South Dakota’s cybersecurity program is running out of time, money as local governments face attacks

Feifei Cui-Paoluzzo via Getty Images

The $7 million in state cybersecurity funding for SecureSD expires in 2028. Once it runs out, local governments will have to absorb costs.

This article was originally published by the South Dakota Searchlight.

Pennington County residents haven’t been able to access some services since a cyberattack knocked out county computer systems in July.

The water system in Rapid City, which is part of Pennington County, was among the first of dozens of utilities targeted in a nationwide wave of cyberattacks this summer. The attackers did not access its network in Rapid City, city officials said.

Mitchell, meanwhile, is recovering from its own breach, which left city staff without computer access.

The three incidents — all hitting South Dakota local governments within weeks of each other — underscore a vulnerability that state officials have spent years and millions of dollars trying to address.

Local governments hold sensitive taxpayer data, but often lack the staff, budget or expertise to protect it from cyberattacks. A 2025 report by the Multi-State Information Sharing and Analysis Center found that 68% of state, local, tribal and territorial governments lack the budget to address major cybersecurity priorities, and that small and rural communities are especially vulnerable.

A state-funded program in South Dakota is working to close that gap — but time and money are running short.

State Funding in Place of Declined Federal Funding

SecureSD is a $7 million program run by the South Dakota Attorney General’s Office and Dakota State University that delivers cybersecurity tools, training and technical support to local governments.

Lawmakers launched the program with funds in 2024 in response to Gov. Kristi Noem rejecting a piece of $1 billion in cybersecurity grants to states. Noem spokesman Ian Fury told South Dakota Searchlight at the time that the grants were “wasteful spending,” adding the administrative burden of the grant “would have far exceeded the allowable administrative cost.”

That 2022 four-year federal grant program, part of the 2021 Infrastructure Investment and Jobs Act, faces an uncertain future. Congress extended the program through next month, but did not provide new funding. Efforts to reauthorize the program haven’t cleared both chambers.

South Dakota’s SecureSD program is led by Mike Waldner, who previously directed South Dakota’s centralized education email system.

The program reviews regular vulnerability reports from the Department of Homeland Security for local governments that sign up for the program, which flag issues like outdated software or misconfigured firewalls. It also helps transition local governments to more secure data and email, purchases equipment or contracts with information technology companies to monitor cybersecurity needs, and trains local employees. SecureSD also runs Project Boundary Fence, in which cybersecurity experts test local governments’ defenses and report back on weaknesses.

Most counties have participated in at least one aspect of the program, including Project Boundary Fence, and participation has “ramped up” in recent years, Waldner said.

“It’s like walking through a parking lot and checking doors. We’re not there to steal anything, but we’ll tell people when their doors are unlocked so they can fix it,” Waldner said.

The “hands down number one priority” of SecureSD, Waldner said, is moving local governments onto professionally managed email systems that meet federal security standards — a step up from the patchwork of local setups many counties currently rely on. 

More than half of county-level email addresses, based on a South Dakota Searchlight analysis of county auditor email addresses, are not on government domains, making them more vulnerable to attacks and impersonation. Only verified U.S.-based public sector organizations, including state and local governments, can get a .gov email address, and agencies must have advanced security protocols that make it harder for scammers to copy or fake official government messages.

“We’re working our tails off to remedy that and fix that, for a number of reasons,” Waldner said.

Rapid City is transitioning to a government, cloud-based email system using SecureSD funding, said Jim Gilbert, the city’s director of information technology. Katy Urban, public information officer with the Pennington County State’s Attorney Office, said the county is in the process of the same transition.

The $7 million in state funding for SecureSD expires June 30, 2028. Waldner said all of it will be spent — but once it runs out, local governments will have to absorb the cost of maintaining any improvements themselves. That uncertainty is “one of the biggest reasons an entity pauses” when considering cybersecurity upgrades, he said.

Waldner has had to prioritize the secure data and email transition as the expiration date nears. He said additional funding could eventually allow the program to expand into other areas, including cybersecurity management and data backup.

“My hope is we can secure funding and not only pay for the data and email solution, but pay for additional cybersecurity functions I know are needed,” Waldner said.

Future of State Help for Local Governments

Sen. Randy Deibert, R-Spearfish, was among the lawmakers who championed the $7 million appropriation in 2024. A former Lawrence County commissioner, he said the program’s upcoming funding deadline was a built-in inflection point for the Legislature.

“It’s probably time to take a good look at that local government cybersecurity program and get an update on it for lawmakers: what’s working, what’s not, what should work,” Deibert said. “We should have some recommendations after a couple of years.”

Deibert said the original vision wasn’t just funding — it was to offer state-level IT support to counties that couldn’t afford their own, similar to how the state helped school districts move onto secure email systems. He noted that Lawrence County has been fortunate to have a strong IT person on staff, but acknowledged not every county is in that position.

“I’m not certain that throwing dollars at it is the key,” Deibert said.

Lt. Gov. Tony Venhuizen leads the Governor’s Resilience and Infrastructure Task Force. That group is evaluating South Dakota’s critical infrastructure — energy, water, data networks and more — and identifying vulnerabilities to natural disasters and cyberattacks. The task force discussed SecureSD at its August meeting and plans to recommend legislative proposals next session, including how to expand and continue the program.

“We haven’t made a final decision on what to propose, but it’s clear the need is still there and is going to still be there to continue to serve local governments in this way,” Venhuizen said.

The task force is also considering how much the state should require local governments to participate in cybersecurity programs, rather than leaving it voluntary.

Gov. Larry Rhoden recently awarded $500,000 to the task force to primarily fund research by Dakota State University and South Dakota Mines. The money is meant to build a map of the state’s critical infrastructure systems to identify vulnerabilities and redundancies. The funding will also support public education on cybersecurity and how residents can prepare for disruptions.

South Dakota Searchlight is part of States Newsroom, a nonprofit news network supported by grants and a coalition of donors as a 501c(3) public charity. South Dakota Searchlight maintains editorial independence. Contact Editor Seth Tupper for questions: info@southdakotasearchlight.com.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.