We’re exhibiting at

TribalNet 2026

September 20-24, 2026

Dallas, TX

Booth #320

State & Local Government Sector

Three Real-World Purple Team Engagements | Fully Anonymised | ISO 17025 Accredited Methodology

 

ISO 17025 Accredited · MITRE ATT&CK v15 · All engagements conducted under explicit written authorisation

Sector

State & Local Government

Engagement

Purple Team Exercise

ATT&CK Tactics

MITRE ATT&CK v15

Location

United States

About These Case Studies

The following case studies describe real purple team engagements conducted by GLI Secure across insurance sector organisations. All identifying details , organisation names, locations, system names, and personnel , have been fully anonymised. Statistical outcomes, detection improvements, and regulatory findings are accurate as documented during and after each engagement.

 

All purple team exercises described in this document were conducted under explicit written authorisation from the client organisation, using GLI Secure’s ISO 17025-accredited testing methodology. MITRE ATT&CK technique IDs are referenced as documented in ATT&CK Enterprise Framework v15.

Confidentiality Notice: These case studies anonymised; any resemblance to specific organisations is coincidental.

About Goverment Sector document

Case Study INS-CS-01

Municipal Ransomware Simulation, Mid-Sized US City

Testing essential services continuity and recovery capability against a Royal ransomware attack profile

Organisation

A mid-sized US city government with 3,200 employees and a $180M annual operating budget (anonymised)

Sector

State & Local Government, Municipal government

Location

Upper Midwest, United States

Engagement

Purple Team Exercise, Ransomware Simulation and Government Business Continuity

Duration

7 weeks (3-week planning, 2-day exercise, 2-week SLCGP documentation)

Frameworks

CISA SLCGP Grant Requirements | CJIS Security Policy 5.9 | NIST SP 800-53 Rev 5 | State cybersecurity mandate | MITRE ATT&CK Enterprise v15

The Situation

Between 2018 and 2024, ransomware attacks on US government entities cost an estimated $1.09 billion in downtime alone. The city’s IT Director had tracked every significant municipal ransomware incident, Baltimore ($10-18M), Atlanta ($17M), Tulsa. He had one question he could not answer: how long would his city be down?

 

The city operated finance and payroll, permitting and inspections, police records management (CJIS-governed), 911 Computer Aided Dispatch (CAD), utility billing, and citizen services. A ransomware event encrypting all of these simultaneously would halt the entire city government.

 

The state had recently passed a cybersecurity mandate requiring all local government entities to complete a risk assessment and develop a cybersecurity plan. The IT Director saw the purple team exercise as the mechanism for meeting both the state mandate requirement and the SLCGP grant documentation requirement.

Core Challenge

Determine how long the city would be operationally paralysed following a realistic ransomware attack, whether essential services (911 dispatch, police records, payroll) could be maintained in manual mode, and identify the specific gaps that SLCGP grant funding should address.

What GLI Secure Did

The exercise combined a technical simulation and a government operations stress test. The technical component tested ransomware detection capability and backup integrity. The operations component tested whether each city department could maintain minimum essential services during an extended IT outage.

 

We selected the Royal ransomware group attack profile because Royal was specifically documented by CISA as targeting US municipal governments in its 2023 Stop Ransomware advisory.

 

Recovery timeline modelling was the most consequential output: measuring the realistic time to restore each critical city system from available backups.

The Purple Team Approach

Critical Asset Inventory and Recovery Priority

Mapped all city systems by operational criticality: Tier 1 (911 CAD, CJIS police records, life safety), Tier 2 (payroll, utility billing, service continuity), Tier 3 (permitting, citizen portal). Found: 911 CAD and CJIS had no offline backups and no documented manual fallback procedure.

Network Architecture Assessment

Finding: completely flat network across all departments. A single compromised workstation anywhere in the city government had unrestricted access to 911 CAD, police records management, and all administrative systems.

Initial Access Simulation (Royal Profile)

Simulated Royal's documented initial access: exploitation of unpatched internet-facing VPN. Found: city VPN appliance running firmware 19 months out of date with a Critical CVE exploited in the comparable municipal attack.

Backup Integrity Testing

Found: 911 CAD had no backup. CJIS police RMS backup was 4 months old, backup jobs had been failing since a storage migration. Payroll system restoration took 61 hours, exceeding the bi-weekly payroll cycle.

Essential Services Continuity Testing

Activated manual procedures for Tier 1 systems. Found: only 2 of 7 departments had staff who could execute their manual continuity procedures. Police dispatch manual protocol had not been practised in 3 years.

SLCGP Documentation

Documented all gaps in SLCGP application format: specific control deficiencies, risk narrative, proposed remediation, NIST CSF mapping, and cost estimates for grant-eligible improvements.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1190 Exploit Public-Facing VPN (Royal Profile) Not Detected

No monitoring on VPN authentication anomalies.

T1021 Lateral Movement (Flat Network) Not Detected

No east-west traffic monitoring.

T1486 Data Encrypted for Impact (Multiple Departments) Partial

No ransomware behavioural detection on city servers.

T1490 Inhibit System Recovery (Backup Access) Not Detected

Backups network-accessible with no monitoring.

T1489 Service Stop (911 CAD, Police RMS) Not Detected

No service health monitoring with alert capability.

T1566 Phishing (Staff Account Alternative) Detected

Email security quarantined simulated phishing in 3 minutes.

Key Findings

Critical

911 CAD Has No Backup:

The city’s 911 Computer Aided Dispatch system had no backup of any kind. In a ransomware event, 911 dispatch would revert to telephone-only protocol indefinitely, a life safety issue and a NIST SP 800-34 continuity planning gap.

Critical

CJIS Police RMS Backup 4 Months Old:

Backup jobs had been failing silently for 4 months following a storage migration. In a ransomware event, 4 months of police records would be lost, a CJIS Security Policy violation with FBI audit implications.

Critical

Payroll Recovery Exceeds Payroll Cycle:

61-hour payroll system restoration time exceeds the bi-weekly payroll cycle. City employees could miss a payroll event, a public service and labour relations crisis.

High

VPN with Critical Exploited CVE:

The CVE was documented as exploited in the Royal ransomware municipal attack profile. Patched within 48 hours of the exercise.

High

Manual Continuity Procedures Not Exercised:

5 of 7 departments had continuity procedures that no current staff member had ever executed.

Measurable Outcomes

VPN CVE Patched within 48 hours
911 CAD Backup Offline backup solution implemented within 45 days
CJIS Backup Monitoring Backup job monitoring with failure alerting, FBI audit cleared
Payroll RTO Improved, RTO reduced to 18 hours
SLCGP Grant Application Submitted using exercise documentation
SLCGP Grant Awarded $1.2M for network segmentation, EDR, and backup infrastructure
State Mandate Compliance Exercise documentation accepted as risk assessment and cybersecurity plan

Regulatory Impact

The CJIS police RMS backup failure had direct FBI audit implications. The CJIS Security Policy requires criminal justice information to be protected with appropriate backup and recovery procedures. The city reported the backup failure to the state CJIS Systems Officer as required.

 

The exercise documentation was submitted to the state as the risk assessment required under the state cybersecurity mandate, satisfying the mandate’s annual assessment requirement while simultaneously producing the SLCGP grant documentation.

 

The 911 CAD finding had potential state tort liability implications beyond cybersecurity. A ransomware event disrupting 911 dispatch services could trigger liability claims from individuals who suffered harm during the disruption. The city’s general counsel was briefed within 24 hours.

We had a business continuity plan. What we did not have was staff who had ever executed it, backups that had been tested, or any idea how long we would actually be down. The purple team exercise told us we would be down for weeks if ransomware hit us that day. It also found us $1.2 million in federal grant funding to fix the worst gaps.

— IT Director, Municipal Government (anonymised)

Key Takeaways

Ready to test your State & Local Government security defences?

Case Study INS-CS-02

Water Treatment OT Attack, Municipal Utility Authority

Testing IT/OT segmentation and SCADA security against a Salt Typhoon-profile attack on municipal water infrastructure

Water Treatment OT Attack

Organisation

A municipal water authority serving 280,000 residents with 3 treatment facilities and 12 pump stations (anonymised)

Sector

State & Local Government, Municipal water utility, critical infrastructure

Location

Mid-Atlantic United States

Engagement

Purple Team Exercise, OT/ICS Security Validation and Water Infrastructure Resilience

Duration

10 weeks (5-week OT asset inventory, 3-day exercise, 2-week EPA/AWIA compliance report)

Frameworks

EPA AWIA 2018 | CISA ICS-CERT Advisories | NIST SP 800-82 Rev 3 | EPA Water Sector Cybersecurity Strategy 2024 | MITRE ATT&CK for ICS v15

The Situation

In April 2024, CISA and EPA issued a joint advisory warning that Iranian-backed threat actors had targeted US water sector OT systems. In November 2024, CISA documented Salt Typhoon (China) pre-positioning within US critical infrastructure including water systems. The water authority’s IT Director had a gnawing concern: the treatment plant SCADA systems were supposed to be air-gapped, but IT staff had connected them to the corporate network for remote monitoring purposes. Nobody could tell him exactly what was connected to what anymore.

 

EPA’s AWIA 2018 required the authority to complete a Risk and Resilience Assessment and Emergency Response Plan every 5 years. The cycle was approaching. The authority engaged GLI Secure to conduct a purple team exercise that would both validate the OT security posture and produce the documented findings required for the AWIA RRA update.

Core Challenge

Determine whether the IT/OT network boundary was intact, whether SCADA systems controlling water treatment processes were accessible from the corporate network, and whether any such access would be detected, using a Salt Typhoon pre-positioning attack profile.

What GLI Secure Did

We began with a five-week OT asset discovery phase. The water authority’s network documentation was outdated; actual connectivity between IT, OT, and SCADA systems had evolved through years of incremental changes never fully documented.

 

The OT asset discovery produced the first accurate network diagram the authority had ever had, mapping 847 connected devices across the IT network, the OT DMZ, and the SCADA control network.

 

The exercise tested the security of the IT/OT boundary and SCADA systems using passive and minimally-invasive OT testing methodologies, specifically designed not to disrupt water treatment operations under any circumstances.

The Purple Team Approach

OT Asset Discovery and Network Mapping

Produced: 847-device inventory, accurate network diagram showing IT/OT connectivity, and identification of 14 devices on the SCADA network with no documented owner or business justification.

IT/OT Boundary Assessment

Found: 6 connections between corporate IT and the OT DMZ not in documented network architecture. 3 of these permitted communication from the corporate network to OT-zone systems without traversing a monitored firewall.

Salt Typhoon Pre-Positioning Simulation

Using low-and-slow LOTL techniques consistent with Volt Typhoon/Salt Typhoon TTPs, no custom malware, tested whether the IT network could be accessed without generating alerts. Result: no detection across a simulated 3-day dwell period.

IT to OT Lateral Movement Testing

From a simulated compromised IT workstation, tested whether the 3 undocumented connections permitted lateral movement to the OT network. Found: 2 of 3 permitted connectivity to OT-zone systems. 1 permitted direct access to an engineering workstation with Wonderware SCADA software.

SCADA Engineering Workstation Access (Isolated Environment)

Using an isolated test environment replicating the SCADA engineering workstation configuration, demonstrated the access achievable once the workstation was reached. Found: default credentials were still active on the test system replica.

EPA AWIA RRA Documentation

Documented all findings in the AWIA 2018 Risk and Resilience Assessment format, including threat scenarios, consequence analysis, current countermeasures, and recommended improvements.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1199 Exploit Public-Facing Application (IT Initial Access) Partial

VPN patched. Web app vulnerability found but not exploited.

T1078 Valid Accounts (LOTL Technique) Not Detected

No UEBA baseline on IT network. LOTL dwell undetected 3 days.

T0812 Default Credentials (ICS, Engineering Workstation Replica) SUCCESS ON REPLICA

Default credentials active on isolated test system.

T0866 Exploitation of Remote Services (OT DMZ Access) Not Detected

No monitoring on IT-to-OT DMZ connections.

T0817 Drive-by Compromise (OT Network Enumeration) Not Detected

No IDS/IPS on OT network. Passive enumeration undetected.

Key Findings

Critical

3 Undocumented IT-to-OT Network Connections:

Two of three undocumented connections permitted lateral movement from IT to OT without traversing a monitored security boundary, the pre-conditions for a Salt Typhoon-style pre-positioning attack on water infrastructure.

Critical

SCADA Engineering Workstation Reachable from IT Network:

The Wonderware SCADA engineering workstation was reachable via one of the undocumented connections. Access to this workstation would provide an attacker with ability to modify water treatment parameters, the scenario of the 2021 Oldsmar, Florida water treatment attack.

High

Default Credentials on OT Systems:

The isolated test replica had default credentials active. The production systems were assessed for default credential risk and 7 were found with default credentials still configured.

High

Zero OT Network Monitoring:

The OT network, containing all SCADA and ICS for three water treatment facilities, had no security monitoring infrastructure.

medium

3-Day LOTL Dwell Undetected:

Low-and-slow LOTL techniques consistent with Salt Typhoon remained undetected across a simulated 3-day dwell period on the IT network. No UEBA baseline existed.

Measurable Outcomes

Undocumented IT-OT Connections All 3 removed or gated through monitored firewall
SCADA Engineering Workstation Isolated to OT network, no IT network path remaining
Default Credentials Remediated on all 7 identified OT systems
OT Network Monitoring Passive IDS deployed at all three treatment facilities
EPA AWIA RRA 5-year Risk and Resilience Assessment documentation completed
CISA Notification Authority enrolled in CISA water sector cyber hygiene services

Regulatory Impact

The exercise produced the documentation required for the AWIA 2018 5-year RRA cycle. The EPA has made clear that cyber threats must be explicitly addressed in water utility RRAs.

 

The reachable SCADA engineering workstation with documented default credentials was reported to CISA’s water sector cybersecurity team, consistent with EPA’s guidance that water utilities report vulnerabilities enabling tampering with treatment processes.

 

The undocumented IT-to-OT connections represented a direct NIST SP 800-82 Rev 3 architecture gap. NIST SP 800-82 Rev 3 recommends all IT-OT communication route through a monitored DMZ, the undocumented connections bypassed this entirely.

I knew there were some connections between our IT and OT networks that shouldn’t be there, but I could not have told you where they were. Five weeks of OT asset discovery later, we had a network diagram that showed exactly what was connected to what, and it was much worse than I expected. One of those undocumented connections went straight to the engineering workstation that controls our chemical dosing systems.

— IT Director, Municipal Water Authority (anonymised)

Key Takeaways

Ready to test your State & Local Government security defences?

Case Study INS-CS-03

Election Systems Security, State County Elections Office

Testing voter registration infrastructure and election management system security ahead of a general election cycle

Election Systems Security

Organisation

A county elections office managing approximately 340,000 registered voters (anonymised)

Sector

State & Local Government, County elections administration

Location

Battleground state, United States

Engagement

Purple Team Exercise, Election Infrastructure Security and Integrity Validation

Duration

8 weeks (4-week planning and scoping, 2-day exercise, 2-week CISA/EAC evidence documentation)

Frameworks

CISA Election Security Initiative | EAC VVSG 2.0 | HAVA | MITRE ATT&CK Enterprise v15

The Situation

The county elections office operated voter registration infrastructure, an election management system (EMS), and election night reporting systems for 340,000 registered voters. The elections director had tracked documented adversary activity through CISA’s election security briefings, including activity attributed to Russian GRU/SVR, Iranian APT33/35, and Chinese actors in both the 2020 and 2022 election cycles.

 

The most concerning threat was not the EMS, which was supposed to be air-gapped, but the voter registration database and the election night reporting system. Both were internet-connected. Both had been identified as targets in CISA’s election security advisories. Neither had ever been independently security tested.

 

The elections director wanted to test before the election cycle, not during it, with sufficient time to remediate all critical findings.

Core Challenge

Determine whether the county’s voter registration database, election management system, and election night reporting systems were vulnerable to the specific attack techniques documented in CISA’s election security advisories, and whether any attack activity would be detected.

What GLI Secure Did

The exercise was structured around the specific attack techniques documented in CISA’s election security advisories: SQL injection against voter registration portals, credential attacks against election night reporting systems, and social media account takeover for result manipulation.

 

The exercise was conducted with specific safety constraints: no production voter registration data was at any point exposed, modified, or exfiltrated. All testing used isolated copies or sanitised test environments. The integrity of the actual voter registration database was the absolute constraint.

 

We also tested the elections office’s communications response capability during the heightened-attention environment of an election period.

The Purple Team Approach

Voter Registration Portal Security Assessment

Tested the publicly-accessible voter registration lookup portal for SQL injection. Found: the portal was vulnerable to SQL injection allowing retrieval of individual voter records without authentication.

SQL Injection Demonstration (Isolated Copy)

Demonstrated the vulnerability against an isolated database copy sanitised of all real voter data. The vulnerability allowed retrieval of voter demographic information, not bulk export, but sufficient for targeted voter record manipulation.

EMS Air-Gap Validation

Found: EMS was air-gapped as documented. One USB port was active and uncontrolled, a physical access risk documented in CISA's EMS security guidance.

Election Night Reporting System Testing

Found: the platform used default credentials for the administrative interface and had not been patched in 14 months. A public CVE existed for the underlying CMS.

Social Media Account Access Testing

Found: 2 of 3 official elections social media accounts lacked MFA, a documented disinformation attack vector from prior election cycles.

CISA/EAC Evidence Documentation

Documented all findings in CISA Election Security Initiative and EAC VVSG 2.0 evidence format, producing documentation that CISA election security coordinators and state election officials requested.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1190 Exploit Public-Facing Voter Registration Portal (SQL Injection) SUCCESS ON ISOLATED COPY

Vulnerability confirmed against sanitised test environment.

T1078 Valid Accounts (Election Night Reporting Default Credentials) SUCCESS

Default admin credentials active on reporting platform.

T1566 Phishing (Elections Office Staff) DETECTED

Email security quarantined 4 of 5 simulated phishing emails.

T1491 Defacement (Election Night Reporting System) DEMONSTRATED

Default credentials would enable result manipulation.

T1098 Account Manipulation (Social Media Accounts) DEMONSTRATED

MFA absent, account takeover achievable via credential stuffing.

Key Findings

Critical

SQL Injection in Voter Registration Portal:

The publicly-accessible voter registration lookup portal was vulnerable to SQL injection, enabling targeted retrieval of individual voter records, consistent with the targeted manipulation documented in CISA’s 2016 and 2020 election security post-mortems.

Critical

Default Credentials on Election Night Reporting Platform:

An attacker with internet access could log in, modify displayed results during election night, and publish false results before official certification, a high-impact disinformation scenario with significant public trust consequences.

High

2 Official Social Media Accounts Without MFA:

Account takeover enabling publication of false election night information is a documented disinformation technique from prior election cycles. CISA specifically identifies social media account security as high-priority.

MEDIUM

Uncontrolled USB Port on EMS:

Physical access would be required, but the active USB port represents the primary remaining attack vector against an otherwise properly air-gapped EMS.

Measurable Outcomes

SQL Injection Voter registration portal patched within 7 days
Election Night Default Credentials Changed and MFA enforced within 24 hours
Social Media MFA MFA enabled on all 3 official accounts within 24 hours
EMS USB Port Port physically disabled and documented in physical security log
CMS Patching Election night reporting platform patched within 14 days
CISA Election Security Findings shared with CISA State Election Security Coordinator

Regulatory Impact

The SQL injection vulnerability was shared with the CISA State Election Security Coordinator, consistent with CISA’s recommended disclosure process. CISA provided technical assistance with patch validation and offered enhanced monitoring during the election period.

 

The default credentials on the election night reporting platform have direct HAVA implications. HAVA requires states to implement voting system security standards. The election night reporting infrastructure is subject to the broader election security programme that HAVA funds.

 

The exercise documentation was submitted to the State Election Security Coordinator as part of the county’s contribution to the state’s CISA election security planning process.

Default credentials on the system we use to publish election results on election night. Social media accounts without MFA on the accounts our residents follow for real-time election updates. These are not sophisticated attacks. Any one of them could have generated a disinformation event that damaged public confidence in the election. We found them 6 months before the election, not on election night.

— County Elections Director (anonymised)

Key Takeaways

Book a Free State & Local Government Purple Team Discovery Call

GLI Secure | ISO 17025 Accredited

Strengthen your cybersecurity posture today.

Strengthen your cybersecurity posture and protect your organization from evolving threats. Discover how GLI Secure reduces risk, simplifies compliance, and protects customer trust.

Font Resize