Severe weather alert · Public paper

Suffolk County · FIPS 25025 · Through Monday 11:59 p.m. Pacific

Saturday, September 26, 2026, Boston Harbor and the New England coast: the September nor’easter is the public clock.

Effective immediately. Evening high tide at Boston Harbor about 11:54 p.m. NWS Boston/Norton products in force: High Wind Warning, Coastal Flood Warning, and Flood Watch. Not a municipal evacuation order. Not a newspaper. Not Legal Publication. Not a government website.

Starlink powered

Not a government websiteIndependent public notice register

Company newsroom — sourced from Microsoft · Notice Nearby

Preparing governments for an era of interconnected cyber risk

Microsoft

October 1, 2026

Read original on the Microsoft newsroom

According to this year’s Microsoft Digital Defense Report , government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. Governments are also the most frequently targeted sectors for nation-state activity. They are attractive targets because they hold sensitive information , operate essential services, and sit at the center of networks of agencies, contractors, technology providers, and critical infrastructure operators.    Dwell time, the period between when an attacker gains access and when defenders detect and stop them, also increased this year across multiple sectors. While organizations responded faster once an intrusion was identified, detecting threats early remains a challenge. Attackers increasingly gain access through techniques that mimic legitimate activity, making malicious behavior harder to spot. For example, phishing accounted for 23% of observed intrusions in 2026, up from 7% in 2025, highlighting the continued importance of compromised identities as an entry point for broader attacks.   Taken together, the implication for governments is clear. Security in the AI era is no longer simply about preventing individual intrusions. It is about ensuring institutions can operate effectively in an environment where risks are interconnected, threats move faster, and attackers remain hidden longer. Public-private partnerships are also more important than ever for securing critical government infrastructure and developing the policies and regulations needed for emerging technologies.    In this year’s report, which examines cyber threat trends observed between July 2025 and June 2026, Terrell Cox, Microsoft’s Corporate Vice President & Deputy Chief Information Security Officer, and I explore how these dynamics are reshaping cyber risk. In a companion blog , Terrell takes a closer look at what these findings mean for CISOs and security professionals. To strengthen resilience, governments should focus on five priorities: 1. Prepare for a faster threat environment   AI is compressing the window for action. Adversaries are moving faster. A vulnerability’s discovery in the wild to active weaponization can be well below 24 hours. While the number of publicly disclosed software vulnerabilities (commonly tracked as CVEs) is projected to reach a record 72,000 in 2026.   Governments best prepared for the future will be those that can rapidly gather and assess information, make decisions, coordinate across institutions and industries, and communicate effectively during a crisis. This requires clearly defined responsibilities and trusted relationships established before an incident occurs, enabling swift and coordinated action when it matters most.    2. Build security into the AI ecosystem   AI is becoming part of the infrastructure that governments, businesses, and citizens rely on every day. As governments continue to adopt AI across public services and encourage its broader use, they should approach its security as a resilience challenge rather than a narrow technical issue.   AI systems depend on interconnected infrastructure, data, models, applications, suppliers, and governance processes. Governments should promote security across this ecosystem through secure-by-design practices, testing and evaluation, stronger s upply chain protections, transparency, accountability, and international cooperation on AI risk.   The goal is not to create a separate AI security agenda. It is to integrate AI security into broader efforts to protect critical infrastructure and build national resilience.   3. Plan for incidents to spread Governments may not immediately know whether an intrusion is criminal, geopolitical, or something else. Cybercriminals and nation-state actors pursue different objectives, but increasingly rely on many of the same entry points, including compromised identities, exposed applications, social engineering, and legitimate administrative tools.   Microsoft found that 52.2% of intrusions involving valid accounts resulted in additional credential theft, highlighting how quickly attackers can expand beyond an initial foothold. A seemingly isolated compromise can evolve into ransomware, espionage, data theft, or disruption of essential services.   Governments should therefore assess incidents not only by how they begin, but by where they could lead. Response plans should account for the suppliers, partners, and service providers supporting critical functions. As attacks expand beyond their initial targets, they can also cross organizational, sectoral, and national boundaries, reinforcing the need for global collaboration.   4. Enable timely, two-way public-private information sharing   A compromised account at one organization may provide early warning of a broader campaign. Signals that appear inconclusive in isolation can reveal coordinated activity when combined across organizations and jurisdictions. Modern cybercrime operates through interconnected networks of actors, services, and infrastructure that no single institution can fully see or disrupt on its own.   Information sharing must be timely, trusted, and two-way— also known as bidirectional. The goal is not simply for companies to report threats to government. Public agencies should also return actionable intelligence, guidance, and warnings that help organizations protect their networks, customers, and operations. Trusted channels can enable this exchange among government agencies, law enforcement, critical infrastructure operators, technology providers, and international partners while respecting legal and privacy requirements.   Policymakers can support this cooperation through protections for good-faith information sharing, common anonymization standards, and investment in shared threat intelligence and detection capabilities. Information sharing should also lead to action, including investigations, disruption efforts, and accountability for those responsible for serious cyber intrusions.   5. Prepare essential services to operate through disruption The organizations governments depend on to deliver public services, including transportation systems, communications infrastructure, schools, universities, and critical infrastructure operators, are increasingly targeted by cyber threats. Resilience therefore requires understanding not only government systems, but the broader ecosystem that supports them. Planning documents alone are not enough. Governments should regularly conduct tabletop exercises bringing together policymakers, operational leaders, law enforcement, critical infrastructure operators, and private-sector partners to test how they would respond to incidents disrupting essential services. These exercises can expose gaps in decision-making, information sharing, public communications, and cross-sector coordination before a real-world crisis. Microsoft’s work through initiatives such as the Advancing Regional Cybersecurity (ARC) program, most recently in Kenya , illustrates how scenario-based exercises and cross-sector collaboration can help strengthen preparedness and response capabilities across the broader ecosystem.   Government leaders should also know which services are most critical, which identities, systems, suppliers, and infrastructure support them, and how incidents will be escalated. Shared-service approaches can help extend security and response capabilities to local governments and public institutions that cannot build them independently.   As cyber incidents cross organizational and national boundaries, resilience depends not only on technical preparedness, but on whether institutions can coordinate effectively under pressure.   In an era of AI-enabled and increasingly interconnected cyber threats, resilience is no longer simply about recovering from an attack. It is about preparing for a world in which cyber incidents move faster, spread further, and affect more organizations than ever before. Governments best prepared for the future will be those that can contain harm, adapt quickly, and continue delivering critical services when citizens need them the most.    Tags: Digital Defense Report , Report — Company newsroom — sourced from Microsoft. Matter furnished by the company. Not a Notice Nearby paid placement. This page reprints matter furnished by the company from its official newsroom. Notice Nearby did not write this release. Read the original: https://blogs.microsoft.com/on-the-issues/2026/10/01/preparing-governments-for-an-era-of-interconnected-cyber-risk

Company newsroom — sourced from Microsoft. Matter furnished by the company. Not a Notice Nearby paid placement. NN-PR-NR-2026-0842. This page reprints matter furnished by Microsoft from its official newsroom. Notice Nearby did not write it, and it is not a $79 paid placement. It is not a legal public notice, not an obituary, and not an official Notice Nearby announcement. Record of Sale, LLC · Oregon.

The chain stores a hash, not the notice. The hash is not statutory publication. View on blockchain. Base stores the content hash, publication number, press-release id, and timestamp — not the full release text. The complete release remains on Notice Nearby. This is advertising, not a legal notice.

92c03bf8 f4168ac4 a1c16219 9d2613ec 0baedc94 6fd91c1e 75295747 37a21cc5

All press releases · Official newsroom