Cybersecurity threats continue to evolve, and attackers are increasingly targeting counties through the vendors, software providers, and third-party systems they rely on every day. These incidents, often called supply chain […]

Cybersecurity threats continue to evolve, and attackers are increasingly targeting counties through the vendors, software providers, and third-party systems they rely on every day. These incidents, often called supply chain attacks, occur when cybercriminals compromise a trusted outside partner to gain access to county systems or information.
For counties, third-party relationships are essential for daily operations. Outside vendors may support payroll, benefits administration, financial systems, public records, cloud storage, software platforms, and other critical services. While these partnerships create efficiencies, they can also introduce cybersecurity risks if proper safeguards are not in place.
Third-party cybersecurity incidents can happen in several ways. A vendor may experience a data breach, a software provider may have a vulnerability exploited, or an attacker may use compromised vendor credentials to access connected systems.
Common risks include:
Because counties manage sensitive information, including PII, financial records, and employee data, understanding vendor security practices is important to reducing risk.
Cybersecurity should be considered throughout the vendor relationship, from selection and contracting to ongoing monitoring.
Counties should consider:
Vendor agreements should clearly define expectations for protecting information, reporting incidents, and managing access.
Even when an outside provider manages information, counties still have a responsibility to understand how data is protected. Employees also play an important role by following cybersecurity best practices when interacting with vendor platforms.
Employees should:
Cybercriminals often exploit trusted relationships, making awareness and communication essential.
Third-party vendors are valuable partners, but cybersecurity risks do not stop at county systems. As cyber threats become more sophisticated, counties should regularly evaluate vendor relationships, access permissions, and data protection practices. Strengthening vendor oversight can help reduce data breaches, service interruptions, financial impacts, and potential claims affecting counties and CAPP. By treating cybersecurity as a shared responsibility between counties, employees, and trusted partners, counties can better protect information, control costs, and maintain essential services. For questions or additional cybersecurity resources, please contact CTSI at 303.861.0507.
Cybersecurity threats continue to evolve, and attackers are increasingly targeting counties through the vendors, software providers, and third-party systems they rely on every day. These incidents, often called supply chain […]
The 2026 legislative session introduced several updates to Colorado’s workers’ compensation system focused on modernization, compliance, workplace protections, and administrative processes. While these changes vary in scope, counties should understand […]
County vehicles are essential tools for delivering services and supporting community programs. In some cases, counties may consider allowing vehicles to transport participants, volunteers, or individuals involved in county-supported activities, […]
More than three decades after the passage of the Americans with Disabilities Act (ADA), accessibility remains an important responsibility for county governments. The ADA is a civil rights law designed to […]