A new pilot project developed by the Hessen CyberCompetenceCenter and Hochschule Fresenius is designed to help municipalities analyse suspicious files in an isolated environment. Yet the initiative points to a broader shift in public-sector cybersecurity: from protecting individual IT systems towards maintaining government operations in the face of cyberattacks.
Cyberattacks against cities and municipalities are no longer confined to isolated IT systems. When administrative networks fail, citizen services, internal communications and essential municipal processes can quickly be disrupted. Against this backdrop, the German state of Hesse is expanding its cybersecurity support structures for local authorities.
At the ninth Hesse Cybersecurity Summit in Marburg, a new pilot project took centre stage: a “sandbox” jointly developed by the Hessen CyberCompetenceCenter, known as Hessen3C, and Hochschule Fresenius. The solution is designed to analyse suspicious files and email attachments in an isolated digital environment, helping municipalities identify potential malware before it reaches productive administrative systems.
The project reflects a broader development in public-sector cybersecurity. As digital services become an integral part of government operations, cybersecurity is increasingly becoming a prerequisite for the state’s ability to function.
Cybersecurity Becomes a Question of Government Continuity
Held under the theme “80 Years of Hesse – Cybersecurity in a Changing Era,” the summit brought together representatives from politics, public administration, business and academia.
At the centre of the discussions was a threat landscape that is changing on several fronts. Cyberattacks are becoming increasingly professionalised and automated, artificial intelligence is expanding the capabilities available to attackers, and geopolitical conflicts are increasingly extending into the digital domain.
A particular focus was placed on the resilience of municipalities.
Hesse’s State Secretary for the Interior, Martin Rößler, framed cybersecurity as an integral part of public service provision. Administration, energy supply, healthcare, education and business are now so deeply interconnected through digital infrastructure that protecting these systems has become directly linked to the ability of government institutions to operate.
The distinction is important.
A cyberattack against a municipality is no longer simply an IT incident. If specialist administrative applications, communications platforms or central services become unavailable, a technical incident can rapidly develop into an organisational crisis.
Municipalities Are a Particularly Sensitive Attack Surface
Cities, municipalities and districts face specific cybersecurity challenges.
They process large volumes of personal and, in many cases, highly sensitive information. At the same time, they operate numerous specialist digital applications while having to ensure that essential services remain available to citizens and businesses.
Resources, however, vary significantly between local authorities.
Large cities may be able to maintain dedicated cybersecurity teams and specialist personnel, while smaller municipalities often have to manage information security with substantially fewer technical and human resources.
Hesse is therefore pursuing an increasingly centralised support model. Hessen3C acts as the state’s central contact point for information and cybersecurity and supports municipalities in both preventing and responding to security incidents.
The underlying strategy is significant: not every municipality should be required to maintain the full spectrum of threat detection, malware analysis and incident-response capabilities on its own.
The “Sandbox” Isolates Suspicious Files
The newly presented sandbox adds another component to this shared-security model.
Based on open-source software, the system is entering a pilot phase and is intended to allow suspicious email attachments and other files to be examined within a protected digital environment.
The underlying cybersecurity principle is well established.
Instead of opening a potentially malicious file directly on a standard workstation or within a productive administrative network, the file is executed or examined within an isolated environment.
Security teams can then observe how it behaves.
Suspicious actions may include unusual network communications, attempts to manipulate the operating environment or efforts to download additional malicious components. Because these activities take place inside the sandbox, analysts can investigate them without exposing the productive administrative network to the same level of risk.
For smaller municipalities in particular, access to such capabilities may be valuable because maintaining dedicated infrastructure and expertise for malware analysis is often difficult.
The project also addresses a persistent attack vector: manipulated attachments and files remain one way for attackers to introduce malicious software into organisations or establish an initial foothold for subsequent attacks.
A Sandbox Is Not a Complete Security Architecture
The technology has clear value, but its role should not be overstated.
A sandbox is an analysis tool, not a complete cyber-defence architecture.
Advanced malware may attempt to detect whether it is running within a virtual or controlled analysis environment and modify its behaviour accordingly. Moreover, many successful cyberattacks no longer depend on malicious attachments at all.
Stolen credentials, phishing websites, social engineering, compromised cloud accounts and vulnerabilities in publicly accessible systems can provide alternative entry points.
The real strength of Hesse’s initiative therefore lies not simply in the individual technology but in its integration into a broader security framework.
Municipal cyber resilience requires several layers of defence, including secure identity and access management, effective patch and vulnerability management, network segmentation, reliable backups, monitoring, employee awareness and established incident-response procedures.
A sandbox can improve the detection and assessment of certain suspicious files. It cannot replace fundamental cyber hygiene or a functioning response strategy.
Hesse Is Building a Shared Municipal Security Network
The sandbox is only one part of Hesse’s wider approach.
Through the Malware Information Sharing Platform, MISP, information on cyber threats and technical indicators can be exchanged between participating organisations. Hessen3C provides municipalities with access to the platform free of charge.
The advantage of this model lies in creating a shared threat picture.
If suspicious activity or a relevant indicator is identified in one location, the information can be distributed more rapidly to other organisations. Cyber defence consequently becomes less of an isolated task for individual municipalities and more of a collaborative process.
This is particularly important in a threat environment where attackers can reuse infrastructure, techniques and indicators against numerous organisations.
Hessen3C also provides advisory and support services for the prevention and management of cybersecurity incidents.
Together, these capabilities represent a shift from isolated municipal security measures towards a broader ecosystem of shared expertise, threat intelligence and incident support.
From Protecting IT to Maintaining Operations
This development also changes the benchmark by which municipal cybersecurity should be measured.
The central question is no longer simply:
How can a successful cyberattack be prevented?
An equally important question is:
Which public services remain available after an attack, and how quickly can normal operations be restored?
This moves cybersecurity directly into the field of operational resilience.
Technical safeguards remain essential, but organisations must also establish responsibilities before an incident occurs, ensure that communications can continue during outages and determine which services must receive priority during recovery.
As a result, modern cyber resilience increasingly includes business continuity and recovery planning alongside prevention, detection and incident response.
For municipalities, this perspective is particularly important. If citizen services, internal communications or central administrative applications remain unavailable for an extended period, a cybersecurity incident becomes directly visible to the population and local economy.
The consequences are therefore no longer purely technical.
Standardisation Could Reduce the Burden on Municipalities
Another element of Hesse’s strategy is the so-called Zukunftspakt, or “Pact for the Future,” between the state and its municipalities.
One of its objectives is to establish more standardised and resilient IT structures with high security standards while using existing resources more efficiently.
The underlying challenge extends far beyond Hesse.
As public services become increasingly digital, maintaining a large number of largely independent IT environments at comparable security levels becomes increasingly complex and resource-intensive.
Shared services, standardised architectures and centrally available cybersecurity expertise can offer substantial advantages.
However, greater centralisation also introduces new dependencies.
If multiple municipalities rely on central infrastructure or common services, the impact of a failure or successful compromise of those components can become significantly larger.
Consolidation must therefore not be confused with resilience.
On the contrary, centralised structures make high security standards, redundancy, contingency planning and robust recovery mechanisms even more important.
Cybersecurity Must Be Continuously Tested
Hesse is also using its KOMPASS cybersecurity seal to recognise municipalities that systematically improve their IT security.
Such initiatives can help institutionalise cybersecurity and move it beyond a collection of voluntary or isolated measures.
However, a certification or security seal should never be regarded as evidence of a permanently secure state.
Cybersecurity is not a project that can be completed at a specific point in time.
Systems change. New vulnerabilities emerge. Employees and responsibilities change. Attack techniques evolve.
The real value therefore lies in establishing continuous processes: regular reviews, clearly defined responsibilities and the ability to adapt security structures as both technology and threats change.
Municipal Cyber Resilience Is Becoming a Core Government Responsibility
The cybersecurity summit in Marburg illustrates how the debate around public-sector security is evolving.
The focus is shifting away from simply protecting individual IT systems towards ensuring the resilience of government and municipal structures as a whole.
Hesse’s new sandbox provides a concrete example. It can help municipalities investigate suspicious files in a controlled environment and strengthen defences against one important attack vector.
Its broader significance, however, lies in the model behind it.
Not every municipality needs to develop every cybersecurity capability independently. Malware analysis, threat intelligence, expert advice and incident-response support can, at least to some extent, be pooled and made available through shared structures.
For cities and municipalities, such models are becoming increasingly important.
Digitalisation makes administration more efficient and enables new public services. At the same time, it increases dependence on functioning IT infrastructure.
When digital government systems fail, a cybersecurity incident can rapidly become a question of public-service continuity and government operability.
Municipal cyber resilience can therefore no longer be measured solely by whether an attack was successfully prevented.
The decisive question is whether a public administration can remain operational during an attack—and recover quickly when prevention fails.

