On the night of October 29 to 30, 2023, a ransomware attack hit Südwestfalen-IT, the shared municipal IT provider for a large part of the Südwestfalen region. What happened next is a textbook example of what a single point of failure means for municipal IT.
According to media reports, the attackers got in through a compromised VPN access, the classic entry point for externally reachable remote-access systems.
From that single access point, the attackers moved through the provider's internal network, the same network dozens of municipalities had connected their own administrative IT to.
The group “Akira” then encrypted core systems at Südwestfalen-IT. Because so many municipalities were tied into the same infrastructure, the encryption didn't hit one administration, it hit an entire region at once.
According to heise online, up to 103 municipalities had to run in emergency mode for weeks, with limited access to citizen portals, administrative software, and internal systems.
The Südwestfalen-IT case didn't hit a big city with its own IT department, it hit the exact setup most common across Germany: small and mid-sized municipalities sourcing IT from a shared provider. The target wasn't any single municipality, it was the shared infrastructure they were all plugged into.
Similar incidents also affected the town of Mössingen (November 17, 2023) and, in 2025, two Berlin Senate administrations, attributed to the group “Rhysida”.
Based on public reporting (including heise online). accessgranted was not involved in this incident.
Public administration combines publicly reachable citizen services with legacy administrative software and constant foot traffic. When many municipalities also hang off the same central infrastructure, a single compromised access is enough for an incident to travel along those connections to every administration attached to it.
Online application workflows for ID cards, vehicle registration, or housing benefits are publicly reachable and a direct target for attackers after citizen data or a foothold into backend systems.
Specialized software for registration offices, social services, or building authorities has often grown over decades, was rarely designed for today's threats, and is hard to replace quickly.
When many municipalities run on the same central infrastructure, one successful attack becomes an incident for dozens of administrations at once, exactly what happened at Südwestfalen-IT.
Open service counters, many separate locations, and direct contact with citizens make pretexting and unauthorized entry easier in an environment built for accessibility rather than security.
Public administration is regulated from two directions at once: NIS2 across the board, and the OZG specifically for digital citizen services. Both come down to the same question: is your IT actually as secure as it needs to be?
Annex 1 of the German BSIG lists “state and administration” as its own sector. Municipalities that reach the relevant thresholds face the same obligations as energy providers or hospitals, including registration with the BSI and mandatory incident reporting.
For services delivered through the OZG portal network, the ITSiV-PV requires regular web checks and penetration tests from BSI-certified providers. BSI IT-Grundschutz remains the general reference framework, and GDPR applies on top for all citizen data.
Registration and reporting obligations apply regardless of whether a municipality runs its own IT or sources it from a shared provider.
A pentest for a municipality rarely has a single decision-maker. In practice you'll find the IT director or head of the IT department, the municipal IT provider itself, an information security officer or CISO, the mayor or treasurer controlling the budget, and the data protection officer at the table, each with different priorities.
Municipal budgets are planned tightly and security competes with many other mandatory tasks. A clearly scoped, fixed-price engagement keeps the cost predictable from the start.
Public buyers have to follow tender and procurement rules, security services included. We structure our offers so they work equally well for direct awards below the relevant thresholds and as the basis for a formal tender.
It's often unclear who owns which part of the infrastructure, the individual municipality or the shared IT provider. We clarify this during scoping so the test targets what's actually within your responsibility.
That was exactly the assumption in the Südwestfalen-IT case, and it was wrong. The target wasn't the small individual municipality, it was the shared infrastructure it was plugged into. Size doesn't protect you when the attack surface is shared.
Administrative processes and procurement law run differently than in the private sector. So instead of a step-by-step timeline, here is what you can hold us to, from the first conversation to the final report.
You get an offer with a clear scope of work, a fixed price, and a traceable cost breakdown. We define the scope together beforehand: which systems fall under your own responsibility and which run through the municipal IT provider.
Direct awards are subject to value thresholds that vary by state and municipality. We tailor scope and offer so they can stay below those thresholds, or we prepare the documents so they hold up as the basis for a formal tender.
Every finding is rated by severity, exploitability, and impact on citizen services and administrative operations. The final report documents web checks and penetration test in a form you can use as evidence for ITSiV-PV and NIS2, with a management summary for IT leadership, department heads, and administrative leadership.
For the duration of the test, a named contact is available on both sides. If a critical risk surfaces during testing, we tell you immediately rather than waiting for the final report.
Citizen portals, administrative software, and network are tested manually and within the agreed scope. Test windows are agreed in advance, destructive tests are excluded, and live citizen services keep running.
Citizen portals, specialized software, and the town hall itself can't be ticked off with one test. These are the modules we typically bring together for municipalities.
Simulated entry attempts at citizen offices, town halls, and server rooms. Covers the physical attack surface that matters most where public foot traffic is high.
Phishing and pretexting simulations tailored to direct citizen contact and how caseworkers actually operate.
Focused on network segmentation, VPN access, and the connection to the municipal IT provider, exactly where the Südwestfalen-IT breach started.
Our NIS2 page breaks down which obligations under Art. 21 NIS2 (Sec. 30 BSIG) a penetration test can help you demonstrate.