FC Health Index1,428.60+0.42%Novo NordiskDKK 812.4+1.10%Intuitive SurgicalUSD 546.9−0.30%EU AI Act — Art. 6in forceM+7FDA 510(k) AI clearances (YTD)312+18 w/wNHS AI Diagnostic Fund£123mcommittedKarolinska trials open48+2Reimbursement CPT codes (AI)17+1 QFC Health Index1,428.60+0.42%Novo NordiskDKK 812.4+1.10%Intuitive SurgicalUSD 546.9−0.30%EU AI Act — Art. 6in forceM+7FDA 510(k) AI clearances (YTD)312+18 w/wNHS AI Diagnostic Fund£123mcommittedKarolinska trials open48+2Reimbursement CPT codes (AI)17+1 Q
Wednesday, 16 September 2026 · Oslo · London · New York

Cybersecurity · Analysis

European ransomware crews moved down market, and municipalities are the softest target on the continent.

Small and mid-size local authorities run essential services on thin IT teams and inherited systems. Attackers noticed before national policy did.

A municipal office corridor with closed doors
A municipal office corridor with closed doors

Independent coverage

M

By Michelle Greenlee

Contributing Writer — Enterprise Tech / Cybersecurity · Freelance

Edited by Dr. Mikael Lindholm, MD

Published 20 August 2026

7 min read

Evidence: Reporting

The large ransomware incident, against a hospital group or a manufacturer, gets the coverage. The steadier pattern across Europe this year has been smaller: municipalities, water utilities, regional transport authorities, school districts.

These organisations share a profile. They deliver services people depend on daily, they operate systems accumulated over decades, and their entire IT function may be three people.

Why they are attractive

Not because the ransom is large. Because the probability of payment or of a fast, disruptive outage is high, and because the effort required is low.

Many run remote access that was expanded quickly during the pandemic and never re-architected. Many have no segmentation between administrative systems and operational ones.

The shared services answer

The response that appears to work is not more tooling at the individual authority. It is shared capability at regional or national level: a pooled security operations centre, centrally procured endpoint detection, and an incident response retainer that a municipality of twenty thousand people could never justify alone.

Denmark, Norway and the Netherlands have variants of this. The consistent finding is that coverage matters more than sophistication. A basic monitored baseline across every authority beats an advanced capability at a few.

The part nobody funds

Recovery. Most affected authorities interviewed could describe their backup arrangement and could not describe how long a full restoration of a citizen-facing service would take.

The answer, when tested, is usually weeks rather than days, and it is the number that determines the real impact of an incident.

The practical minimum

Four things, in order. Offline backups that have been restored from, at least once, as a test. Multi-factor authentication on every remote access path without exception. Segmentation between administration and operational technology. And a written decision process for who authorises what during an incident, held on paper.

Sources

Published 20 August 2026