Skip to content

Security

How should public sector IT teams monitor for uptime?

Monitoring shows you trouble coming; tested backup and recovery is how citizen services survive when it arrives anyway.

Monitoring screen with a spiking line graph in the foreground and a lit European town hall at dusk behind it

The short answer

Public sector IT monitoring should cover four layers: infrastructure, citizen-facing applications, cloud and SaaS workloads, and backups. Each alert needs a named owner and an escalation path, and monitoring must connect to tested recovery. ENISA ranks public administration as the EU's most targeted sector, and NIS2 now makes this resilience a legal duty for in-scope bodies.

Key takeaways

  • Public administration was the most targeted sector in the EU at 38.5% of incidents in the ENISA Threat Landscape 2025, mostly low-impact DDoS.
  • Monitor four layers: infrastructure, applications such as citizen portals, cloud and SaaS workloads, and the backup environment itself.
  • An alert without an owner is decoration: give every alert a responsible person, a response time and an out-of-hours route.
  • Monitoring can't undo ransomware or data destruction, so pair it with immutable backups and recovery tests timed against each service's RTO.
  • In the Netherlands the Cyberbeveiligingswet covers ministries, provinces, municipalities and water boards, so uptime and recovery are now evidence you must be able to show.

Why is public sector IT such a frequent target?

Because disrupting public services creates political and social pressure, and that's exactly what hacktivists and ransomware groups want. The figures from ENISA bear this out.

Picture a municipality's citizen portal on a weekday morning. Traffic graphs have been climbing oddly for forty minutes before the portal stops responding. Residents can't book appointments, and the contact centre fills up. The signs were in the monitoring data, but nobody was assigned to act on them. Whether you run IT in-house or as an MSP using an EDR platform across municipal clients, monitoring only helps when it connects to people and to recovery.

According to the ENISA Threat Landscape 2025, public administration was the most targeted sector in the EU at 38.5% of incidents, dominated by low-impact DDoS (94.8%); only 2% of the DDoS incidents ENISA tracked led to service disruption. ENISA's sectoral threat landscape for public administration analysed 586 publicly reported incidents in 2024:

  • DDoS made up more than 60% of incidents.
  • Data breaches accounted for 17.4%, and ransomware for about 10%.
  • Central government was hit in 69% of incidents, local entities in 24% and regional bodies in 6.8%.
  • Among local entities, municipalities were the most common target, at almost 44%.

Structural factors add to the risk: long procurement cycles keep legacy systems running, small teams manage large estates, and citizen data raises the stakes of any breach.

What should public sector IT actually monitor?

Four layers, each with signals that point to real citizen impact. Watching everything equally creates noise; watching the right signals creates warning time.

LayerExamplesPriority signals
InfrastructureServers, network, storage, firewallsCapacity, hardware health, unusual traffic patterns that suggest DDoS
ApplicationsCitizen portals, registries, case managementSynthetic checks that mimic a resident logging in or booking an appointment, response times, error rates
Cloud and SaaSMicrosoft 365, hosted applicationsService health, sign-in anomalies, admin changes
Backup environmentBackup jobs, restore points, repositoriesJob success, verified restore points, retention changes, repository access

Add certificate expiry and patch status for every internet-facing system. An expired certificate or an unpatched portal is one of the easiest outages to prevent, and patch gaps are a common way in for attackers.

What does downtime cost when the service is public?

More than money. Residents lose access to essential services, staff fall back on paper, and trust in digital government takes a hit that lasts beyond the outage.

The October 2023 ransomware attack on Südwestfalen-IT, a shared IT provider for local government, shows the scale. The Record reported that more than 70 municipalities in North Rhine-Westphalia lost access to town hall services, resident records, registry offices, finance systems and email. A single provider failure became a regional outage.

Direct costs include emergency recovery, external incident response, overtime and possible regulatory consequences. For a model you can reuse, see our guide to the cost of downtime.

How do you build an uptime strategy? A five-step plan

Rank your services, monitor all four layers, connect alerts to people, treat backups as production and rehearse recovery every quarter.

  1. Inventory and rank critical services. List every citizen-facing and internal service and give each a maximum tolerable downtime. That becomes its RTO, how long it can be down, and its RPO, how much data it can afford to lose. Our RTO and RPO explainer shows how to set both.
  2. Deploy layered monitoring with baselines. Cover endpoints, network, applications and cloud workloads. Record a few weeks of normal behaviour so deviations stand out.
  3. Wire alerts to people. Every alert needs an owner, a response time and the authority to act, including out of hours. Practise with drills.
  4. Monitor backups as a production system. Track job success, restore-point integrity and who accesses the repository. A failed backup nobody notices is an outage waiting to happen. See how to verify your backup works.
  5. Rehearse recovery every quarter. Restore real services against their RTO, record the results and fix what's slow.

ENISA's recommendations for public administration add concrete controls: content delivery networks and web application firewalls with always-on protection against DDoS, DNS failover to a static backup site, MFA with conditional access, and EDR with network segmentation against ransomware.

What can monitoring do, and what can't it do?

Monitoring prevents or shortens incidents you can see coming. It can't undo successful ransomware or data destruction; that's the job of backup and disaster recovery.

AspectMonitoringBackup and disaster recovery
GoalSpot problems before residents noticeRestore service when prevention fails
HandlesCapacity issues, hardware faults, DDoS onset, patch gapsRansomware, data destruction, major outages
NIS2 linkRisk analysis and incident handling, Art. 21(2)(a)-(b)Business continuity and backup management, Art. 21(2)(c)
Key metricMean time to detect and respondActual recovery time against RTO
LimitationCan't undo damageCan't prevent incidents

What does NIS2 require from public administration?

For in-scope public bodies, Directive (EU) 2022/2555 turns resilience into a legal duty. Public administration is listed in Annex I, and Article 2(2)(f) brings central government entities into scope, with Member States able to include regional and local bodies.

  • Article 21(2): ten measures, including (c) "business continuity, such as backup management and disaster recovery, and crisis management".
  • Article 23: for significant incidents, an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.
  • Article 20: management bodies approve and oversee the measures, must follow training and can be held liable.

In the Netherlands the Cyberbeveiligingswet came into force on 15 August 2026. According to Digitale Overheid, it applies to ministries (including agencies), provinces, municipalities and water boards, and to some independent administrative bodies and joint arrangements. In Germany the NIS2UmsuCG has applied since 6 December 2025. Check your organisation's position in our NIS2 scope guide.

What to do next

Public sector uptime is now a regulated outcome, not only a service level. Rank your services, monitor all four layers, connect every alert to someone accountable and rehearse recovery until the evidence builds itself.

Mindtime covers the recovery side. Backups are monitored 24/7, every backup job is checked automatically, and data is stored only in our own Tier III data centres in the Netherlands and Germany as immutable copies plus an air-gapped copy. Critical workloads are restored on a 4-hour SLA, and our disaster recovery service runs automated DR tests every quarter, with evidence for auditors. Support is personal, in Dutch, German and English. MSPs serving municipalities can add the Mindtime EDR platform for the endpoint layer, with their own team running the service.

Would your monitoring and recovery setup satisfy an auditor? Get a free assessment.

This article is information, not legal advice.

Frequently asked questions

What does NIS2 require from public sector organisations?

In-scope public bodies must take the risk-management measures in Article 21(2) of the NIS2 Directive, including incident handling and "business continuity, such as backup management and disaster recovery, and crisis management". Article 23 sets reporting deadlines of 24 hours, 72 hours and one month, and Article 20 makes management bodies responsible. National laws, such as the Dutch Cyberbeveiligingswet, set out exactly which bodies are covered.

Which uptime metrics should government IT teams track?

Track availability per critical service using synthetic checks that mimic real resident journeys, mean time to detect and mean time to repair, backup job success with verified restore points, and actual recovery time against the RTO in quarterly tests. It also helps to track how many incidents monitoring caught before users reported them, a direct measure of whether your monitoring works.

Can monitoring alone prevent downtime in public sector IT?

No. Monitoring prevents or shortens incidents you can see coming, such as capacity exhaustion, hardware faults and the start of a DDoS attack. It can't undo a successful ransomware attack or data destruction. You need both layers: monitoring to reduce incidents and tested backup and disaster recovery to limit the damage when an outage gets through.

Are Dutch municipalities covered by the Cyberbeveiligingswet?

Yes. According to Digitale Overheid, the Cyberbeveiligingswet, the Dutch implementation of NIS2, applies to ministries and their agencies, provinces, municipalities and water boards. Independent administrative bodies and joint arrangements are covered when they meet the criteria for a government institution. The law came into force on 15 August 2026; check the official guidance for your organisation's obligations.

How do public bodies protect citizen portals against DDoS?

ENISA recommends putting critical portals behind a content delivery network and web application firewall with always-on protection, and setting up DNS failover to a static backup site. Monitoring traffic baselines gives early warning, and a tested communication plan keeps residents informed. Most DDoS attacks on public administration are low impact, but portals still need a plan for the ones that land.

Sources

  1. ENISA Threat Landscape 2025 (booklet)ENISA, 2025
  2. ENISA Sectorial Threat Landscape: Public AdministrationENISA, 2025
  3. Public administration increasingly targeted by DDoS attacksENISA, 2025
  4. Voor welke overheidsorganisaties geldt de Cyberbeveiligingswet?Digitale Overheid (Dutch Ministry of the Interior), 2026
  5. Massive ransomware attack hinders services in 70 German municipalitiesThe Record by Recorded Future News, 2023
  6. Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022
Part ofEDR Platform for MSPs