US state, local and authorities

    Oversight for states, cities, authorities and public systems

    Most public-sector risk does not sit in Washington. It sits in a state agency running a benefits platform, a transit authority replacing signalling systems, a utility under cyber mandates, a county running elections and courts, and a hospital or school system holding sensitive records. These buyers answer to auditors general, legislatures, ratepayers and residents — and rarely have a federal-scale assurance staff.

    Who this is for

    State agencies and departments

    Benefits, revenue, health and human services platforms with mixed federal and state obligations.

    Cities, counties and municipal bodies

    Consolidated oversight where one small team covers cyber, privacy, procurement and audit response.

    Transit and transportation authorities

    Operational technology, capital programmes and safety-critical vendor dependencies.

    Utilities and public power

    Cyber mandates, resilience reporting and third-party access control.

    Hospital and public health systems

    Protected health information handling, vendor assurance and clinical AI review.

    School districts and public universities

    Student-record privacy, grant stewardship and platform vendor oversight.

    Oversight surfaces we operate

    One control set, many regimes

    State bodies rarely answer to a single framework. Controls are held once and mapped to every regime that asks for them, so one piece of evidence satisfies several reviewers.

    • Single control library mapped across state and federal regimes
    • Evidence reused across audit, grant and certification cycles
    • Gap views by regime rather than by questionnaire

    Cyber and operational technology

    Where the estate includes plant, fleet, signalling or metering, oversight has to cover the operational side rather than stopping at corporate IT.

    • Segmentation and remote-access control evidence
    • Vendor and integrator access governance
    • Incident, near-miss and recovery-time reporting

    Vendor and integrator assurance

    Public bodies carry concentrated dependence on a handful of platform vendors and system integrators. Those dependencies are tracked as controls with named owners.

    • Tiering by service criticality and data held
    • Contract obligation flow-down to subcontractors
    • Concentration and exit-readiness views

    Audit and legislative response

    Auditor-general and legislative requests are answered from a standing evidence base rather than a fire drill.

    • Scoped read access for reviewers
    • Finding-to-remediation traceability
    • Attestation records with dates and owners

    AI use in public services

    Eligibility screening, case triage, fraud scoring and chat assistance all create administrative-law exposure. Each use is registered and gated before it reaches a resident-facing decision.

    • Authorised-use registry by programme
    • Human-review and appeal-readiness records
    • Stated-reason retention for adverse outcomes

    Capital programme oversight

    Large capital and modernisation programmes get schedule, cost and control reporting in one cadence for the board or commission.

    • Milestone and dependency integrity signals
    • Agreed escalation thresholds
    • Commission-ready reporting pack

    The regimes this answers to

    StateRAMPCloud service authorisation and continuous monitoring for state and local buyers.
    NIST SP 800-53 and the Cybersecurity FrameworkThe common control spine most state programmes are measured against.
    CJIS Security PolicyCriminal-justice information handling for police, courts and corrections systems.
    IRS Publication 1075Federal tax information safeguards for revenue and benefits agencies.
    HIPAA and state health privacy lawProtected health information handling across public health and hospital systems.
    FERPA and state student-privacy statutesEducation record handling for districts and public universities.
    State breach-notification statutesJurisdiction-by-jurisdiction notification duties and clock management.
    Auditor-general and single-audit regimesInternal control, grant stewardship and finding-resolution evidence.

    Questions buyers ask

    We have a team of three. Is this realistic for us?

    Yes. The point of holding controls once and mapping them across regimes is that a small team stops answering the same question in five formats. Engagements are scoped to the staff you actually have.

    Can you work under an existing cooperative contract?

    Where a suitable vehicle or cooperative agreement exists we will work through it, including through a teaming arrangement. See the how-to-buy page for the routes we use.

    Do you cover operational technology as well as IT?

    Yes, where the estate includes it — transit signalling, plant, metering, building systems and fleet telematics are treated as in-scope control surfaces, not an exception.

    What about AI already in production?

    We start with an inventory of what is running, classify by impact on residents, and put review gates on the uses that carry administrative-law exposure first.

    Built for teams that carry more than their headcount

    Tell us the regimes you answer to and the systems you cannot afford to lose. The briefing is scoped to those, and a senior practitioner reviews every enquiry.

    Request a briefing