Home / Purple Team Services / Goverment Sector
State & Local Government Sector
Three Real-World Purple Team Engagements | Fully Anonymised | ISO 17025 Accredited Methodology
ISO 17025 Accredited · MITRE ATT&CK v15 · All engagements conducted under explicit written authorisation
Sector
State & Local Government
Engagement
Purple Team Exercise
ATT&CK Tactics
MITRE ATT&CK v15
Location
United States
About These Case Studies
The following case studies describe real purple team engagements conducted by GLI Secure across insurance sector organisations. All identifying details , organisation names, locations, system names, and personnel , have been fully anonymised. Statistical outcomes, detection improvements, and regulatory findings are accurate as documented during and after each engagement.
All purple team exercises described in this document were conducted under explicit written authorisation from the client organisation, using GLI Secure’s ISO 17025-accredited testing methodology. MITRE ATT&CK technique IDs are referenced as documented in ATT&CK Enterprise Framework v15.
Confidentiality Notice: These case studies anonymised; any resemblance to specific organisations is coincidental.
Case Study INS-CS-01
Municipal Ransomware Simulation, Mid-Sized US City
Testing essential services continuity and recovery capability against a Royal ransomware attack profile
Organisation
A mid-sized US city government with 3,200 employees and a $180M annual operating budget (anonymised)
Sector
State & Local Government, Municipal government
Location
Upper Midwest, United States
Engagement
Purple Team Exercise, Ransomware Simulation and Government Business Continuity
Duration
7 weeks (3-week planning, 2-day exercise, 2-week SLCGP documentation)
Frameworks
CISA SLCGP Grant Requirements | CJIS Security Policy 5.9 | NIST SP 800-53 Rev 5 | State cybersecurity mandate | MITRE ATT&CK Enterprise v15
The Situation
Between 2018 and 2024, ransomware attacks on US government entities cost an estimated $1.09 billion in downtime alone. The city’s IT Director had tracked every significant municipal ransomware incident, Baltimore ($10-18M), Atlanta ($17M), Tulsa. He had one question he could not answer: how long would his city be down?
The city operated finance and payroll, permitting and inspections, police records management (CJIS-governed), 911 Computer Aided Dispatch (CAD), utility billing, and citizen services. A ransomware event encrypting all of these simultaneously would halt the entire city government.
The state had recently passed a cybersecurity mandate requiring all local government entities to complete a risk assessment and develop a cybersecurity plan. The IT Director saw the purple team exercise as the mechanism for meeting both the state mandate requirement and the SLCGP grant documentation requirement.
Core Challenge
Determine how long the city would be operationally paralysed following a realistic ransomware attack, whether essential services (911 dispatch, police records, payroll) could be maintained in manual mode, and identify the specific gaps that SLCGP grant funding should address.
What GLI Secure Did
The exercise combined a technical simulation and a government operations stress test. The technical component tested ransomware detection capability and backup integrity. The operations component tested whether each city department could maintain minimum essential services during an extended IT outage.
We selected the Royal ransomware group attack profile because Royal was specifically documented by CISA as targeting US municipal governments in its 2023 Stop Ransomware advisory.
Recovery timeline modelling was the most consequential output: measuring the realistic time to restore each critical city system from available backups.
The Purple Team Approach
Critical Asset Inventory and Recovery Priority
Mapped all city systems by operational criticality: Tier 1 (911 CAD, CJIS police records, life safety), Tier 2 (payroll, utility billing, service continuity), Tier 3 (permitting, citizen portal). Found: 911 CAD and CJIS had no offline backups and no documented manual fallback procedure.
Network Architecture Assessment
Finding: completely flat network across all departments. A single compromised workstation anywhere in the city government had unrestricted access to 911 CAD, police records management, and all administrative systems.
Initial Access Simulation (Royal Profile)
Simulated Royal's documented initial access: exploitation of unpatched internet-facing VPN. Found: city VPN appliance running firmware 19 months out of date with a Critical CVE exploited in the comparable municipal attack.
Backup Integrity Testing
Found: 911 CAD had no backup. CJIS police RMS backup was 4 months old, backup jobs had been failing since a storage migration. Payroll system restoration took 61 hours, exceeding the bi-weekly payroll cycle.
Essential Services Continuity Testing
Activated manual procedures for Tier 1 systems. Found: only 2 of 7 departments had staff who could execute their manual continuity procedures. Police dispatch manual protocol had not been practised in 3 years.
SLCGP Documentation
Documented all gaps in SLCGP application format: specific control deficiencies, risk narrative, proposed remediation, NIST CSF mapping, and cost estimates for grant-eligible improvements.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | Technique | Detection Result |
|---|---|---|
| T1190 | Exploit Public-Facing VPN (Royal Profile) |
Not Detected
No monitoring on VPN authentication anomalies. |
| T1021 | Lateral Movement (Flat Network) |
Not Detected
No east-west traffic monitoring. |
| T1486 | Data Encrypted for Impact (Multiple Departments) |
Partial
No ransomware behavioural detection on city servers. |
| T1490 | Inhibit System Recovery (Backup Access) |
Not Detected
Backups network-accessible with no monitoring. |
| T1489 | Service Stop (911 CAD, Police RMS) |
Not Detected
No service health monitoring with alert capability. |
| T1566 | Phishing (Staff Account Alternative) |
Detected
Email security quarantined simulated phishing in 3 minutes. |
Key Findings
Critical
911 CAD Has No Backup:
The city’s 911 Computer Aided Dispatch system had no backup of any kind. In a ransomware event, 911 dispatch would revert to telephone-only protocol indefinitely, a life safety issue and a NIST SP 800-34 continuity planning gap.
Critical
CJIS Police RMS Backup 4 Months Old:
Backup jobs had been failing silently for 4 months following a storage migration. In a ransomware event, 4 months of police records would be lost, a CJIS Security Policy violation with FBI audit implications.
Critical
Payroll Recovery Exceeds Payroll Cycle:
61-hour payroll system restoration time exceeds the bi-weekly payroll cycle. City employees could miss a payroll event, a public service and labour relations crisis.
High
VPN with Critical Exploited CVE:
The CVE was documented as exploited in the Royal ransomware municipal attack profile. Patched within 48 hours of the exercise.
High
Manual Continuity Procedures Not Exercised:
5 of 7 departments had continuity procedures that no current staff member had ever executed.
Measurable Outcomes
| VPN CVE | Patched within 48 hours |
| 911 CAD Backup | Offline backup solution implemented within 45 days |
| CJIS Backup Monitoring | Backup job monitoring with failure alerting, FBI audit cleared |
| Payroll RTO | Improved, RTO reduced to 18 hours |
| SLCGP Grant Application | Submitted using exercise documentation |
| SLCGP Grant Awarded | $1.2M for network segmentation, EDR, and backup infrastructure |
| State Mandate Compliance | Exercise documentation accepted as risk assessment and cybersecurity plan |
Regulatory Impact
The CJIS police RMS backup failure had direct FBI audit implications. The CJIS Security Policy requires criminal justice information to be protected with appropriate backup and recovery procedures. The city reported the backup failure to the state CJIS Systems Officer as required.
The exercise documentation was submitted to the state as the risk assessment required under the state cybersecurity mandate, satisfying the mandate’s annual assessment requirement while simultaneously producing the SLCGP grant documentation.
The 911 CAD finding had potential state tort liability implications beyond cybersecurity. A ransomware event disrupting 911 dispatch services could trigger liability claims from individuals who suffered harm during the disruption. The city’s general counsel was briefed within 24 hours.
“
We had a business continuity plan. What we did not have was staff who had ever executed it, backups that had been tested, or any idea how long we would actually be down. The purple team exercise told us we would be down for weeks if ransomware hit us that day. It also found us $1.2 million in federal grant funding to fix the worst gaps.
— IT Director, Municipal Government (anonymised)
Key Takeaways
- Government business continuity plans must be operationally tested by the staff who would execute them, not just documented. Plans that exist only on paper are not plans.
- 911 CAD and CJIS police RMS are life safety and federal compliance systems requiring the highest-priority backup investment in any municipal government environment. They are also the most commonly underfunded.
- SLCGP grant documentation is a direct byproduct of a well-structured purple team exercise. The gap documentation that exercises produce is exactly what grant applications require.
- Silent backup failures are a systemic vulnerability in government IT environments where IT staff manage dozens of systems with minimal monitoring. Backup job monitoring with failure alerting prevents catastrophic data loss.
Ready to test your State & Local Government security defences?
Case Study INS-CS-02
Water Treatment OT Attack, Municipal Utility Authority
Testing IT/OT segmentation and SCADA security against a Salt Typhoon-profile attack on municipal water infrastructure
Organisation
A municipal water authority serving 280,000 residents with 3 treatment facilities and 12 pump stations (anonymised)
Sector
State & Local Government, Municipal water utility, critical infrastructure
Location
Mid-Atlantic United States
Engagement
Purple Team Exercise, OT/ICS Security Validation and Water Infrastructure Resilience
Duration
10 weeks (5-week OT asset inventory, 3-day exercise, 2-week EPA/AWIA compliance report)
Frameworks
EPA AWIA 2018 | CISA ICS-CERT Advisories | NIST SP 800-82 Rev 3 | EPA Water Sector Cybersecurity Strategy 2024 | MITRE ATT&CK for ICS v15
The Situation
In April 2024, CISA and EPA issued a joint advisory warning that Iranian-backed threat actors had targeted US water sector OT systems. In November 2024, CISA documented Salt Typhoon (China) pre-positioning within US critical infrastructure including water systems. The water authority’s IT Director had a gnawing concern: the treatment plant SCADA systems were supposed to be air-gapped, but IT staff had connected them to the corporate network for remote monitoring purposes. Nobody could tell him exactly what was connected to what anymore.
EPA’s AWIA 2018 required the authority to complete a Risk and Resilience Assessment and Emergency Response Plan every 5 years. The cycle was approaching. The authority engaged GLI Secure to conduct a purple team exercise that would both validate the OT security posture and produce the documented findings required for the AWIA RRA update.
Core Challenge
Determine whether the IT/OT network boundary was intact, whether SCADA systems controlling water treatment processes were accessible from the corporate network, and whether any such access would be detected, using a Salt Typhoon pre-positioning attack profile.
What GLI Secure Did
We began with a five-week OT asset discovery phase. The water authority’s network documentation was outdated; actual connectivity between IT, OT, and SCADA systems had evolved through years of incremental changes never fully documented.
The OT asset discovery produced the first accurate network diagram the authority had ever had, mapping 847 connected devices across the IT network, the OT DMZ, and the SCADA control network.
The exercise tested the security of the IT/OT boundary and SCADA systems using passive and minimally-invasive OT testing methodologies, specifically designed not to disrupt water treatment operations under any circumstances.
The Purple Team Approach
OT Asset Discovery and Network Mapping
Produced: 847-device inventory, accurate network diagram showing IT/OT connectivity, and identification of 14 devices on the SCADA network with no documented owner or business justification.
IT/OT Boundary Assessment
Found: 6 connections between corporate IT and the OT DMZ not in documented network architecture. 3 of these permitted communication from the corporate network to OT-zone systems without traversing a monitored firewall.
Salt Typhoon Pre-Positioning Simulation
Using low-and-slow LOTL techniques consistent with Volt Typhoon/Salt Typhoon TTPs, no custom malware, tested whether the IT network could be accessed without generating alerts. Result: no detection across a simulated 3-day dwell period.
IT to OT Lateral Movement Testing
From a simulated compromised IT workstation, tested whether the 3 undocumented connections permitted lateral movement to the OT network. Found: 2 of 3 permitted connectivity to OT-zone systems. 1 permitted direct access to an engineering workstation with Wonderware SCADA software.
SCADA Engineering Workstation Access (Isolated Environment)
Using an isolated test environment replicating the SCADA engineering workstation configuration, demonstrated the access achievable once the workstation was reached. Found: default credentials were still active on the test system replica.
EPA AWIA RRA Documentation
Documented all findings in the AWIA 2018 Risk and Resilience Assessment format, including threat scenarios, consequence analysis, current countermeasures, and recommended improvements.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | Technique | Detection Result |
|---|---|---|
| T1199 | Exploit Public-Facing Application (IT Initial Access) |
Partial
VPN patched. Web app vulnerability found but not exploited. |
| T1078 | Valid Accounts (LOTL Technique) |
Not Detected
No UEBA baseline on IT network. LOTL dwell undetected 3 days. |
| T0812 | Default Credentials (ICS, Engineering Workstation Replica) |
SUCCESS ON REPLICA
Default credentials active on isolated test system. |
| T0866 | Exploitation of Remote Services (OT DMZ Access) |
Not Detected
No monitoring on IT-to-OT DMZ connections. |
| T0817 | Drive-by Compromise (OT Network Enumeration) |
Not Detected
No IDS/IPS on OT network. Passive enumeration undetected. |
Key Findings
Critical
3 Undocumented IT-to-OT Network Connections:
Two of three undocumented connections permitted lateral movement from IT to OT without traversing a monitored security boundary, the pre-conditions for a Salt Typhoon-style pre-positioning attack on water infrastructure.
Critical
SCADA Engineering Workstation Reachable from IT Network:
The Wonderware SCADA engineering workstation was reachable via one of the undocumented connections. Access to this workstation would provide an attacker with ability to modify water treatment parameters, the scenario of the 2021 Oldsmar, Florida water treatment attack.
High
Default Credentials on OT Systems:
The isolated test replica had default credentials active. The production systems were assessed for default credential risk and 7 were found with default credentials still configured.
High
Zero OT Network Monitoring:
The OT network, containing all SCADA and ICS for three water treatment facilities, had no security monitoring infrastructure.
medium
3-Day LOTL Dwell Undetected:
Low-and-slow LOTL techniques consistent with Salt Typhoon remained undetected across a simulated 3-day dwell period on the IT network. No UEBA baseline existed.
Measurable Outcomes
| Undocumented IT-OT Connections | All 3 removed or gated through monitored firewall |
| SCADA Engineering Workstation | Isolated to OT network, no IT network path remaining |
| Default Credentials | Remediated on all 7 identified OT systems |
| OT Network Monitoring | Passive IDS deployed at all three treatment facilities |
| EPA AWIA RRA | 5-year Risk and Resilience Assessment documentation completed |
| CISA Notification | Authority enrolled in CISA water sector cyber hygiene services |
Regulatory Impact
The exercise produced the documentation required for the AWIA 2018 5-year RRA cycle. The EPA has made clear that cyber threats must be explicitly addressed in water utility RRAs.
The reachable SCADA engineering workstation with documented default credentials was reported to CISA’s water sector cybersecurity team, consistent with EPA’s guidance that water utilities report vulnerabilities enabling tampering with treatment processes.
The undocumented IT-to-OT connections represented a direct NIST SP 800-82 Rev 3 architecture gap. NIST SP 800-82 Rev 3 recommends all IT-OT communication route through a monitored DMZ, the undocumented connections bypassed this entirely.
“
I knew there were some connections between our IT and OT networks that shouldn’t be there, but I could not have told you where they were. Five weeks of OT asset discovery later, we had a network diagram that showed exactly what was connected to what, and it was much worse than I expected. One of those undocumented connections went straight to the engineering workstation that controls our chemical dosing systems.
— IT Director, Municipal Water Authority (anonymised)
Key Takeaways
- The assumption that OT systems are air-gapped is one of the most dangerous in critical infrastructure security. Undocumented IT-OT connections created through years of incremental operational changes are present in almost every water utility assessed.
- OT asset discovery is the prerequisite for all water sector OT security. Most water utilities have significant OT systems invisible to their IT security teams.
- AWIA 2018 RRA documentation and cybersecurity assessment findings are directly complementary. Structuring the exercise to produce EPA-required documentation maximises the return on the engagement.
- Default credentials on SCADA systems remain one of the most common and highest-impact OT vulnerabilities. CISA has documented Volt Typhoon specifically exploiting OT default credentials.
Ready to test your State & Local Government security defences?
Case Study INS-CS-03
Election Systems Security, State County Elections Office
Testing voter registration infrastructure and election management system security ahead of a general election cycle
Organisation
A county elections office managing approximately 340,000 registered voters (anonymised)
Sector
State & Local Government, County elections administration
Location
Battleground state, United States
Engagement
Purple Team Exercise, Election Infrastructure Security and Integrity Validation
Duration
8 weeks (4-week planning and scoping, 2-day exercise, 2-week CISA/EAC evidence documentation)
Frameworks
CISA Election Security Initiative | EAC VVSG 2.0 | HAVA | MITRE ATT&CK Enterprise v15
The Situation
The county elections office operated voter registration infrastructure, an election management system (EMS), and election night reporting systems for 340,000 registered voters. The elections director had tracked documented adversary activity through CISA’s election security briefings, including activity attributed to Russian GRU/SVR, Iranian APT33/35, and Chinese actors in both the 2020 and 2022 election cycles.
The most concerning threat was not the EMS, which was supposed to be air-gapped, but the voter registration database and the election night reporting system. Both were internet-connected. Both had been identified as targets in CISA’s election security advisories. Neither had ever been independently security tested.
The elections director wanted to test before the election cycle, not during it, with sufficient time to remediate all critical findings.
Core Challenge
Determine whether the county’s voter registration database, election management system, and election night reporting systems were vulnerable to the specific attack techniques documented in CISA’s election security advisories, and whether any attack activity would be detected.
What GLI Secure Did
The exercise was structured around the specific attack techniques documented in CISA’s election security advisories: SQL injection against voter registration portals, credential attacks against election night reporting systems, and social media account takeover for result manipulation.
The exercise was conducted with specific safety constraints: no production voter registration data was at any point exposed, modified, or exfiltrated. All testing used isolated copies or sanitised test environments. The integrity of the actual voter registration database was the absolute constraint.
We also tested the elections office’s communications response capability during the heightened-attention environment of an election period.
The Purple Team Approach
Voter Registration Portal Security Assessment
Tested the publicly-accessible voter registration lookup portal for SQL injection. Found: the portal was vulnerable to SQL injection allowing retrieval of individual voter records without authentication.
SQL Injection Demonstration (Isolated Copy)
Demonstrated the vulnerability against an isolated database copy sanitised of all real voter data. The vulnerability allowed retrieval of voter demographic information, not bulk export, but sufficient for targeted voter record manipulation.
EMS Air-Gap Validation
Found: EMS was air-gapped as documented. One USB port was active and uncontrolled, a physical access risk documented in CISA's EMS security guidance.
Election Night Reporting System Testing
Found: the platform used default credentials for the administrative interface and had not been patched in 14 months. A public CVE existed for the underlying CMS.
Social Media Account Access Testing
Found: 2 of 3 official elections social media accounts lacked MFA, a documented disinformation attack vector from prior election cycles.
CISA/EAC Evidence Documentation
Documented all findings in CISA Election Security Initiative and EAC VVSG 2.0 evidence format, producing documentation that CISA election security coordinators and state election officials requested.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | Technique | Detection Result |
|---|---|---|
| T1190 | Exploit Public-Facing Voter Registration Portal (SQL Injection) |
SUCCESS ON ISOLATED COPY
Vulnerability confirmed against sanitised test environment. |
| T1078 | Valid Accounts (Election Night Reporting Default Credentials) |
SUCCESS
Default admin credentials active on reporting platform. |
| T1566 | Phishing (Elections Office Staff) |
DETECTED
Email security quarantined 4 of 5 simulated phishing emails. |
| T1491 | Defacement (Election Night Reporting System) |
DEMONSTRATED
Default credentials would enable result manipulation. |
| T1098 | Account Manipulation (Social Media Accounts) |
DEMONSTRATED
MFA absent, account takeover achievable via credential stuffing. |
Key Findings
Critical
SQL Injection in Voter Registration Portal:
The publicly-accessible voter registration lookup portal was vulnerable to SQL injection, enabling targeted retrieval of individual voter records, consistent with the targeted manipulation documented in CISA’s 2016 and 2020 election security post-mortems.
Critical
Default Credentials on Election Night Reporting Platform:
An attacker with internet access could log in, modify displayed results during election night, and publish false results before official certification, a high-impact disinformation scenario with significant public trust consequences.
High
2 Official Social Media Accounts Without MFA:
Account takeover enabling publication of false election night information is a documented disinformation technique from prior election cycles. CISA specifically identifies social media account security as high-priority.
MEDIUM
Uncontrolled USB Port on EMS:
Physical access would be required, but the active USB port represents the primary remaining attack vector against an otherwise properly air-gapped EMS.
Measurable Outcomes
| SQL Injection | Voter registration portal patched within 7 days |
| Election Night Default Credentials | Changed and MFA enforced within 24 hours |
| Social Media MFA | MFA enabled on all 3 official accounts within 24 hours |
| EMS USB Port | Port physically disabled and documented in physical security log |
| CMS Patching | Election night reporting platform patched within 14 days |
| CISA Election Security | Findings shared with CISA State Election Security Coordinator |
Regulatory Impact
The SQL injection vulnerability was shared with the CISA State Election Security Coordinator, consistent with CISA’s recommended disclosure process. CISA provided technical assistance with patch validation and offered enhanced monitoring during the election period.
The default credentials on the election night reporting platform have direct HAVA implications. HAVA requires states to implement voting system security standards. The election night reporting infrastructure is subject to the broader election security programme that HAVA funds.
The exercise documentation was submitted to the State Election Security Coordinator as part of the county’s contribution to the state’s CISA election security planning process.
“
Default credentials on the system we use to publish election results on election night. Social media accounts without MFA on the accounts our residents follow for real-time election updates. These are not sophisticated attacks. Any one of them could have generated a disinformation event that damaged public confidence in the election. We found them 6 months before the election, not on election night.
— County Elections Director (anonymised)
Key Takeaways
- Election night reporting infrastructure is the highest-impact disinformation attack surface in county elections administration. Default credentials and missing MFA on results publication platforms have outsized public trust consequences.
- Voter registration portals are internet-accessible systems requiring rigorous security testing. SQL injection vulnerabilities in voter registration lookup interfaces are a documented election security concern that CISA specifically identifies.
- Social media account security for official government accounts requires MFA as a minimum control. Account takeover enabling false information publication during an election is a repeatable attack technique.
- Election infrastructure security exercises are most valuable when conducted well before an election cycle, the 6-month lead time provided sufficient time to remediate all critical findings and engage with CISA.
Book a Free State & Local Government Purple Team Discovery Call
GLI Secure | ISO 17025 Accredited
Strengthen your cybersecurity posture today.
Strengthen your cybersecurity posture and protect your organization from evolving threats. Discover how GLI Secure reduces risk, simplifies compliance, and protects customer trust.