Public Sector Critical Infrastructure, the Most Vulnerable Attack Surface

What Is Critical Infrastructure?

According to the Cybersecurity and Infrastructure Security Agency (CISA), critical infrastructure includes the 16 sectors whose disruption would have devastating impacts on national security, the economy, public health, or public safety. Many of these, such as Emergency Services, Government Facilities, Water Systems, Healthcare, and Transportation — fall squarely within the Public Sector.

These Critical Infrastructure systems are interdependent and increasingly digital, but also human-driven and voice-reliant. From 911 dispatch to unemployment claims, the phone remains a lifeline between constituents and government. And attackers have noticed.

Why the Voice Channel Is a Public Sector Risk

CISA has warned that social engineering and vishing attacks can bypass traditional defenses. In fact, voice-based attacks are now among the top methods of initial access for threat actors targeting municipalities, state agencies, and federal institutions.

The Voice Channel Must Be Treated as Critical Infrastructure

The voice network is the only channel that delivers direct access to the human layer — the one layer attackers know they can still breach. That’s why protecting voice communications is now a ‘reasonable cybersecurity’ requirement in today’s regulatory and legal environment.

Voice is not just a communications tool. For public sector entities, it is:

  • A Service Delivery Mechanism
  • A Crisis Communications Backbone
  • A Pathway to Mission-Critical Systems
  • A Soft Target for Exploitation

Alarming Voice Threat Metrics

  • 1,265% increase in phone-based attacks since the rise of GenAI
  • 442% spike in vishing attacks between early and late 2024
  • 70% of organizations have already been targeted by vishing
  • 94% of security leaders agree voice should be part of their cybersecurity strategy
  • 41% remain unaware that technical solutions for voice security exist

Top Voice-Based Threats in the Public Sector

  • Vishing (Voice Phishing): Attackers impersonate officials to gain trust, extract credentials
  • Spoofing: Fake caller IDs used to deceive employees or constituents
  • Robocalls & Spam Storms: Floods of automated calls degrade systems and staff performance
  • GenAI-Based Attacks: Digitally-enhanced impersonations of staff, agency leaders or IT support
  • Social Engineering: Direct, psychological manipulation of staff to breach sensitive systems
  • Telephone Denial of Service (TDoS): spam storm-generated sabotage

Public Sector Impact Zones: The Cost of Inaction

Civic Operations:

  • Delayed response times to constituents and inter-agency coordination
  • Disruption of emergency programs, benefits, and public safety alerts
  • Voice-based sabotage of critical Public Safety Answering Points (PSAPs)

Constituent Experience:

  • High call abandonment rates due to robocalls and spoofed call queues
  • Increased fraud targeting vulnerable populations (e.g., seniors, veterans)
  • Exposure to identity theft via compromised Personally identifiable Information

Risk Management & Security:

  • Voice used as an entry point to breach IT systems
  • Non-compliance with mandates like FISMA, CJIS, and NIST 800-53
  • Legal exposure under new ’reasonable cybersecurity’ standards

Public Agencies Cannot Rely on Awareness Training Alone

Security awareness training is essential — but it is not enough.

Government employees, help desk agents, and call center operators are under constant pressure. In the moment, even well-trained staff can be manipulated by a convincing voice.

CISA’s own research confirms that human factors — not technical gaps — are now the leading cause of breaches. And in many recent incidents, including the MGM Resorts and Caesars breaches, the attack started with a simple phone call.

CISA, Compliance, and the Voice Imperative

As CISA continues to push for sector-specific resilience and risk reduction, public sector organizations must look beyond traditional IT defenses.

Voice traffic must be included in zero trust strategies, incident response plans, and annual risk assessments. The absence of a voice security solution is now a material vulnerability — and a potential liability.

The Most Important Technical Control: A Voice Firewall

A Voice Firewall is a purpose-built security layer that operates at the edge of your voice network — analyzing, filtering, and blocking unwanted or malicious voice traffic before it reaches a human endpoint.

Mutare’s Voice Traffic Filter is the leading enterprise-grade voice security solution, with a multi-layered architecture that includes:

  • STIR/SHAKEN – Analyzes STIR/SHAKEN attestation scores in call data for evidence of suspected call spoofing.
  • Proprietary Dynamic Database – Integrates data from worldwide resources to identify known spam, scam, spoofing and robocalls.
  • Threat Radar – Applies a set of analytic processes to detect atypical call patterns consistent with nefarious activity.
  • Custom Rules – Creates organization-specific custom rules directing filtering actions for matching calls.
  • Voice CAPTCHA – Extra layer of vetting that challenges callers to enter random digits before call is complete

It is Time to Protect Public Services…Secure the Voice Channel, Now!

  1. Eliminate voice threats at the network edge
  2. Demonstrate ‘reasonable cybersecurity’ in line with CISA guidance
  3. Restore staff focus and rebuild public trust in your agency’s voice systems