Local Public Administration · Municipal companies
A municipal company needs its own governance and evidence.
Its relationship with the municipality does not remove the company's identity, activity, systems, contracts and responsibilities. Cybersecurity should support the services actually delivered and their continuity.
Entity, activity and sector
Activity determines risk more than designation.
A municipal company may operate services with very different impacts and depend on administrative systems, citizen platforms, field equipment or operational technology. The framework should confirm legal personality, sector, size, services and applicable criteria without assuming that the municipal relationship automatically produces a qualification.
- Legal personality, activity, sector and size assessed together
- Company governance distinguished from municipal governance
- Administrative and operational systems included in the same map
- Evidence produced and retained by the responsible entity
Govern before delegating
Clear responsibility, specialist support and effective reporting.
Governance connects decisions, risk, resources and oversight. It must not exist only in an organization chart or an isolated document.
Own governing bodies and responsibilities
The company's competent bodies should understand risk, approve priorities, ensure resources and oversee measures applicable to the entity and the services it manages.
Coordination without dilution
The municipality may share guidance, technology or capability, but each entity's boundaries, decision-makers, access, responsibilities, contacts and evidence must remain clear.
Effective roles and channels
Where applicable under the confirmed framework, the Cybersecurity Officer (RCS) and Permanent Contact Point (PCP) should have suitable reporting, resources, information and operational coordination.
Services and dependencies
Begin with the services the company delivers and operates.
Transport, waste, environment, facilities, culture, housing and other services create different dependencies and impacts. The security architecture should reflect actual activity.
Management and digital services
- Identity, email and collaboration
- Finance, human resources and procurement
- Portals, citizen services and payments
- Document management and integrations
Field operations
- Equipment and mobility
- Facilities and operational teams
- Collection, control or supervision systems
- Communications and remote access
Sectors and impact
- Transport and mobility
- Waste, environment and public space
- Water, sanitation and energy where applicable
- Housing, culture and other local services
Third parties and service chain
- Software, cloud and telecommunications
- Maintenance and specialist support
- Operational subcontracting
- Access, responsibilities and contractual continuity
Municipal implementation
From the initial assessment to continuous improvement.
Each stage should produce a decision, verifiable implementation or evidence that allows progress to be monitored.
- 01
Characterise the entity
Confirm activity, sector, size, services, governance and relationships with the municipality and other entities.
- 02
Map operations
Connect services, processes, assets, data, facilities, teams, suppliers and the impact of unavailability.
- 03
Treat risk
Prioritize documentary, identity, infrastructure, endpoint, network, backup, monitoring and third-party measures.
- 04
Prepare response and continuity
Define decisions, contacts, containment, communication, recovery and alternatives for priority services.
- 05
Demonstrate and improve
Retain the company's evidence, test controls and update risks, contracts, exceptions and the roadmap.
Usable outcomes
Deliverables that support decision-making and implementation.
A municipal company needs its own instruments, coordinated with the municipality but connected to its governance, systems, contracts, operations and evidence.
- 01Framework, activity, sector and assumptions matrix
- 02Map of services, processes, assets and dependencies
- 03Governance model and coordination with the municipality
- 04Company gap assessment and roadmap
- 05Supplier and external-access requirements and controls
- 06Incident, communication, recovery and continuity plans
Entity evidence
Three perspectives that corroborate one another.
Governance
Resolutions, responsibilities, priorities, resources, risk acceptance and oversight by competent bodies.
Technical and contractual
Inventories, configurations, records, tests, corrections, contracts, requirements and third-party access control.
Operational
Events, incidents, exercises, response times, recovery and continuity of delivered services.
First steps
Begin with enough information to make better decisions.
The initial assessment should separate what is common to the municipal group from what the company decides, implements and demonstrates.
Open the RJCS Checker- 01Confirm legal personality, activity, sector, size and services delivered
- 02Separate proprietary, shared and third-party-operated systems
- 03Identify services with the greatest impact on users and the territory
- 04Review remote access, support contracts, backups and recovery
- 05Organize uncertainties and assumptions in the RJCS Checker
Continue along the B2G pathway
From context to role and response.
Choose the next subject without losing the connection to the framework, entity and implementation.
Continue through the ecosystem
Understand, prepare and implement.
Connect this context to technical knowledge, working tools, implementation capabilities and ongoing support.
Frequently asked questions
Provide guidance without anticipating official decisions.
Does a municipal company automatically have the same framework as the municipality?
This should not be assumed. Legal personality, activity, sector, size, services and applicable criteria should be assessed for the entity itself. Official qualification belongs to the competent authority.
Can it use the municipality's policies and procedures?
A shared basis may be used where appropriate, but documents should reflect the municipal company's actual governing bodies, responsibilities, systems, suppliers, risks and operations.
Are operational systems and field equipment in scope?
They should be considered when they support the entity's services and processes. The assessment should not be limited to administrative systems or Microsoft 365.
Which evidence should belong to the company?
Evidence demonstrating its decisions, measures, configurations, contracts, tests, incidents and continuity. Shared evidence should clearly identify its scope and the entities covered.
Primary sources
Always confirm against the official source.
Informational content. It does not constitute an official qualification, legal opinion or substitute for the powers of the entity and competent authority.
