
One system handles cybersecurity. That one handles loss prevention and insurance risk. Meanwhile, oversight of federal grants and constituent services lives in an entirely different system.
Does this scenario sound familiar? If the answer is yes and you’re responsible for maintaining security, compliance, business continuity and public trust in state or local government, it’s time to rethink business as usual.
Getting ahead of change and threats today means seeing the full risk picture — without blind spots, without delays and with accountability and action built in. This demands a fresh approach. Read on for why, and how the right technology can help.
Due to spending cuts and budget scrutiny, too many state and local agencies are continuing to manage cyber risk and IT compliance via spreadsheets, email chains, manual processes and siloed legacy systems. Problems ranging from detection lag to contradictory reporting challenge the organization as the attack surface expands and risk gets even more complicated.
Cybersecurity alone covers an ever-expanding array of threats, from phishing and social engineering to deep fakes and AI-powered malware, with frameworks like FISMA and CIS that are increasingly relevant at the state and local level.
Given the scope of what public sector organizations are responsible for, there's so much more to track. As data and requirements continue to grow and grow, manual processes keep public sector agencies in perpetual catch-up mode.
As my colleague Jason Venner, a Diligent director who spent 20 years leading and managing public sector risk and audit teams at transportation organizations and US government agencies, points out, “Whether you're talking about enterprise risk, IT risk, fraud risk, whatever the case may be, you just can’t manage it all chasing documents and spreadsheets through phone calls and email chains.”
To compound the problem, too many agencies manage threats at the department level, through siloed systems. This compromises reporting, response and remediation.
Here’s an example to illustrate:
An agency is able to identify dozens, even hundreds, of risks. But then processes break down. There’s no defensible way of determining which issue requires attention and resources. The risk register, if one exists at all, lives in a spreadsheet that only gets updated before the yearly budget cycle or an audit committee meeting.
Between these annual cycles, nothing is actively monitoring for emerging risk. When a risk is flagged for remediation, no tracking mechanism holds specific teams or staff accountable.
So, how do state and local government risk teams achieve the visibility, accountability and action they need today?
First, bring all those silos and systems together into one place: Audit findings, incident reports, vendor assessments, vulnerability scans. Leaders need centralized visibility across them all, from the most urgent cyber threats to the status of internal controls.
Risk consolidation especially matters for public sector organizations because they’re answering to so many different stakeholders: boards, legislatures, accreditors, taxpayers and the general public, all expecting a defensible, documented risk process.
Secondly, make risk management continuous. Organizations that do so catch things earlier, spending less time firefighting and more time addressing root causes.
Importantly, a governance, risk and compliance (GRC) solution that automates, orchestrates and centralizes work across functions helps lean public sector teams prioritize limited resources.
Delivering status updates via one real-time platform, rather than constructing them by hand, is one example. Teams can save hours, days, even weeks' worth of work while reducing the chance of something important falling through the cracks.
IT, risk and compliance professionals can free up even more time by automating routine administrative tasks. Some examples to consider include routing assessments for review, flagging overdue remediation items and aggregating status updates.
Automation speeds up the work teams already know how to do. AI goes a step further: it surfaces risks and patterns no one knew to look for in the first place. When data that used to live in separate systems and spreadsheets is connected, AI's anomaly-finding capabilities can flag things no single team, looking only at its own silo, would catch on its own, like a vendor contract that keeps coming in above market rate, a spending pattern that repeats across departments, or a control gap that shows up in multiple business units. That shift, from reactive review to continuous pattern detection, is what turns AI from a nice-to-have into a genuine force multiplier for lean teams.
Here's a real-world example illustrating the value, from Scott Bridgen, Diligent's General Manager of Risk and Audit. One local government client, an early adopter of Diligent's ACL AI capability, used its anomaly-finding tools to catch spending leakage in petty cash and vendor contracts before it became a bigger problem.
"They used AI to look at that data — where it was coming from, the repeatable patterns, the individuals involved," Scott recalls. "In the first six months, they saved roughly $400,000."
That's the kind of return that becomes possible when automation handles the busywork and AI takes on the pattern recognition, freeing risk and compliance teams to spend their time on judgment calls instead of data gathering.
Guided by insights like these, Diligent’s AI- and analytics-powered platform moves state and local IT and risk leaders into the future:
Take the next step to better visibility, readiness, responsiveness and efficiency. Learn more about Diligent cyber risk and IT compliance solutions.