Following an increase in ransomware cyber attacks, most notably May 2017’s WannaCry attack, U.S. public sector entities are starting to see the effects of these attacks on the almost $4 trillion municipal debt market. As a result, issuers are now starting to consider the cybersecurity posture of borrowers at the town, city, and local levels when they apply for bonds.
Municipal bonds are “the debt obligations of states, their political subdivisions and certain authorities.” The municipal bond market allows over 50,000 US state and local government units to raise money for entities like public schools, water and sewer systems, transportation, and more.
According to Reuters, despite the rise in global cyber incidents, no borrower had previously suffered any increased borrowing costs due to a cyber threat, but this may not be the case going forward. Leading credit ratings provider S&P Global is now beginning to inquire into cyber defenses being implemented at the town, city, and state level. Additionally, while looking at bond applications, credit analysts are starting to incorporate cyber security as a factor. Moody's Investors Service is also trying to determine how to best evaluate cyber risk.
So, why haven’t credit ratings providers/issuers considered cybersecurity defenses as a critical part of their bond assessments until now? Many investors haven’t been worried enough to ask since they cannot see or measure lasting damage — therein lies the danger. Towns, cities, and states need to be taking the appropriate measures to guard against a cyber incident. These days it’s not a matter of “if” a breach occurs, but “when.”
We’ve already seen state governments hit with crippling attacks, like the 2012 attack on the state of South Carolina, which compromised millions of residents’ financial information. The incident was handled quickly, and South Carolina subsequently implemented $76 million in security upgrades.