Pennington County residents haven’t been able to access some services since a cyberattack knocked out county computer systems in July.
The water system in Rapid City, which is part of Pennington County, was among the first of dozens of utilities targeted in a nationwide wave of cyberattacks this summer. The attackers did not access its network in Rapid City, city officials said.
Mitchell, meanwhile, is recovering from its own breach, which left city staff without computer access.
The three incidents — all hitting South Dakota local governments within weeks of each other — underscore a vulnerability that state officials have spent years and millions of dollars trying to address.
Local governments hold sensitive taxpayer data, but often lack the staff, budget or expertise to protect it from cyberattacks. A 2025 report by the Multi-State Information Sharing and Analysis Center found that 68% of state, local, tribal and territorial governments lack the budget to address major cybersecurity priorities, and that small and rural communities are especially vulnerable.
A state-funded program in South Dakota is working to close that gap — but time and money are running short.
State funding in place of declined federal funding
SecureSD is a $7 million program run by the South Dakota Attorney General’s Office and Dakota State University that delivers cybersecurity tools, training and technical support to local governments.
Lawmakers launched the program with funds in 2024 in response to Gov. Kristi Noem rejecting a piece of $1 billion in cybersecurity grants to states. Noem spokesman Ian Fury told South Dakota Searchlight at the time that the grants were “wasteful spending,” adding the administrative burden of the grant “would have far exceeded the allowable administrative cost.”
That 2022 four-year federal grant program, part of the 2021 Infrastructure Investment and Jobs Act, faces an uncertain future. Congress extended the program through next month, but did not provide new funding. Efforts to reauthorize the program haven’t cleared both chambers.
South Dakota’s SecureSD program is led by Mike Waldner, who previously directed South Dakota’s centralized education email system.
The program reviews regular vulnerability reports from the Department of Homeland Security for local governments that sign up for the program, which flag issues like outdated software or misconfigured firewalls. It also helps transition local governments to more secure data and email, purchases equipment or contracts with information technology companies to monitor cybersecurity needs, and trains local employees. SecureSD also runs Project Boundary Fence, in which cybersecurity experts test local governments’ defenses and report back on weaknesses.
Most counties have participated in at least one aspect of the program, including Project Boundary Fence, and participation has “ramped up” in recent years, Waldner said.
“It’s like walking through a parking lot and checking doors. We’re not there to steal anything, but we’ll tell people when their doors are unlocked so they can fix it,” Waldner said.
The “hands down number one priority” of SecureSD, Waldner said, is moving local governments onto professionally managed email systems that meet federal security standards — a step up from the patchwork of local setups many counties currently rely on.
More than half of county-level email addresses, based on a South Dakota Searchlight analysis of county auditor email addresses, are not on government domains, making them more vulnerable to attacks and impersonation. Only verified U.S.-based public sector organizations, including state and local governments, can get a .gov email address, and agencies must have advanced security protocols that make it harder for scammers to copy or fake official government messages.
“We’re working our tails off to remedy that and fix that, for a number of reasons,” Waldner said.
Rapid City is transitioning to a government, cloud-based email system using SecureSD funding, said Jim Gilbert, the city’s director of information technology. Katy Urban, public information officer with the Pennington County State’s Attorney Office, said the county is in the process of the same transition.
The $7 million in state funding for SecureSD expires June 30, 2028. Waldner said all of it will be spent — but once it runs out, local governments will have to absorb the cost of maintaining any improvements themselves. That uncertainty is “one of the biggest reasons an entity pauses” when considering cybersecurity upgrades, he said.
Waldner has had to prioritize the secure data and email transition as the expiration date nears. He said additional funding could eventually allow the program to expand into other areas, including cybersecurity management and data backup.
“My hope is we can secure funding and not only pay for the data and email solution, but pay for additional cybersecurity functions I know are needed,” Waldner said.
Future of state help for local governments
Sen. Randy Deibert, R-Spearfish, was among the lawmakers who championed the $7 million appropriation in 2024. A former Lawrence County commissioner, he said the program’s upcoming funding deadline was a built-in inflection point for the Legislature.
“It’s probably time to take a good look at that local government cybersecurity program and get an update on it for lawmakers: what’s working, what’s not, what should work,” Deibert said. “We should have some recommendations after a couple of years.”
Deibert said the original vision wasn’t just funding — it was to offer state-level IT support to counties that couldn’t afford their own, similar to how the state helped school districts move onto secure email systems. He noted that Lawrence County has been fortunate to have a strong IT person on staff, but acknowledged not every county is in that position.
“I’m not certain that throwing dollars at it is the key,” Deibert said.
Lt. Gov. Tony Venhuizen leads the Governor’s Resilience and Infrastructure Task Force. That group is evaluating South Dakota’s critical infrastructure — energy, water, data networks and more — and identifying vulnerabilities to natural disasters and cyberattacks. The task force discussed SecureSD at its August meeting and plans to recommend legislative proposals next session, including how to expand and continue the program.
“We haven’t made a final decision on what to propose, but it’s clear the need is still there and is going to still be there to continue to serve local governments in this way,” Venhuizen said.
The task force is also considering how much the state should require local governments to participate in cybersecurity programs, rather than leaving it voluntary.
Gov. Larry Rhoden recently awarded $500,000 to the task force to primarily fund research by Dakota State University and South Dakota Mines. The money is meant to build a map of the state’s critical infrastructure systems to identify vulnerabilities and redundancies. The funding will also support public education on cybersecurity and how residents can prepare for disruptions.

(0) comments
Welcome to the discussion.
Log In
Keep it Clean. Please avoid obscene, vulgar, lewd, racist or sexually-oriented language.
PLEASE TURN OFF YOUR CAPS LOCK.
Don't Threaten. Threats of harming another person will not be tolerated.
Be Truthful. Don't knowingly lie about anyone or anything.
Be Nice. No racism, sexism or any sort of -ism that is degrading to another person.
Be Proactive. Use the 'Report' link on each comment to let us know of abusive posts.
Share with Us. We'd love to hear eyewitness accounts, the history behind an article.