages and sound systems to temporary fencing, generators, catering equipment and vehicles, third-party asset hire is a practical way to meet short-term needs without owning everything year-round.

Read More »

Understanding the Reasonable Administrative Action exclusion in the Workers Compensation and Injury Management Act 2023 (WA)

The Workers Compensation and Injury Management Act 2023 (WA) introduced a significant change to the assessment of psychological injury claims in Western Australia. While the Act retains a broad definition of injury, section seven contains a new exclusion for psychological and psychiatric disorders arising from ‘reasonable administrative action’ taken by an employer.

Read More »

Tabletop incident management exercise (strengthened preparedness testing)

If a cyber incident happened tomorrow, would the right people know what to do next? A tabletop incident exercise lets members test this in a supported, low-pressure setting with realistic scenarios. It checks the practical, human side of response – who does what, how decisions are made, and how communications work when information is still emerging. IT, leadership, communications, legal, operations and key vendors take part, so handovers and decision points are clear.

After the session, members have a clear view of what’s working, what needs improvement, and the small changes that will make plans easier to activate under pressure.

To build capability over time, we have added to this service by introducing two additional assurance activities for members to consider:

  • Progressive exercise program – scenario escalation from single-event exercises to compound scenarios to stress test decision-making.
  • Phishing simulation – targeted testing of the human and credential attack surface using current-generation AI-assisted lures.
  • Vulnerability assessment and penetration testing (VAPT) – independent assessment of internet-facing systems to identify exploitable vulnerabilities and misconfigurations; findings directly inform tabletop scenario design.

If a cyber incident escalated quickly, what decisions would need to be made first? This exercise gives members a structured way to work through those questions in a controlled setting, stress-testing roles, escalation paths, communications and continuity assumptions. Because it’s progressive, members can start with simpler scenarios and build towards more complex, multi-event incidents over time. Phishing simulation adds a practical check on human and credential risk, and VAPT helps identify external technical exposures – both of which can be fed back into future scenarios to keep them realistic and focused.

Supplier/vendor cyber risk review

When the risk sits with a supplier, how does a council stay confident it will still get early warning, clear decisions and timely action? The risk review gives members a structured way to explore that – especially for vendors that run critical technology services, maintain systems, or need access into council environments. In practice, it looks at the everyday ‘must haves’ that tend to matter most during an incident: who can access what (including remote access), what visibility exists to spot issues early (logging and monitoring), and how incident reporting will work – who is notified, when, and with what detail. It also asks how subcontractors are managed, so councils can see whether risk is being introduced further down the chain.

Members can use this supplier cyber risk framework during selection to compare options up front, or revisit key vendors as services change. The framework should be incorporated into the broader supply chain risk management control to ensure cyber risk becomes more consistent and repeatable, not a one-off procurement checklist.

Australian Signals Directive (ASD) essential eight alignment

The program also offers an ASD Essential Eight assessment to document current maturity. The assessment records which controls are implemented, how consistently they are applied, and what supporting evidence is available. Findings are summarised as strengths, gaps and areas for follow-up. This can provide a common reference point for planning and tracking uplift activity over time, and for supporting governance and audit discussions.

As part of the Cyber Uplift Program expansion, the audit scope has also been widened beyond technical preventative controls to include three additional areas that strengthen resilience:

  • Disaster recovery preparedness: Assesses a member’s ability to restore systems and data following a cyber incident, helping to validate that recovery arrangements are realistic and viable.
  • Business continuity: Assesses the ability to maintain critical services during and after an incident, linking cyber maturity directly to service delivery outcomes.
  • Staff awareness and training: Assesses baseline cyber hygiene across the workforce, recognising that human and credential risks remain a major driver of incidents.

The Australian Signals Directorate’s Essential Eight remains an important baseline for assessing and improving cyber maturity. At the same time, the broader direction of travel across cyber risk management is towards a more risk-based and resilience- focused approach, with increasing emphasis on disaster recovery preparedness, business continuity and staff awareness and training. This reflects a recognition that effective cyber resilience depends not only on technical controls, but also on an organisation’s ability to recover services, maintain critical operations and strengthen human resilience.

Effective funding model

What changes when cyber uplift is co-funded (meaning the cost is shared, so the member pays less upfront)? It makes it easier for members to take up audits, exercises and vendor reviews without the work feeling out of reach. From there, the program links assurance to staged uplift steps, helping councils translate findings into repeatable capability – and show steady, measurable progress over time.

Case Study

A local government member wanted to strengthen cyber resilience in a practical way, with a clear focus on incident readiness: how a cyber event is managed from first alert through to recovery, how decisions are made under pressure, and how services return to normal operations.

The engagement began with a series of tabletop exercises, tailored to the members operating environment – including its governance structure, services and vendor arrangements. Rather than a generic scenario, the sessions reflected the decisions and pressures most relevant to how the member delivers services.

The exercises stepped through realistic scenarios from detection to recovery. One scenario involved ransomware and data extortion, creating immediate pressure to act quickly while managing uncertainty. As the scenario unfolded, the member worked through key decision points: when and how to escalate, how technical and executive actions align, what to communicate (and when), and how to balance competing priorities while services are impacted.

The sessions also tested the foundations underneath any effective response. Governance and accountability were reviewed in a structured way, confirming who leads which decisions, where approvals are required, and how communication pathways work across internal stakeholders and external support. The exercises reinforced strong practice and highlighted clear opportunities to tighten procedures, clarify roles and improve coordination.

Alongside the tabletop work, a phishing simulation tested day-to-day cyber awareness – how well suspicious emails were recognised, how quickly concerns were raised, and whether reporting pathways were used consistently. The results reinforced the value of ongoing awareness and practical cyber hygiene, and supported a culture where people feel confident to report early rather than second-guessing.

Overall, the engagement lifted preparedness, improved incident response maturity, and strengthened the member’s ability to manage and recover from cyber threats. Participation was strong and reflected a clear commitment to continuous improvement.

Conclusion

Want a clear starting point? Use the expanded Cyber Uplift Program to check what’s working now, confirm response and recovery readiness, and agree the next practical steps for improving supplier risk management. For more information, or to arrange a scoping meeting, please contact your LGIS account manager.

Share on Twitter
Share on LinkedIn

Other sections of this season's Risk Matters

CEO’s Message – Winter 2026

This year marks the significant milestone of the 30th anniversary of LGIS. It’s an opportunity to reflect on the remarkable journey we have undertaken together over the past three decades. Since our founding in 1995, LGIS has evolved from a practical response to emerging risks into a pioneering mutual scheme that proudly serves the diverse needs of Western Australia’s local governments.

Read more »