Pen testing · Public sector & education
Penetration Testing for Municipalities
Penetration testing shows a municipality how its defences hold up before an attacker runs the same experiment for real. Hamilton's 2024 breach began at an internet-facing server, which is exactly the surface a test examines first. We probe your citizen-facing portals, payment flows and remote access in a controlled way, and assess the boundaries that separate corporate IT from water, traffic and transit control systems, then hand your IT lead and council a findings report ranked by service impact.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The municipal attack surface a test has to cover
A municipality's exposure is defined by what residents and vendors can reach from the internet and by what an intruder could pivot to once inside. Both belong in scope.
Permit and licensing portals
Online building-permit, planning and business-licence applications accept documents and personal details from the public around the clock, making them the most trafficked doorway into municipal data.
Payment and account channels
Tax and utility payment pages, recreation registration checkout and pre-authorized payment enrolment move money and banking details, and card acceptance brings PCI expectations through your acquirer agreements.
Remote access and the perimeter
VPN gateways, exposed servers, MSP management channels and Microsoft 365 sign-in are where credential attacks land. An internet-facing server was the entry point in Hamilton's incident, not an exotic exploit.
The IT-to-OT boundary
Segmentation between corporate networks and water or wastewater SCADA, traffic-signal management and transit systems determines whether an office compromise can touch physical operations. Testing evaluates that boundary without disturbing the controls behind it.
Board and shared infrastructure
Library, transit or police-board systems that share networks, identity or hosting with the municipality widen the blast radius, and their internet-facing services deserve the same scrutiny as city hall's.
Regulatory map
Why regulators and insurers expect municipal testing
No statute orders a municipality to buy a pen test, but several obligations are hard to evidence without one.
Demonstrating reasonable safeguards
MFIPPA's amended s. 30(5) safeguard duty arrives January 1, 2027, and testing is a recognized way to show measures were checked rather than assumed. Findings and fixes create the paper trail a reasonableness standard rewards.
Insurer scrutiny of controls
AMO warns municipalities that insurers evaluate security practices and can refuse cover. Independent test results substantiate questionnaire answers about perimeter hygiene the way an unaudited self-assessment cannot.
PHI systems held to custodian standards
Where paramedic ePCR or LTC systems are reachable from tested networks, PHIPA's custodian obligations apply, and verifying their isolation is part of a responsible scope.
Getting ahead of an EDSTA regulation
Ontario left municipalities out of O. Reg. 51/26, but prescribed sectors show the direction of travel. Municipalities that test now will meet a future cyber regulation with evidence in hand.
What goes wrong
What testing surfaces before attackers do
The Canadian municipal incident record reads like a pen tester's findings list, which is the strongest argument for commissioning one.
The forgotten exposed server
Hamilton's attackers entered through an internet-facing server and encrypted systems spanning property tax, permits and traffic-signal management. External testing exists to find that server while it is still just a finding.
End-of-life systems nobody flagged
The Toronto Public Library ran end-of-life systems and hosted an intruder for two months undetected. Testing highlights unsupported software and weak detection at boards and branches central IT rarely examines.
Reachable water and signal networks
The Cyber Centre documents attacks on internet-exposed water OT and state interest in municipal infrastructure. A segmentation assessment answers whether your plant or signal network is truly separated or merely assumed to be.
Portal flaws that leak resident files
Weak access controls in permit or registration applications can expose one applicant's documents to another, quietly creating the kind of breach that becomes reportable under MFIPPA's 2027 rules.
Our pen testing for municipalities
How we scope a municipal engagement
Every component ties back to a service the public depends on, and the scoping conversation decides depth for each.

External network testing
Exploration of your internet-facing ranges, exposed services and remote-access points to uncover the vulnerabilities an opportunistic ransomware crew would find first.
Citizen application testing
Focused examination of permit portals, recreation registration, 311 self-service and payment flows for authentication, authorization and input-handling weaknesses that could expose applicant data.
OT boundary and segmentation review
Assessment of the separation between corporate IT and SCADA, traffic and transit environments, including remote vendor connections, conducted without active exploitation of live control systems.
Detection and response observation
Insight into how your environment and MSP react during simulated attack activity, showing whether the two-month dwell times seen elsewhere could happen to you.
Findings for two audiences
A technical report for IT and the MSP with directional remediation guidance, and a plain-language summary the CAO can carry into closed session and the Treasurer can attach to a renewal.
How the engagement runs
Running the test without disrupting services
Municipal testing is planned around service continuity, because the systems in scope collect taxes and run counters every business day.
Step 1
Scoping with IT and operations
We define targets with your IT director, MSP and, where OT is included, plant and traffic staff, agreeing what is tested, what is observed passively and what is off limits.
Step 2
Rules of engagement
Testing windows avoid billing runs, council meetings and peak counter hours; emergency-stop contacts are named on both sides; and OT work is limited to boundary assessment by design.
Step 3
Controlled testing
Testers work through the agreed scope with regular check-ins, escalating anything urgent immediately rather than saving it for the report.
Step 4
Debrief and retest
Findings are walked through with your team, remediation is prioritized against duty and insurer deadlines, and a follow-up verification confirms the fixes closed what was found.
What it costs
What municipal pen testing costs depends on
Price follows scope: the number of external addresses and portals, how many web applications need authenticated testing, whether an internal or assumed-breach component is included, and whether OT boundary assessment brings plant or traffic environments into planning. A township with one website and an MSP-managed firewall is a small engagement; a regional government with a dozen portals, transit systems and two water plants is not.
Constraints add effort too, since testing around live billing cycles and 24/7 operations takes more coordination than testing a startup's staging site. Share your system list and timelines and we will quote a fixed scope, and where budget is tight we will tell you honestly which components deliver the most risk reduction first.
Municipalities: Pen testing questions, answered
By engineering the test around your operational calendar. We schedule intrusive work outside billing runs and peak application periods, use test accounts rather than resident data wherever the platform allows, and agree escalation contacts so anything unexpected is paused within minutes. Payment flows are examined for weaknesses in how they handle authentication and data, not by firing junk transactions at your processor. Municipalities run these tests routinely without residents noticing; the alternative discovery method, a real intrusion, closed Huntsville's offices.
Their boundaries should be, even when the control systems themselves are excluded. The question a test answers is whether someone who compromises a workstation at city hall can reach SCADA or signal management, and Hamilton's incident, which disrupted traffic-signal systems, shows the pathway is real. We assess segmentation, firewall rules, remote vendor connections and shared credentials between environments, and we do it through review and passive verification rather than active exploitation of live controls, because nobody should aim attack traffic at a running treatment process.
It strengthens your position, though no single document guarantees coverage. Underwriters following the practices AMO describes want evidence that controls exist and are verified; an independent test with documented remediation answers that far better than a self-attestation. It also protects you from the trap that caught Hamilton, where an inaccurate picture of MFA coverage contributed to a denied claim: testing reveals where controls actually apply before you certify anything. Bring the questionnaire to the scoping call and we will align the test to the specific attestations you must sign.
No. An authorized, controlled assessment of your own systems is not a privacy breach, so nothing in MFIPPA's current or 2027 provisions requires notifying the regulator or the public. What you do need is internal authorization: written sign-off from the CAO or delegated authority, your MSP informed so defensive tooling is not fighting the testers blind, and board approval where board systems are in scope. If a test uncovers evidence of an existing compromise, that discovery is handled under your incident process, and early detection is a far better outcome than the alternative.
Work backwards from the decisions the results must feed. If findings will drive capital requests, test in late summer or early fall so remediation costs make the draft budget; if the driver is an insurance renewal, finish testing and the priority fixes at least a quarter before the anniversary. Procurement lead times matter in a municipality, so many clients approve testing in one budget and execute early in the next year. Retesting after major changes, such as a new permit portal or ERP go-live, matters more than hitting any particular month.
More for municipalities
Other services for this niche
About this service
Answers & guides
- How much does a penetration test cost (and what affects the price)?
- What is a cybersecurity risk assessment, and how often should we do one?
- What is multi-factor authentication, and do I need it?
- Vulnerability Scan vs Penetration Test: Why You Probably Need Both
- How Often Should You Pen Test Your Web App?
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.