Cybersecurity · Analysis
European ransomware crews moved down market, and municipalities are the softest target on the continent.
Small and mid-size local authorities run essential services on thin IT teams and inherited systems. Attackers noticed before national policy did.

Independent coverage
Contributing Writer — Enterprise Tech / Cybersecurity · Freelance
Edited by Dr. Mikael Lindholm, MD
Published 20 August 2026
7 min read
Evidence: Reporting
The large ransomware incident, against a hospital group or a manufacturer, gets the coverage. The steadier pattern across Europe this year has been smaller: municipalities, water utilities, regional transport authorities, school districts.
These organisations share a profile. They deliver services people depend on daily, they operate systems accumulated over decades, and their entire IT function may be three people.
Why they are attractive
Not because the ransom is large. Because the probability of payment or of a fast, disruptive outage is high, and because the effort required is low.
Many run remote access that was expanded quickly during the pandemic and never re-architected. Many have no segmentation between administrative systems and operational ones.
The shared services answer
The response that appears to work is not more tooling at the individual authority. It is shared capability at regional or national level: a pooled security operations centre, centrally procured endpoint detection, and an incident response retainer that a municipality of twenty thousand people could never justify alone.
Denmark, Norway and the Netherlands have variants of this. The consistent finding is that coverage matters more than sophistication. A basic monitored baseline across every authority beats an advanced capability at a few.
The part nobody funds
Recovery. Most affected authorities interviewed could describe their backup arrangement and could not describe how long a full restoration of a citizen-facing service would take.
The answer, when tested, is usually weeks rather than days, and it is the number that determines the real impact of an incident.
The practical minimum
Four things, in order. Offline backups that have been restored from, at least once, as a test. Multi-factor authentication on every remote access path without exception. Segmentation between administration and operational technology. And a written decision process for who authorises what during an incident, held on paper.
Sources