Public Sector · NIS2 & OZG

One breach at your IT provider
can take down dozens of towns at once

Under NIS2, public administration falls into the “state and administration” sector and has to demonstrate adequate security measures. For online services delivered under Germany's Online Access Act (OZG), the Portal Network Security Ordinance (ITSiV-PV) issued by the Federal Ministry of the Interior additionally requires regular web checks and penetration tests carried out by BSI-certified providers. One risk stands out: many municipalities don't run their own IT, they rely on a shared municipal IT provider, so a single successful breach can take down dozens of towns at once. Citizen portals, specialized administrative software, and the connection to the shared provider: those are the three places we focus on.

ITSiV-PV-ready test reports Experience with municipal IT & legacy systems Free initial consultation
Night of October 29–30, 2023 Ransomware attack on Südwestfalen-IT. Up to 103 municipalities ran in emergency mode for weeks (per heise online).
Real-world incident

What the Südwestfalen-IT breach teaches every municipality

On the night of October 29 to 30, 2023, a ransomware attack hit Südwestfalen-IT, the shared municipal IT provider for a large part of the Südwestfalen region. What happened next is a textbook example of what a single point of failure means for municipal IT.

Südwestfalen-IT · Night of October 29-30, 2023 · Group “Akira” (per media reports)
  1. 01

    Compromised VPN access

    According to media reports, the attackers got in through a compromised VPN access, the classic entry point for externally reachable remote-access systems.

  2. 02

    Spread into the provider's network

    From that single access point, the attackers moved through the provider's internal network, the same network dozens of municipalities had connected their own administrative IT to.

  3. 03

    Ransomware encryption

    The group “Akira” then encrypted core systems at Südwestfalen-IT. Because so many municipalities were tied into the same infrastructure, the encryption didn't hit one administration, it hit an entire region at once.

  4. 04

    Weeks of emergency operations for up to 103 municipalities

    According to heise online, up to 103 municipalities had to run in emergency mode for weeks, with limited access to citizen portals, administrative software, and internal systems.

What this means

The lesson for your municipality

The Südwestfalen-IT case didn't hit a big city with its own IT department, it hit the exact setup most common across Germany: small and mid-sized municipalities sourcing IT from a shared provider. The target wasn't any single municipality, it was the shared infrastructure they were all plugged into.

Similar incidents also affected the town of Mössingen (November 17, 2023) and, in 2025, two Berlin Senate administrations, attributed to the group “Rhysida”.

Based on public reporting (including heise online). accessgranted was not involved in this incident.

Dependency map

One provider, many municipalities, one shared attack surface

Public administration combines publicly reachable citizen services with legacy administrative software and constant foot traffic. When many municipalities also hang off the same central infrastructure, a single compromised access is enough for an incident to travel along those connections to every administration attached to it.

01 VPN access 02 · 03 Municipal IT provider 04 Municipality Municipality Municipality Municipality Municipality Municipality Municipality
  • Entry point: one compromised remote access
  • Shared infrastructure: the joint municipal IT provider
  • Connected municipalities: all affected at the same time
Where we start
  1. A

    Citizen portals

    Online application workflows for ID cards, vehicle registration, or housing benefits are publicly reachable and a direct target for attackers after citizen data or a foothold into backend systems.

  2. B

    Legacy administrative software

    Specialized software for registration offices, social services, or building authorities has often grown over decades, was rarely designed for today's threats, and is hard to replace quickly.

  3. C

    Shared IT provider

    When many municipalities run on the same central infrastructure, one successful attack becomes an incident for dozens of administrations at once, exactly what happened at Südwestfalen-IT.

  4. D

    Public foot traffic at town halls & citizen offices

    Open service counters, many separate locations, and direct contact with citizens make pretexting and unauthorized entry easier in an environment built for accessibility rather than security.

Regulatory framework

Two obligations, one underlying question

Public administration is regulated from two directions at once: NIS2 across the board, and the OZG specifically for digital citizen services. Both come down to the same question: is your IT actually as secure as it needs to be?

NIS2 / BSIG

State and administration as its own sector

Annex 1 of the German BSIG lists “state and administration” as its own sector. Municipalities that reach the relevant thresholds face the same obligations as energy providers or hospitals, including registration with the BSI and mandatory incident reporting.

OZG / ITSiV-PV

Mandatory testing for online administrative services

For services delivered through the OZG portal network, the ITSiV-PV requires regular web checks and penetration tests from BSI-certified providers. BSI IT-Grundschutz remains the general reference framework, and GDPR applies on top for all citizen data.

Registration and reporting obligations apply regardless of whether a municipality runs its own IT or sources it from a shared provider.

Who this matters to

Who decides in local government, and what usually gets in the way

A pentest for a municipality rarely has a single decision-maker. In practice you'll find the IT director or head of the IT department, the municipal IT provider itself, an information security officer or CISO, the mayor or treasurer controlling the budget, and the data protection officer at the table, each with different priorities.

The most common objections

  1. 01

    Tight budgets

    Municipal budgets are planned tightly and security competes with many other mandatory tasks. A clearly scoped, fixed-price engagement keeps the cost predictable from the start.

  2. 02

    Procurement law complicates the process

    Public buyers have to follow tender and procurement rules, security services included. We structure our offers so they work equally well for direct awards below the relevant thresholds and as the basis for a formal tender.

  3. 03

    Unclear responsibility: municipality or IT provider?

    It's often unclear who owns which part of the infrastructure, the individual municipality or the shared IT provider. We clarify this during scoping so the test targets what's actually within your responsibility.

  4. 04

    “We're too small to be a target”

    That was exactly the assumption in the Südwestfalen-IT case, and it was wrong. The target wasn't the small individual municipality, it was the shared infrastructure it was plugged into. Size doesn't protect you when the attack surface is shared.

Procurement-ready approach

Five points that are part of every offer we make to a municipality

Administrative processes and procurement law run differently than in the private sector. So instead of a step-by-step timeline, here is what you can hold us to, from the first conversation to the final report.

  • Fixed-price offer with a defined scope of work

    You get an offer with a clear scope of work, a fixed price, and a traceable cost breakdown. We define the scope together beforehand: which systems fall under your own responsibility and which run through the municipal IT provider.

  • Direct-award thresholds respected

    Direct awards are subject to value thresholds that vary by state and municipality. We tailor scope and offer so they can stay below those thresholds, or we prepare the documents so they hold up as the basis for a formal tender.

  • ITSiV-PV-ready report with management summary

    Every finding is rated by severity, exploitability, and impact on citizen services and administrative operations. The final report documents web checks and penetration test in a form you can use as evidence for ITSiV-PV and NIS2, with a management summary for IT leadership, department heads, and administrative leadership.

  • Named emergency contact

    For the duration of the test, a named contact is available on both sides. If a critical risk surfaces during testing, we tell you immediately rather than waiting for the final report.

  • No interruption of citizen services

    Citizen portals, administrative software, and network are tested manually and within the agreed scope. Test windows are agreed in advance, destructive tests are excluded, and live citizen services keep running.

Relevant modules

These tests bring your admin IT up to standard

Citizen portals, specialized software, and the town hall itself can't be ticked off with one test. These are the modules we typically bring together for municipalities.

01

Physical Pentest

Simulated entry attempts at citizen offices, town halls, and server rooms. Covers the physical attack surface that matters most where public foot traffic is high.

Learn more
02

Social Engineering

Phishing and pretexting simulations tailored to direct citizen contact and how caseworkers actually operate.

Learn more
03

Infrastructure Pentest

Focused on network segmentation, VPN access, and the connection to the municipal IT provider, exactly where the Südwestfalen-IT breach started.

Learn more
NIS2
Also relevant

NIS2 for the state and administration sector

Our NIS2 page breaks down which obligations under Art. 21 NIS2 (Sec. 30 BSIG) a penetration test can help you demonstrate.

NIS2 Pentest

Pentesting for municipalities: your questions

For online services delivered through the OZG portal network, the ITSiV-PV requires regular web checks and penetration tests from BSI-certified providers. NIS2 additionally applies to the state and administration sector once the relevant thresholds are met. In both cases, a penetration test is the recognized way to demonstrate compliance.
NIS2 introduces “state and administration” as its own sector under Annex 1 of the BSIG. Municipalities and authorities that meet the listed thresholds must register with the BSI, report security incidents, and demonstrably implement adequate technical measures, just like companies in other NIS2 sectors.
We structure our offers from the outset to work both for direct awards below the relevant thresholds and as the basis for a formal tender: a clear scope of work, a fixed price, and a traceable cost breakdown.
Yes. Citizen portals and online application workflows are part of a municipality's core attack surface. We test them for authorization flaws, authentication weaknesses, and configuration issues without putting live citizen services at risk.
Yes, as part of our Physical Pentest module we simulate realistic entry attempts, for example posing as a technician or visitor, and check whether reception, access controls, and server rooms hold up. Scope and approach are agreed in advance with a defined group on your side.
It depends on scope: number of locations and administrative systems, whether the municipal IT provider is included, whether physical and social engineering testing are part of it. After a free initial consultation we know your needs and you get a transparent, procurement-ready fixed-price quote.
The Südwestfalen-IT case shows the opposite. The target wasn't a single small municipality, it was the shared IT provider that up to 103 municipalities were connected to. If you run on shared infrastructure, you share its attack surface too, regardless of your own size.
We clarify that during scoping. In practice, part of the infrastructure sits with the individual municipality (administrative software, endpoints, citizen office) and part with the central provider (network, server operations, VPN). We adapt the scope to your actual area of responsibility, coordinating with your IT provider where needed.