Technological solutions abound for addressing social inequities, rectifying administrative inefficiencies, expanding civic engagement, enhancing public communications, improving system monitoring, mitigating harms to the natural environment, speeding up response to social and infrastructural conditions, and supercharging economic growth potential.
However, the costs of procurement, implementation, and maintenance of the interventions can turn intended improvements into expensive problems. The costs are two-fold: production costs (the sticker price) and transaction costs, the latter of which are the subject of this essay. Transaction costs are generally defined as the costs of searching for information, coordination between parties, drawing up and enforcing contracts, and negotiation (Williamson 1981; Whittington 2012; Terman 2023). When unaccounted for, decision-makers find themselves surprised by and unprepared to assume such costs, shining a spotlight on needed changes in administrative activities and cost overruns not captured by the initial resource allocations. This is critical, especially during an era of intense pressure to adopt and upgrade digital infrastructure at scale.
Managing Municipal Cyber Risk
While technological advancements have brought greater efficiencies in civic functions such as finance, administration, monitoring, and communications, the ubiquity of digital infrastructure has created an expansive attack surface that renders personal data, operations, finances, and a host of other elements vulnerable. Most local governments require extensive support and preparation to span the gap between their current readiness and response capabilities and those recommended by cybersecurity leaders in industry and the federal government. "Local governments are often priced out of meeting best practices," according to journalist Jule Pattison-Gordon, who authored an article describing the challenges municipalities face when managing cyber risk (Pattison-Gordon 2022).
These are the costs of increased efficiency, especially via an expanded digital infrastructure footprint, whether through software, hardware, or in the cloud.
My research into municipal cyber risk management found that the cost of strengthening institutional cyber posture extends well beyond the purchase price of new hardware, software, or services. Municipalities encounter substantial transaction costs as they search for appropriate solutions, coordinate among internal departments and external vendors, negotiate contracts and insurance requirements, demonstrate standards compliance, and develop the organizational capacity necessary to maintain new systems once they are deployed.
These costs matter because they are not distributed evenly. A well-resourced government may have dedicated cybersecurity personnel, procurement expertise, legal capacity, and established vendor relationships through which to absorb them. Smaller or less-resourced municipalities face many of the same cybersecurity expectations without the personnel or institutional infrastructure needed to satisfy them. The technological solution is therefore often available while remaining institutionally difficult to adopt.
Technology creates continuing obligations
Municipal adoption of digital infrastructure creates responsibilities that continue long after a system is purchased or installed. The clearest expression of this in my findings is the rise of municipal "self-insurance" as the primary mode of managing cyber risk. Self-insurance encompasses the ongoing work required to reduce exposure and remain resilient:
- Threat monitoring
- Incident-response and communications planning
- Emergency budgeting
- Hiring qualified IT personnel
- Workforce cybersecurity training
- Hardware and software upgrades
- Maintaining data backups, system and data recovery
Chiefly, self-insurance means allocating a budget for that work.
These responsibilities are not optional add-ons. They are necessary because expanded digital infrastructure also expands the attack surface and because municipalities cannot tolerate prolonged interruptions to core services.
The obligations multiply as systems become more interconnected. Legacy hardware and software often contain vulnerabilities, while every new connected device can introduce another potential entry point into municipal networks. Managing systems produced by different vendors, running different software versions, and operating under different security standards requires continuous attention to interoperability, security, and risk containment. Even mechanisms intended to transfer risk do not eliminate these obligations. Cyberinsurers require municipalities to demonstrate adequate personnel, controls, hardware, software, and organizational practices before offering coverage.
The key takeaway is that technology adds capabilities and creates an enduring set of technical, organizational, financial, and governance responsibilities that institutions must continually manage.
Managing those obligations generates transaction costs
My findings show that the ongoing responsibilities created by digital infrastructure must be organized through a wide range of procedural activities, and those activities generate transaction costs. The research identifies four principal sources: search and coordination of information, monitoring and inventory, contracts and negotiations, and compliance and enforcement. These costs appear throughout municipal cybersecurity practice. Hiring qualified personnel requires searching for expertise and negotiating compensation. Procuring technology involves locating vendors, navigating public procurement procedures, managing interoperability, negotiating contracts, and assigning liability. Threat monitoring can require coordinating with federal or state agencies, nonprofit providers, or private firms, along with establishing data-sharing arrangements and monitoring service relationships.
Even assistance intended to reduce municipal burdens creates procedural work. Applying for grants requires identifying programs, preparing applications, coordinating participation, and satisfying reporting or compliance requirements. Budgeting requires internal negotiation; training requires coordination; audits require preparation and remediation; monitoring requires provider search and data-sharing agreements; and government assistance requires grant preparation and compliance. Municipalities may lack the staff time and knowledge needed even to access available assistance. These are the expenditures of how, distinct from the visible production costs of what.
Those costs expose differences in institutional capacity
The transaction costs of cybersecurity governance are not experienced equally because municipalities vary substantially in personnel, expertise, administrative capacity, financial resources, and existing infrastructure. Many local governments lack some combination of money, knowledge, technology, and qualified personnel necessary to prepare for, monitor, and respond to cyber threats. Municipalities with relevant expertise in-house can absorb activities such as audits, testing, monitoring, and training internally. Those without that capacity must seek outside assistance or contract for services, adding search, procurement, coordination, and oversight burdens to underlying cybersecurity tasks.
My findings also reveal a recursive problem: limited capacity can make it harder to obtain the resources intended to increase capacity. Federal and state grants may help municipalities improve their cybersecurity posture, yet participation requires institutional capacity to locate programs, prepare applications, and comply with program requirements. One-time funding may purchase new systems while leaving long-term sustainment costs to the municipality. Similar dynamics appear in cyberinsurance, where municipalities with vulnerable legacy systems or weak security practices may face higher barriers to coverage and must first invest in self-insurance measures before transferring risk. Institutional capacity therefore shapes not only whether municipalities can adopt technological safeguards, but also how costly the process of governing those safeguards becomes.
The cost of a technological intervention cannot be separated from the institutional capacity required to implement and govern it.
Production costs are expenditures on what whereas transaction costs are the expenditures of how. Policymakers must evaluate technology not only according to what it can accomplish, but according to what its integration will require of an institution.
Procedural feasibility should be evaluated alongside technical and financial feasibility before adoption. During implementation, governance requirements must be executable: rules and standards require corresponding personnel, expertise, authority, time, and resources. Over time, however, these transaction costs change. Institutional learning, repeated relationships, and familiarity with procedures can reduce them.
Before adopting a technological solution, decision-makers should ask what continuing obligations it will create and what organizational work will be required to meet them. They should identify who will be responsible for that work and whether those institutions have the capacity to perform it sustainably. Where that capacity does not exist, the cost of building, purchasing, or coordinating it belongs in the assessment of the technology itself.
Technology's benefits come with additional costs, and it is critical that those costs are visible before making decisions about adoption. Evaluating a technology intervention requires asking not only what it costs to acquire or what efficiencies it promises, but what an organization will have to do to use it responsibly and sustainably. Making those procedural requirements explicit gives decision-makers a more complete basis for determining where technology is useful, where additional capacity is necessary, and where another solution may be more appropriate.
Sources
- Pattison-Gordon, J. "Local Governments Seek Other Options Amid Cyber Insurance Woes." Governing. Last modified May 15, 2022. governing.com
- Terman, J. N. (2023). Third-Party Governance. Routledge. doi.org/10.4324/9781003286950
- Whittington, J. (2012). When to Partner for Public Infrastructure? Journal of the American Planning Association, 78(3), 269–285. doi.org/10.1080/01944363.2012.715510
- Williamson, O. E. (1981). The economics of organization: The transaction cost approach. American Journal of Sociology, 87(3), 548–577.