Authored by Larry Yon, Co-Founder, CyberAlliance and Kendrall Felder, CEO, CyberAlliance
During this year’s National League of Cities Summer of Savings and Solutions campaign, CyberAlliance is asking municipal leaders one simple question: If your network went down tomorrow, who in your city could tell you what it would cost, and what to do next?
“What should I be asking my team about our cyber strength, and how do I support the work they’re doing?”
— Fuquay-Varina, N.C. Mayor William H. “Bill” Harris, at a recent NLC gathering
We didn’t have a slide for that. We had a conversation. It’s the same conversation we’d invite any mayor, city manager or finance director to have because most cities cannot yet answer it with confidence.
The Job Changed. The Reporting Didn’t.
Whether you’re a mayor, city manager or council member, the job increasingly looks like running a company: protect essential services, allocate limited dollars and answer for risks you didn’t create and technology you didn’t choose. Today, that responsibility includes cybersecurity and AI.
The problem isn’t a lack of effort. It’s that the reporting most leaders receive — compliance checklists, technical audits and security dashboards — was built for IT teams, not for the people accountable to the council and the community.
Three questions come up in nearly every conversation we have with local leaders:
- If your water system, payroll or permitting went down tomorrow, do you know what it would cost in hours, dollars and public impact?
- Do you know how employees are actually using AI today? Not just what’s written in your policy, but what’s happening in practice?
- If you had one more dollar to invest in cybersecurity or AI next year, could you confidently say where it should go and why?
In our experience, most leaders can answer one of those questions. Far fewer can answer all three. That isn’t a leadership problem. It’s a visibility problem.
Why This Is Harder Than It Looks
The technology usually isn’t the bottleneck. Most cities already have security tools in place. What’s missing is a way to translate technical information into clear executive insight that supports better decisions.
That gap is where budgets get wasted. Cities overspend on some controls, underinvest in others and often discover the difference only after an incident.
What CyberAlliance Does About It
Through the National Municipal Cyber Resilience Initiative, which focuses on education, benchmarking, and scalable approaches to cyber risk management, CyberAlliance and the NLC created Sally, an executive risk platform designed to help municipal leaders understand cybersecurity, responsible AI and technology investment priorities in plain language.
We help leaders make informed decisions they can defend in council meetings, budget discussions and conversations with their communities.
Bring Savings and Solutions to Your Municipality
As part of the National League of Cities Summer of Savings and Solutions campaign, CyberAlliance is offering NLC members a free Municipal AI & Cyber Executive Strategy Session or Municipal AI Governance & Cyber Resilience Review to help leaders understand their cyber resilience, strengthen responsible AI governance, evaluate AI use policies and prioritize investments that improve operational and economic resilience.
If you’re not sure how your city would answer these questions, or whether employees are using AI in ways that align with your city’s policies, that’s exactly the conversation worth having – before today’s opportunity becomes tomorrow’s incident.
Upcoming Webinar
Our upcoming webinar on Aug. 13 at 2 PM ET, hosted by hosted by NLC and CyberAlliance, will explore how local governments can move from reactive cybersecurity conversations to defensible leadership decisions. The session centers on executive risk visibility, governance, peer benchmarking and practical steps cities can take to strengthen cyber resilience.