PUBLIC SECTOR & SLED

Prove your defenses hold to CISA mandates, before the next ransomware wave.

SIEGE runs as a persistent adversary against your environment, emulating the ransomware crews and nation-state actors that have made state, local, and education (SLED) targets a top priority. It validates your controls against CISA directives and NIST standards, and produces the dated evidence your leadership, your cyber-insurance carrier, and your constituents expect.

See the Compliance Crosswalk
01
THE ATTACK PATH

This is how the breach actually happens.

FIG.01: ADVERSARY PATH / PUBLIC SECTORAGENT ACTIVE
INGRESST1190Exposed serviceFOOTHOLDT1078Valid accountsLATERALT1021Remote servicesPRIV ESCT1068Domain escalationCROWN JEWELIMPACTcitizen-services
From an exposed public-facing service to citizen data and critical services. SIEGE maps the route before ransomware takes your agency offline.
02
THE THREAT

Who's actually coming for you.

State and local governments, schools, and public agencies are among the most-targeted organizations for ransomware, often under-resourced and over-exposed. SIEGE emulates how these actors actually operate, as documented in CISA #StopRansomware advisories.

#StopRansomware
Ransomware Against Public Services
Ransomware crews repeatedly hit cities, counties, and school districts, knowing downtime pressures fast payment. SIEGE replays their intrusion-to-encryption playbook so you can prove what actually stops it.
T1190 · Exposed Assets
Internet-Exposed Attack Surface
Unpatched VPNs, RDP, and forgotten services are common entry points into government networks. SIEGE continuously finds and validates the exposed paths CISA's KEV catalog warns about.
Nation-State
Espionage & Disruption
State-sponsored actors target government networks for intelligence and pre-positioning. SIEGE pressure-tests the lateral paths to sensitive systems and citizen data.
03
THE MANDATE

CISA and NIST ask if your controls work. SIEGE proves it.

Federal directives and state cyber-governance requirements all converge on one question: can you demonstrate your defenses actually hold? SIEGE produces the evidence once and maps it to the frameworks your oversight bodies and insurers require.

MandateRequirementSIEGE Evidence
CISA BOD 22-01Remediate Known Exploited Vulnerabilities (KEV)Continuous validation that KEV exposures are actually closed
CISA BOD 23-01Asset visibility & vulnerability detectionAttack-path mapping across discovered assets
CISA CPGsCross-Sector Cybersecurity Performance GoalsAdversarial validation of priority controls
NIST CSF 2.0Govern / Protect / Detect outcomesMapped control validation across the framework
StateRAMP / NIST 800-53Security control baselines for gov systemsExploit-ranked evidence per control family
04
THE PROOF

Built under DARPA. Validated by DoD.

★ DEVELOPED UNDER DARPA CASTLE PROJECT ★ DOD VALIDATED ★ TRUSTED BY US DEFENSE & INTELLIGENCE ★

When SIEGE confirms your defenses hold, that finding carries the weight of the DARPA CASTLE program and validation across DoD and U.S. Government environments. For your leadership, your auditors, your insurer, and the constituents who depend on your services, it is the most credible statement of resilience a public agency can present, proof, not posture.

05
THE MATH

The real cost of a public-sector breach.

#StopRansomware
CISA and MS-ISAC issue ongoing advisories on ransomware targeting SLED organizations. SIEGE replays those exact TTPs.
KEV-driven
Most public-sector intrusions start with a known, exploitable exposure. SIEGE proves yours are closed before attackers test them.
Continuous
Threats evolve daily; an annual assessment can't keep up. SIEGE validates your posture year-round.

Sources: CISA Binding Operational Directives 22-01 & 23-01; CISA Cross-Sector Cybersecurity Performance Goals; CISA / MS-ISAC #StopRansomware advisories; NIST CSF 2.0.

06
FREQUENTLY ASKED

Questions teams ask before a SIEGE engagement.

What cybersecurity mandates apply to state and local governments?
Public-sector and SLED organizations are guided by CISA Binding Operational Directives (such as BOD 22-01's Known Exploited Vulnerabilities remediation and BOD 23-01's asset visibility), CISA's Cross-Sector Cybersecurity Performance Goals, NIST CSF 2.0, and frameworks like StateRAMP and NIST SP 800-53. SIEGE validates your controls against these and maps the evidence to each.
Why is the public sector such a frequent ransomware target?
Government agencies and schools hold sensitive data and run essential services, yet often operate with limited security budgets and legacy systems. Attackers exploit that gap, knowing downtime creates pressure to pay. SIEGE replays real ransomware TTPs so you can prove your defenses hold before an incident.
Will SIEGE disrupt live government services?
No. SIEGE assesses in simulated or mirrored environments and never touches production systems, so citizen-facing services stay online throughout.
How does SIEGE help an under-resourced public-sector security team?
SIEGE's AI agents run continuously and autonomously, effectively multiplying a small team's reach. They surface the handful of exploitable paths that actually matter, ranked by risk, so limited staff can focus remediation where it counts.

See SIEGE map a path through an agency like yours.

Twenty minutes. We'll walk a real attack path to citizen data or critical services and show you the evidence your oversight and insurer expect, no slideware.

Back to All Sectors