• 5 mins read
  • Published

South Dakota Local Governments Face Cybersecurity Funding Deadline

Nina Halbrook Business & Technology Writer Farmington Voice

Post by Nina Halbrook

South Dakota Local Governments Face Cybersecurity Funding Deadline Farmington Voice © farmingtonvoice.com
South Dakota Local Governments Face Cybersecurity Funding Deadline © farmingtonvoice.com

South Dakota's $7 million SecureSD program, which helps local governments defend against cyberattacks, will run out of state funding in 2028, leaving counties and cities to cover ongoing cybersecurity costs themselves

Local governments across South Dakota are confronting a growing wave of cyberattacks just as the state's main cybersecurity support program approaches a funding deadline. Recent incidents in Pennington County and the city of Mitchell have disrupted public services and highlighted the vulnerability of local agencies that often lack the resources to defend against sophisticated threats.

Pennington County residents have experienced service outages since a July cyberattack disabled county computer systems. Rapid City's water system, part of Pennington County, was among the first utilities targeted in a nationwide series of attacks this summer, though city officials said their network was not breached. Meanwhile, Mitchell city staff lost computer access after a separate breach, further underscoring the risks facing local governments.

SecureSD Program Nears Expiration

To address these challenges, South Dakota lawmakers established SecureSD in 2024, allocating $7 million to provide cybersecurity tools, training, and technical support to local governments. The program is managed by the South Dakota Attorney General's Office and Dakota State University, and was created after the state declined to participate in a federal cybersecurity grant program, citing administrative burdens and concerns about wasteful spending.

SecureSD assists counties and cities by reviewing vulnerability reports, helping transition agencies to secure data and email systems, purchasing equipment, and offering cybersecurity training. The program also operates Project Boundary Fence, which tests local government defenses and reports on weaknesses. According to program director Mike Waldner, participation has increased in recent years, with most counties engaging in at least one aspect of the initiative.

The top priority for SecureSD has been moving local governments to professionally managed email systems that meet federal security standards. A South Dakota Searchlight analysis found that more than half of county-level email addresses are not on government domains, making them more susceptible to attacks and impersonation. Rapid City and Pennington County are both transitioning to secure, cloud-based email systems using SecureSD funding.

Uncertain Future for Local Cybersecurity

The $7 million in state funding for SecureSD is set to expire on June 30, 2028. Once the funds are depleted, local governments will be responsible for maintaining and funding their own cybersecurity improvements. Waldner noted that this uncertainty can make agencies hesitant to invest in upgrades, as they may not be able to sustain the costs long-term. He said additional funding could allow the program to expand into areas like cybersecurity management and data backup.

Sen. Randy Deibert, who helped secure the original appropriation, said the funding deadline was intended as a point for the Legislature to review the program's effectiveness and consider future recommendations. The original vision included not just funding, but also providing state-level IT support to counties unable to afford their own staff.

The Governor's Resilience and Infrastructure Task Force, led by Lt. Gov. Tony Venhuizen, is currently evaluating South Dakota's critical infrastructure and considering legislative proposals to continue or expand SecureSD. The task force is also weighing whether participation in cybersecurity programs should be required for local governments. Recently, Gov. Larry Rhoden awarded $500,000 to the task force for research and public education on cybersecurity and infrastructure resilience.

Broader Context and Next Steps

South Dakota's situation reflects a national trend, as many local governments struggle to fund cybersecurity amid increasing threats. A 2025 report by the Multi-State Information Sharing and Analysis Center found that 68% of state, local, tribal, and territorial governments lack the budget to address major cybersecurity priorities, with small and rural communities especially at risk. The uncertain future of federal cybersecurity grants has left states like South Dakota to find their own solutions.

As local governments prepare for the end of SecureSD funding, the Legislature and state officials will need to decide whether to renew or expand support. The outcome will determine whether counties and cities can continue to protect sensitive taxpayer data and maintain essential services in the face of ongoing cyber threats. For additional perspective on how state and local officials are navigating cybersecurity challenges, see this report on election security and federal-state cooperation.

SecureSD's future will be shaped by legislative review, recommendations from the Governor's task force, and the willingness of local governments to invest in ongoing cybersecurity measures. Residents and officials alike will be watching closely as the 2028 deadline approaches.

Related Stories