RackTop Systems
State & Local Government

Cyber-Resilient Storage for State & Local Government

State and local government agencies are among the most targeted organizations for ransomware. BrickStor SP protects citizen data, government records, and public safety systems with real-time active defense and immutable protection.

Why government agencies are prime targets

Ransomware groups specifically target state and local governments because they hold high-value data and often lack the cybersecurity resources of large enterprises. Attacks have shut down 911 centers, halted court systems, disrupted tax collection, and compromised millions of citizen records.

State and local governments are among the most frequently targeted organizations for ransomware
Attacks on municipalities have disrupted 911 dispatch, permitting systems, tax collection, and court operations
Citizen PII, court records, property records, and public safety data are high-value targets
Many agencies operate with limited IT staff and legacy infrastructure that expands the attack surface
Recovery from unprotected attacks has cost some municipalities millions in ransom and remediation
City Hall to Courthouse

Built for the team running government operations

Public records that survive a breach

Official records, court filings, election artifacts, and 911 incident logs sit on immutable storage that no compromised privileged admin can delete or overwrite. The retention obligation in the state code maps to a setting in the platform, not a backup-vendor SLA.

911, court, and permitting stay online

Dispatch either answers the call 90 minutes from now or it does not. BrickStor SP's surgical recovery restores only the files touched by the attack, which is why public-safety, judicial, and constituent-service systems come back on the timeline citizens expect.

GSA, SEWP, and Carahsoft procurement

Available through GSA Schedule, NASA SEWP V, and the Carahsoft state and local programs. The platform that meets your CJIS, IRS Pub 1075, and StateRAMP requirements also fits the contract vehicles your purchasing office already uses.

Small-team operations, enterprise-grade controls

County and municipal IT teams rarely have a dedicated SOC. Hub Central, hardened defaults, and a Jumpstart program designed for limited staff mean a 4-person team can operate the same controls a federal agency runs, without a separate security tooling stack.

CJIS Security Policy

Two CJIS dates shape the next two budget cycles

CJIS Security Policy v6.1 took effect June 26, 2026, on top of the v6.0 modernization that restructured the policy onto NIST SP 800-53 control families. For any agency or service provider that handles Criminal Justice Information, two dates now drive the plan, and the projects that satisfy them are the ones with the longest lead times.

September 21, 2026

FIPS 140-2 validations go Historical

The last day a FIPS 140-2 certificate is active. The following day NIST’s Cryptographic Module Validation Program moves every remaining 140-2 certificate to the Historical List, which takes it off the table as justification for new procurement under CJIS controls SC-13 and SC-28.

September 30, 2027

The zero-cycle period closes

Priority 2 through Priority 4 modernized requirements have been reviewed but not sanctioned since October 1, 2024. Plan for normal audit and enforcement treatment from October 1, 2027. Existing and Priority 1 requirements, including multi-factor authentication, have been sanctionable since 2024.

Where CJIS controls land on storage

CJI is unstructured data. Case files, investigative documents, evidence exports, body-worn and interview video, court filings, and RMS and CAD extracts all end up as files on a share. Five of the control families that come due read directly against the storage holding them.

AC / IAAccess Control, Identification & Authentication
Attribute-based policy is evaluated on every SMB, NFS, S3, and Web Drive operation, so a single compromised credential cannot walk the entire share structure.
AUAudit and Accountability
Every file operation is recorded with the user, client address, operation, and full path, in a log an administrator cannot quietly edit. That record is also what turns breach scoping into a query.
SCSystem and Communications Protection
Systems shipped since 2022 with FIPS drives use FIPS 140-3 Level 2 validated self-encrypting drives, and BrickStor SP 23.8 and later uses a FIPS 140-3 Level 1 validated software cryptographic module.
CPContingency Planning
ImmutaVault holds immutable, isolated copies inside the platform, and Intelligent Bulk Remediation restores only the files an attack touched, which is how recovery to a known trusted state becomes an operation with a duration.
SISystem and Information Integrity
Active Defense inspects file activity inline and terminates a malicious session in under a second, catching the bulk-read and mass-change behavior that precedes exfiltration and encryption.

Planning your CJIS work? Start here

CJIS Security Changes for 2026 and 2027

What changed in v6.1, what the FIPS 140-2 sunset actually requires, what the zero cycle does and does not defer, and what to ask a vendor for.

Read the guide →

The FBI does not certify or endorse products against the CJIS Security Policy, and there is no national CJIS certification for technology. Compliance is assessed at the agency by the CJIS Systems Agency. These descriptions cover the data-layer controls BrickStor SP supports and the evidence it produces; talk to RackTop for a control-mapping walkthrough of your environment.

Government Sectors

Protecting every level of government

Municipal Governments

Protect city records, permitting data, and constituent services from ransomware and unauthorized access.

County Governments

Secure property records, court documents, social services files, and election data with immutable protection and access controls.

Public Safety Agencies

Defend 911 dispatch records, incident reports, evidence files, and body camera footage with active defense and audit logging.

Health & Human Services

Protect HIPAA-regulated client records and social services case files with encryption, ABAC, and immutable preservation.

Courts & Judicial

Preserve court records, case filings, and judicial documents with immutable snapshots and tamper-proof audit trails.

Public Works & Utilities

Secure infrastructure documentation, engineering records, and operational data for water, power, and transportation systems.

Compliance

Regulatory and framework alignment

BrickStor SP provides capabilities that support the cybersecurity frameworks and mandates most commonly applied to state and local government agencies.

FBI CJIS Security PolicyVersion 6.1 control families for any agency or provider that handles Criminal Justice Information
CISA Shields UpGuidance for state and local agencies on defensive posture and cyber resilience
NIST Cybersecurity FrameworkRisk-based framework adopted by most state cybersecurity programs
StateRAMPState-level cloud security program modeled on FedRAMP
CIS ControlsCenter for Internet Security controls referenced in many state cybersecurity mandates
HIPAAFor agencies managing protected health information in health and human services programs
IRS Publication 1075For agencies handling federal tax information in state systems

Frequently asked questions

Two dates drive most planning. September 21, 2026 is the last day a FIPS 140-2 cryptographic module validation is active; the following day NIST moves all remaining 140-2 certificates to the Historical List, so they no longer support new procurement under CJIS controls SC-13 and SC-28. September 30, 2027 ends the zero-cycle period for Priority 2 through Priority 4 modernized requirements, which enter normal audit and enforcement treatment from October 1, 2027. Existing and Priority 1 requirements, multi-factor authentication among them, have been sanctionable since October 1, 2024.
No product is. The FBI does not certify or endorse products, solutions, or vendors against the CJIS Security Policy, and no national CJIS certification for technology exists. Compliance is assessed at the agency by the CJIS Systems Agency through the audit process. What BrickStor SP provides is data-layer control coverage across Access Control, Audit and Accountability, System and Communications Protection, Contingency Planning, and System and Information Integrity, plus the queryable evidence an auditor asks for.
Yes. Systems shipped since 2022 with FIPS drives use FIPS 140-3 Level 2 validated self-encrypting drives, and BrickStor SP version 23.8 and later uses a FIPS 140-3 Level 1 validated software cryptographic module. That matters for the September 21, 2026 transition, after which FIPS 140-2 certificates move to the NIST CMVP Historical List.
State and local governments hold valuable data (citizen PII, court records, property data, public safety files) and often have limited cybersecurity resources and legacy infrastructure. This combination makes them attractive targets for ransomware groups.
BrickStor SP's Active Defense stops ransomware before it spreads, and Intelligent Bulk Remediation restores only affected files from immutable snapshots in minutes. This minimizes downtime for constituent-facing services like permitting, court systems, and public records access.
Yes. RackTop solutions are available through GSA Schedule, NASA SEWP V, and other contract vehicles. Contact us or reach out to our distribution partner Carahsoft for procurement details.
BrickStor SP combines end-to-end encryption, attribute-based access control, behavioral monitoring, and immutable audit logging to protect personally identifiable information stored in unstructured files and shared drives.
Yes. BrickStor SP is designed to deliver enterprise-grade security with operational simplicity. The Jumpstart program helps agencies get up and running quickly, and Hub Central provides centralized management across all deployments.
Customer Proof

Safeguarding utility data archives from ransomware

A member-owned electric utility gains real-time ransomware visibility and confident recovery for its data archives.

33,000

utility customers served

3 weeks

from trial to signed contract

8 TB

extended to secure cloud via TDM

With BrickStor SP, I’m more confident in my data than ever before. I know it’s there. I know it’s protecting my archives. And I know that if I have a ransomware problem, I can go in and recover very easily.

Tamie Fox, Director of IT, Florida Keys Electric Cooperative
Read the Florida Keys Electric Cooperative case study →

Protect Citizen Data and Government Services

BrickStor SP helps state and local agencies defend against ransomware, protect citizen records, and maintain service continuity with storage-layer active defense.

Ransomware Defense for State & Local Government Data