Why this brief exists
Cities read cybersecurity directives as a technical matter and delegate them to the people who run the systems. That is the wrong reading. The change of the last cycle is about accountability, and accountability cannot be delegated to a team that does not control the budget.
Scope is wider than the IT estate
Water operators, transport operators, waste operators and municipal energy companies are the entities most often missed. They are frequently constituted as separate legal persons, and they are frequently the entities with the least mature security function.
The practical failure mode
The recurring pattern in supervision is not an absent measure. It is an unowned one: a control that exists on paper, is implemented partially, and has no named person able to say whether the residual risk is acceptable.
What good looks like
A short register of in-scope entities. A named accountable person per entity, at management level. A tested restore. A rehearsed incident procedure with the people who are actually on duty at three in the morning. Everything else follows from those four.
For ESCA members
ESCA runs a shared market consultation format for municipal cyber capability, so that smaller authorities can procure a security operations capability together rather than each failing to attract a bidder alone.