
Municipal cybersecurity in Puerto Rico: realistic priorities
Priorities for towns and agencies: identity, backups, awareness, and response on limited budgets.
Municipalities and agencies in Puerto Rico operate on IT budgets a fraction of private sector — but citizen data and critical services attract ransomware like enterprise. CISA SLTT guidance prioritizes identity, backups, patches, and awareness as "must do" before expensive SIEM. NIST CSF tier 1-2 is realistic goal for mid-size municipality; tier 4 is fantasy without federal funding.
Priority 1 — Identity: MFA on M365/Google government tenants, disable former employee accounts within 24h, separate admin accounts without email browsing. Priority 2 — Backups: citizen data, payroll, permits — offline copy outside municipal network. Priority 3 — Awareness: municipal employees are phishing targets like corporate; quarterly Spanish simulations.
Incident response: pre-established contact with CISA (reports), MS-ISAC if eligible, and IR vendor with minimum retainer. Prepared public communication template — local PR press does not forgive silence when online payments fail. Bruce Schneier emphasizes post-breach transparency where legally possible.
Regional collaboration: share IOCs between municipalities, joint EDR procurement, shared training reduces per capita cost. Mainland vendors serving PR government must understand territorial context — federal compliance plus local regulation.
18-month roadmap: Q1 quick wins, Q2 basic segmentation, Q3 pre-hurricane tabletop, Q4 light audit. Measure progress for legislature and citizens — municipal security is public trust, not just IT project.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


