Integrated IT services Public-sector vertical Book a call

Defense for citizen-facing systems
ransomware, identity, compliance.

Mandala IT protects municipal infrastructure, government portals and education systems against the threats that disrupt public services — with predictable budgets, audit-ready evidence, and breach-notification timing that meets statutory clocks.

  • 0 Global gov cyber spend (USD)
  • 0 US federal cyber spend (USD)
01 · Market

A multi-tens-of-billions market driven by ransomware reality and regulator pressure.

Public-sector cybersecurity is no longer optional spend — it's the operational license to keep citizen services running.

Global gov cyber spend

0

Approximate global public-sector cybersecurity spend (industry research, $25B band).

US federal cyber budget

0

US federal civilian and defense cybersecurity spend — rising every cycle.

US local-gov ransomware / yr

0

Reported ransomware incidents against US local governments and school districts annually.

Why budgets keep growing

Ransomware on municipal infrastructure is now routine, not exceptional. The floor keeps rising every legislative cycle.

Why the model fits

Public-sector buyers prefer fixed-fee predictability over per-event variability. Mandala IT offers performance metrics for accountability but commits to capped monthly billing.

02 · Risk surface

The threat landscape Mandala IT is built to defend against.

Eight overlapping threats — every one disrupts citizen services and triggers statutory notification obligations.

03 · The company

Mandala IT — built for the operational reality of public-sector IT.

Mandala IT operates inside the rapidly expanding public-sector cyber segment, delivering an integrated detection-response-and-evidence layer designed to defend services, document incidents, and meet notification clocks.

  • Real-time ransomware-variant detection and lateral-movement containment
  • Citizen-portal identity verification with MFA step-up
  • Privileged-user activity monitoring with insider-exfiltration alerts
  • Breach-notification drafting against statutory clocks
  • Fixed-fee monthly model — predictable for procurement

“Public-sector cyber is not optional anymore — it is the operational license to keep services running. The right vendor brings detection and the paper trail.”

04 · Differentiator

Performance-tracked, fixed-fee billed — accountability without budget surprises.

Mandala IT combines performance metrics with capped fixed-fee billing — the structure public-sector procurement actually approves.

01

Procurement-friendly billing

Fixed monthly fee with performance metrics tracked transparently — no per-event surprises.

02

Accountability built in

Performance metrics are reported quarterly to elected officials.

03

Multi-agency scale

One contract can cover a department, an entire municipality, or a school-district consortium.

04

Predictable renewals

Multi-year contracts with floor-and-cap structures keep budgets stable.

05

Municipal + education + gov

Same engine serves city CIO, school-district IT director, and state agency CISO.

06

Evidence + notification engine

Every billable event has an audit chain — when the regulator or AG calls, the trail is ready.

05 · Pillars

What we cover for you.

Five pillars under one engine — the bundle every government / municipal / education CIO buys together.

Defense pillars

  • Citizen data protection
  • Ransomware defense
  • Identity verification at scale
  • Compliance posture (FedRAMP / NCD / Cyber Essentials)

What it documents

  • Incident timelines for elected officials
  • Statutory breach-notification packages
  • Audit-ready evidence chains
  • Quarterly metrics for council / board review

How it operates

  • 24/7 monitoring with municipal-tier on-call
  • Real-time detection & automated containment
  • Continuous compliance posture tracking
  • Fixed-fee billing with performance reporting
Case study · anonymised under client NDA

How we contained two ransomware attempts during a 36-month fixed-fee municipal engagement.

Buyer profile

US municipal IT · 28,000 endpoints

Scope
Police · water · transit · school district
Engagement
Managed detection + breach drafting · 36-month fixed fee
Team deployed
7 analysts + 1 procurement liaison
Stack
Splunk Cloud (kept, MSSP handover staged)
  1. 2 Ransomware attempts contained one pre-encryption, one pre-lateral
  2. 0 Breach notifications triggered across 36 months
  3. 36mo Fixed budget held no overage line-items

The situation

The municipality had three ransomware near-misses in the prior 18 months and was facing state-AG attention. Procurement needed predictable monthly billing under a 36-month vehicle; per-event variable pricing was a non-starter.

What we did

  1. 01Multi-agency Control Plane with per-department isolation across police, water, transit, and the school district.
  2. 0224/7 detection against the incumbent Splunk Cloud — contract structured to allow staged MSSP handover.
  3. 03Statutory-clock-aware breach-notification drafting (state-AG + FERPA + CISA timelines pre-templated).
  4. 04Quarterly metrics drafted for council and elected officials in plain language.
06 · Architecture

A six-layer protection stack — defense, evidence, and notification on every incident.

Every relevant event is evaluated by six cooperating layers in under two seconds.

  1. L1

    Identity

    Decide who is accessing the system — citizen, employee, or contractor.

    • Citizen identity verification for benefits and licensing portals
    • Employee MFA, privileged-access management, contractor scoping
    • Short-lived signed tokens issued to downstream agency services
  2. L2

    Behavioral monitoring

    Decide whether the activity is legitimate, in real time.

    • Insider-anomaly detection — privileged-user exfiltration, dual-control violations
    • Lateral-movement detection inside agency networks
    • Citizen-portal ATO detection
  3. L3

    Web & portal protection

    Stop the payload at the door of the citizen portal.

    • Inline blocking of injection, XSS, CSRF on benefits and licensing portals
    • Continuous vulnerability scanning of public-facing endpoints
    • API abuse detection — scraping, enumeration, business-logic abuse
  4. L4

    Threat intelligence

    Decide whether the source is already known to be hostile.

    • Ransomware-variant signatures and nation-state-actor intel
    • Live phishing-domain feeds targeting gov / education
    • Cross-tenant signal sharing
  5. L5

    Control plane

    Your CIO and elected-officials' cockpit. Where work delivered and metrics for council review live side by side.

    • Multi-agency administration with per-department isolation
    • Real-time dashboards plus quarterly council / board metrics
    • Multi-channel alerting and fixed-fee billing
  6. L6

    Mandatory breach notification

    Produce the notification package the AG / regulator / public will receive.

    • Statutory clock tracking (72-hour GDPR, state-AG, FERPA, NCSC, IL PPA)
    • Vetted breach-notification templates per jurisdiction
    • Hash-chained audit retention — examiner-ready by default
A municipal-network intrusion, end to end · under 2 seconds
  1. 01Auth
  2. 02Lateral?
  3. 03Payload check
  4. 04Source reputation
  5. 05Risk score
  6. 06Verdict
  7. 07Contain · escalate · notify
08 · Engage

Engage Mandala IT across the defense surface of public-sector services.

Engagement terms

Issuer
Mandala IT (IT services consultancy)
Engagement model
Project · Managed · Retainer · Staff-aug
Minimum engagement
From USD 10,000 per engagement
Sector
Public sector · municipal · education
Pricing model
Fixed-fee monthly retainer
Status
Open
Request proposal Book a 30-min discovery call instead

Tell us about your project

Leave your details — a Mandala IT consultant will follow up within one business day\.

How we handle your data — Privacy policy

Note. Scope, deliverables, timelines, and SLA tiers are agreed in a mutual Statement of Work. Commitments on this page are illustrative; binding terms live in the engagement contract.

09 · FAQ

Quick answers.

How does Mandala IT work with public-sector procurement?

Fixed-fee monthly billing with multi-year contracts and quarterly performance reports.

Which certifications does Mandala IT pursue for gov customers?

ISO 27001 first, then SOC 2 Type II. FedRAMP and StateRAMP pursued on customer pull.

Does Mandala IT handle classified data?

Not at this stage. Positioned for civilian municipal, state, and education customers.

How do you deploy inside a municipality?

We deploy a cloud-hosted control plane with optional on-premises agents for endpoint visibility. Multi-agency by design — one contract can cover several departments.

Do you guarantee outcomes?

We commit to measurable improvement against your baseline — quantified per engagement in the Statement of Work. SLA-backed commitments and clear remedies, not vague guarantees.

How fast can you start?

Scoping call within 2 business days. Signed Statement of Work typically within 7–14 days. Monitoring live within 30 days of SOW for standard engagements; emergency incident-response retainer can be activated within 24 hours.

Do you sub-contract any of the work?

We deliver primarily with directly-employed analysts and engineers. Where a vertical needs specialist coverage (forensics, firmware analysis, jurisdiction-specific filings), named partners are disclosed in the SOW before signature — never silently white-labelled.

What if we're already using CrowdStrike / Splunk / your state's existing MSSP?

We integrate with your existing security stack rather than displace it. Our team runs the operating layer over the tools the agency has already procured — tuning, monitoring, breach-notification drafting, quarterly metrics. We can sit alongside an existing MSSP or take over the contract; we will not silently white-label a competitor.

Where does our data live? Can we keep it in-region?

Region-specific options — EU, UK, US, Israel, GCC — are scoped per engagement. BAA (US healthcare), DPA (EU), and ISO 27001-aligned controls are issued under the engagement contract. Production data and PII do not leave your designated region without written consent.

Can we see reference clients?

After the first scoping call, under mutual NDA. Most of our clients are regulated and contractually cannot be named publicly. Reference calls with comparable-size buyers in your vertical are arranged before SOW signature.