08/05/2026

Security Awareness in Municipalities: 'You Need Staying Power and Strong Nerves'

'You Need Staying Power and Strong Nerves' Awareness

Petra, please introduce yourself briefly.

Petra Stibane: I'm a public administration specialist, not a computer scientist — I want to say that up front. In the district town of Eberswalde, I head the Central Services Department, which includes, among other things, the IT division. In addition, I also hold the role of Information Security Officer, or ISO for short. Since 2023, we have been building up information security in our administration according to the requirements of the German Federal Office for Information Security (BSI). A key building block in this is security awareness training for our employees.

What challenges do municipalities face in the area of IT? Does the cliché hold true that their IT is often outdated or hampered by bureaucracy?

Petra Stibane: That varies from one administration to another. But I can't agree with the blanket statement that IT systems are outdated. Until recently, there were indeed a few municipalities that were still working with Windows 10, for example. But in the best case, both the technical and human resources are available to stay up to date. It's no secret, however, that public budgets are underfunded in many places.

This is exactly where I come in as ISO. In this role, I can have a serious conversation with the administrative leadership when IT budgets are insufficient or additional positions are needed.
Partly because politics and administrative professionals meet in public administration, decision-making processes are sometimes — and then quite naturally — longer.

What cyber risks are public authorities currently exposed to?

Petra Stibane: Municipalities are critical infrastructure. Sensitive data is stored here, a great deal of information is managed here. That makes them an attractive target for attacks. In my view, this trend isn't only about ransom expectations, but also about the goal of undermining citizens' trust in the state.

Depending on how well a municipality is set up technically, or how vigilant its employees are, considerable damage can be done with relatively little effort. We know of cases where entire server landscapes had to be shut down; there have also already been ransomware attacks on town halls and district offices. Citizens feel the consequences directly. The citizens' service office stops working, cars can't be registered, ID cards and passports can't be applied for. It becomes especially critical when social benefits can't be paid out or when emergency communications for rescue services fail.

Which cyber threats are currently particularly alarming?

Petra Stibane: We're seeing a lot of phishing emails, through which criminals try to obtain login credentials or money via social engineering. The days of the supposed African prince are over, though. Today we receive highly professional texts — for example, a supposedly genuine email from Zoom prompting a click into a fake "Trust Center." At first glance, it's hardly recognizable as malicious. On top of that, there's classic invoice fraud: fake PDFs with supposedly outstanding claims. The real trend behind this is the professionalization of the cybercrime scene. Work is divided up, similar to a regular company. Some steal passwords and identities, others use them to program targeted attacks.

I'm also concerned about the uncritical hype surrounding AI applications. The unreflective, inexperienced use of language models like ChatGPT poses a real risk of data leakage, because many employees aren't even aware of what they're disclosing there.

Given the critical trends in the digital world, what skills are needed for information-secure behavior?

Petra Stibane: That starts early, namely with a solid general school education. When children and young people are given a well-founded education, they're later well equipped to correctly classify content and, if necessary, question it. That's exactly what we also need in professional life: methodological competence — that is, the ability to independently acquire new and factually correct knowledge. That equips you fairly well to recognize false content and fraud.

When it comes to artificial intelligence, its rapid development, measured against comparatively slow human learning behavior, is simply too fast for users to already be able to move safely in this field. I'm not against technological progress — quite the opposite. What's decisive, though, is whether I can critically examine and classify what the technology offers me. It's exactly this pausing to reflect that falls short.

 

What challenges did you have to solve before introducing security awareness training?

Petra Stibane: First, I advocated to our administrative leadership that we tackle this topic and implement it digitally, rather than offering a classic in-person training day. Fortunately, there was support for this from the very beginning. Preparing the procurement procedure took a lot of time: drafting a service specification that clearly states what we need and what we expect from providers. That requires a broad participatory process, which also involves the staff council and the data protection officer — just like our information security working group, which consists of members from our auditing office, IT, and the organization and digitalization department. This participation is important in order to generate the broadest possible acceptance for this additional learning task.

What measures were implemented to involve managers?

Petra Stibane: It was very important that the administrative leadership clearly informed the other managers about the plans for this training from the very beginning and took a clear position: we're doing this, and it's mandatory. Anyone who doesn't participate also has to expect labor-law consequences. Nevertheless, there were initial teething problems, and the uptake curve rose only slowly. That's why the supervisors and I, as ISO, took on a much stronger role — informing frequently and repeatedly, and seeking personal conversations with colleagues who, in some cases, simply weren't getting started. After the first third of the program's duration, the participation rate picked up noticeably. In the end, what's needed above all is one thing: a lot of talking, a lot of persuading.

How did you manage to motivate employees?

Petra Stibane: Ultimately, here too it came down to conversations — and ones free of hierarchy. As ISO, I report directly to the chief administrative officer and advise senior management, but at the same time I'm also approachable and visible to all employees, right down into the individual departments. You need to know what's currently on colleagues' minds, and that requires a good network within your own administration. The practical relevance also helped a great deal: we continue to receive phishing emails and fraud attempts, and that's exactly what shows why the training matters.

What means did you use to convince reluctant employees?

Petra Stibane: With skeptics, we argued above all that they also benefit from the training in their private lives — for example, because they already shop online or use online banking. The training doesn't only cover work-related topics; it conveys, quite generally, how to move safely in cyberspace. We also explained and put the scope into perspective: the training amounts to roughly a single working day, spread over twelve months with a total effort of eight to ten hours. That's manageable.

Also very effective was the practical relevance — when colleagues realized through the training that there was something they needed to and could change in their own work environment, such as setting up still-missing data disposal bins or better protecting their visitor rooms against unauthorized eavesdropping. They experienced that as empowering and positive. But security incidents also lead to conversations and improvements: when our IT colleagues discovered login credentials taped to a laptop with transparent tape, that was a direct occasion for a conversation — also to illustrate how important the training is in preventing such critical incidents. In a few stubborn cases, we did have to resort to labor-law instruments: setting deadlines and issuing warnings. Further consequences weren't necessary.

Do you have any final advice for other administrations that want to introduce security awareness training?

Petra Stibane: Very briefly: those responsible need staying power and strong nerves. Second: communicate the plan early and broadly, rather than announcing it overnight. And third, which I consider especially important: to find the right provider, you first need to know exactly what your own needs are — what content, what scope, what delivery format for a training program fits your administration. Otherwise you end up with a provider who, for example, offers no personal point of contact, or requires a lot of effort for self-service — and possibly unsuitable training content — which you may neither have wanted nor expected. Given the unmanageably large number of training providers on the market, this groundwork takes time, but it pays off.

Thank you for the conversation.

Machine translation of the original post.



Stefan Karpenstein

Stefan Karpenstein

Public Relations Manager


Share Article