IntelliPay is a PCI DSS Level 1 certified payment processor working with cities, counties, utilities, courts, and school districts nationwide. This guide covers the habits that prevent most breaches at small government agencies. Learn more about government payment solutions.

Quick Read

Most breaches start with a person, not a firewall gap. The 2025 Verizon Data Breach Investigations Report puts the human element in 60% of breaches, and calls out social engineering aimed at insiders as now common in public administration.

  • You don't need a security operations center for any of this. Five habits cover most of what gets small agencies into trouble: recognizing phishing, using passphrases (or passkeys) instead of passwords, patching software promptly, knowing what's plugged into your network, and locking down who can edit your payment pages.
  • Ransomware and basic errors, not sophisticated tradecraft, drive most breaches against local government.
  • Since 2024, the FBI has tracked a nationwide wave of text messages impersonating toll agencies, courts, and utilities, demanding fake payments. Brief your front-line staff on it.
  • If your agency takes card payments online, PCI DSS 4.0.1 also has specific requirements for payment-page script monitoring. We cover those in our companion guide, Payment Page Script Monitoring for Small Government Agencies.

Read time: about 5 minutes. Applies to cities, towns, counties, utility districts, courts, and school districts running IT with a small staff or a part-time contractor.

Why This Isn't Just a Big-City Problem

Ransomware and basic errors, not sophisticated tradecraft, drive most breaches against local government, according to Verizon's Public Administration breach data. A part-time contractor managing a utility billing system, a court's case files, and a recreation department's registration site is a common setup for a small agency. It's also exactly the setup attackers look for. Your data isn't more valuable than a private company's. Your defenses are just thinner.

There's a newer wrinkle too, even though it doesn't touch your network directly. Since 2024, the FBI has tracked a nationwide wave of text messages impersonating toll agencies, demanding payment for a fake unpaid toll. The same template has since been adapted for fake "unpaid court fine" and "past-due utility bill" messages. Your billing and court staff are the ones who field the confused calls when residents get these texts. Tell your front-line staff, in plain terms, what your agency will and will not text someone about, and point residents to ic3.gov if they get one.

It Starts With Someone

Employees need to recognize the handful of tricks that make up most phishing attempts:

PatternWhat It Looks Like
Fake vendor payment changeA message that looks like it's from a contractor or vendor, asking to redirect an upcoming payment to a "new" bank account.
Fake request from a supervisorAn urgent message that appears to come from a department head, asking someone in finance to process a payment or share resident data quickly, often outside normal channels.
Impersonation of your own agencyScammers texting residents fake "outstanding fine" or "overdue payment" notices using your agency's name. They're not after your network. They want money or card numbers directly from residents.

What gives these away: a mismatched sender address, urgency or threats, a generic greeting, and a request to click a link or change payment information. The reliable fix isn't spotting every fake. It's verifying through a phone number or contact you already know, never one supplied in the message itself.

Passwords and Passphrases

Length matters more than complexity. A short password crammed with symbols is often easier for software to guess than a long, memorable one. For any system that touches resident data or payment information, your billing software login, your email, your payment portal's admin account, use a passphrase instead: four to seven unrelated words, at least 12 characters combined. "harbor pencil violet marathon" is stronger, and easier to remember, than "P@ssw0rd1!"

A password manager removes the guesswork. It generates a unique passphrase for every account and remembers it for you, so no one has to reuse one or write it on a sticky note. Turn on multi-factor authentication everywhere it's offered. PCI DSS 4.0.1 now requires it for anyone accessing systems that touch card data, not just remote users.

Ask your vendors this one question about passkeys. You don't need to understand how passkeys work to act on this. You just need to ask your vendors one question: "Do you support passkeys, and can you turn that on for us?" A passkey replaces a password with something tied to a person's device, their fingerprint, face, or PIN, so there's no password for a scammer to steal or trick an employee into typing on a fake site. That matters to a small agency because most successful attacks on local government start with exactly that: someone tricked into handing over a password. PCI DSS 4.0.1, the payment security standard your card processor holds you to, now recognizes passkeys as meeting its strongest security requirement. Turning this on with your payment provider, email provider, and billing software, where they offer it, is one of the few security upgrades that costs your agency nothing and closes a real hole. But only if someone asks the vendor to enable it. That's a task for whoever manages those vendor relationships, not a technical project.

What to avoid: reusing one password across accounts (a breach anywhere becomes a breach everywhere), writing passwords down at the front counter, and letting a shared password go unchanged for years just because no one is forced to change it.

Keep Software Patched

Browsers and operating systems push out security patches regularly, and most of them fix a real, documented vulnerability, not a hypothetical one. Turn on automatic updates for computers, phones, and tablets used for agency business, especially any device used to both browse the web and enter payment information. A device that goes months without an update is running with known, publicly documented holes.

Know What's Connected to Your Network

Wi-Fi-connected devices multiply quietly. Thermostats, printers, security cameras, scanners, they get forgotten for years at a time. A manufacturer's security patch does nothing if a device's firmware is never updated. The PCI Security Standards Council's core recommendations for a small merchant's network still hold:

  • Isolate the device or system you take payments with. Don't browse the web, check email, or use social media from the same computer or tablet used for payment transactions.
  • Protect your virtual terminal. If staff enter card payments through a web-based virtual terminal, don't attach an external card reader to that device.
  • Segment your Wi-Fi. If you offer free Wi-Fi to the public, keep it on a separate network from anything that touches payments.
  • Use a firewall. Ask your payment terminal vendor or IT contractor to confirm you have one and that it's configured correctly.

Outdated Terminals, Liability and Risk

If a counterfeit card is used to make a fraudulent purchase at your agency, and your card reader isn't chip-enabled, your agency pays for it. Not Visa, not Mastercard, not your bank.

Since the EMV liability shift took effect for U.S. retail terminals in October 2015, whichever party is using the less secure technology absorbs the loss. If your terminal only swipes a card's magnetic stripe instead of reading its chip, and that card turns out to be counterfeit, the loss falls on you. Before 2015, the card networks generally covered it.

That old swipe terminal at your parks and rec counter or utility payment window isn't just an IT problem to defer. It's an unbudgeted liability sitting on a folding table, one bad transaction away from a real, unplanned expense with no warning and no one else to bill.

Ask your terminal vendor two questions: does this terminal read chip cards, not just swipe them, and when did we last confirm it's still compliant? If you don't know the answer, that's the risk.

PCI DSS Now Asks for More

PCI DSS 4.0.1 became the only accepted version of the standard as of March 31, 2025. If your agency's website takes card payments, two additions matter most: Requirement 6.4.3 (inventory and authorize every script running on your payment page) and Requirement 11.6.1 (a weekly check for unauthorized changes to that page, as the resident's browser actually receives it). Requirement 8 also expanded multi-factor authentication to everyone accessing systems that touch card data. Whether 6.4.3 and 11.6.1 apply directly to your agency depends on how your payment page is built. See our companion guide, Payment Page Script Monitoring for Small Government Agencies, for the specifics.

What non-compliance can still cost, even with a Level 1 processor

A hosted Level 1 processor narrows your exposure since cardholder data never touches your systems, but it doesn't remove your obligations. You still have to file your annual SAQ A, keep basic policies in place, and confirm your processor's certification is current. Skip that, and it's your agency out of compliance, not your processor's.

PCI fines are written into your merchant agreement and enforced through the card brands, not issued like a traffic ticket. They typically run $5,000 to $100,000 per month for agencies handling their own compliance, and can climb past $500,000 after a breach involving cardholder data on the merchant's own systems, exactly the exposure a hosted payment page is built to remove.

What it can't remove: a breach of other resident data, court records, benefit applications, Social Security numbers. That's not a PCI matter. It falls under your state's breach-notification law, with its own costs.

Either way, the harder cost to reverse is trust. PCI Pal research found 83% of U.S. consumers would stop spending with a business for months after a breach, and 21% would never return. A small agency's residents don't have another utility department or court to switch to. They just stop trusting the one they have.

What a Small Agency Can Do This Month

  1. Schedule phishing training for staff. Fifteen minutes on the three patterns above, twice a year, is enough. Put it on the calendar now so it actually happens.
  2. Switch every staff account to a passphrase, stored in a password manager, and turn on multi-factor authentication wherever it's offered. This is the single highest-value change on this list.
  3. Turn on automatic updates for every device used for agency business, including phones. Most devices do this by default; someone just needs to check that it's actually on.
  4. Ask your IT contractor for a written list of what's connected to your network: computers, terminals, cameras, and who's responsible for updating each one. If no one can produce this list today, that's the problem to fix first.
  5. Call your payment provider and ask one question: "Does our setup meet the current PCI DSS 4.0.1 requirements, and is there anything we need to do on our end?" Let them walk you through the specifics. That's their job, not yours.

Where IntelliPay Fits

Everything above is true whether or not you ever talk to IntelliPay. The habits protect your agency regardless of who processes your payments. But the terminal liability, the PCI fine exposure, and the compliance paperwork we've walked through are exactly what a hosted, Level 1 processor is built to take off your plate.

IntelliPay works with cities, counties, utility districts, courts, and school districts nationwide, and our hosted payment pages, virtual terminal, and in-person solutions are built so cardholder data never touches your systems. That's what narrows your SAQ down to the short form, and what keeps the heaviest end of the fine range described above off your desk. We also don't charge junk fees, our pricing is transparent, and options like surcharging can offset your processing costs instead of quietly eating into your budget every month.

None of that replaces the basics in this guide. A hosted processor can't stop an employee from clicking a phishing link, and it won't patch your parks department's laptop. The passphrases, the patching, the phishing training protect the rest of your agency's systems, the ones that never touch a card number at all. IntelliPay handles the payment side. Everything else in this guide is still on you.

The bottom line

Phishing awareness, passphrases (or passkeys), patching, network inventory, and payment-page controls cover most of what gets small agencies into trouble.

Not sure where your agency stands on PCI DSS 4.0.1, terminal liability, or SAQ scope? Ask us. A 15-minute call with IntelliPay's compliance team will tell you exactly what applies to your setup, at no cost.

Get Your Free Compliance Check

Frequently Asked Questions

What is the single most common way small government agencies get breached?

A person, not a technical gap. Verizon's 2025 Data Breach Investigations Report attributes 60% of breaches to the human element, and flags social engineering aimed at insiders as now common specifically in public administration.

Is my small agency actually a target, or is this a big-city problem?

Small agencies get targeted precisely because the defenses are thinner, not because the data is less valuable. A part-time contractor managing utility billing, court case files, and a recreation department's registration site in one role is a typical small-agency setup. That's exactly the setup attackers look for.

What are the fake toll and court-fine text messages residents are getting?

Since 2024, the FBI has tracked a nationwide wave of text messages impersonating toll agencies, demanding payment for a fake unpaid toll. That same template has been adapted for fake "unpaid court fine" and "past-due utility bill" messages. Agencies should tell front-line staff, in plain terms, what the agency will and will not text someone about, and point residents to ic3.gov if they receive one.

What actually makes a strong password for government systems?

Length matters more than complexity. A passphrase of four to seven unrelated words, at least 12 characters combined, beats a short password crammed with symbols on both security and memorability. A password manager removes the guesswork by generating and storing a unique passphrase for every account. Where a vendor supports it, a passkey is an even stronger option since it removes the shared secret entirely.

What is a passkey and should our agency use one?

A passkey replaces a password entirely. You unlock it with your device's fingerprint, face scan, or PIN, and there's no shared secret for an attacker to steal or phish. PCI DSS 4.0.1 names passkeys directly as a qualifying method for its multi-factor authentication requirement. Support depends on what your software vendor offers, so ask your payment provider, email provider, and billing software vendor whether they support passkeys, and turn it on if they do.

Does using a PCI DSS Level 1 hosted processor remove our compliance obligations entirely?

No, it narrows them substantially but does not remove them. Agencies still need to complete an annual SAQ A, keep basic security policies in place, and confirm the processor's certification is current. The heaviest PCI fines, and the ones tied to a breach of stored cardholder data, are largely what a hosted payment page is built to keep off the agency's own systems. A breach of other resident data that never touched a card number is a separate matter governed by state breach-notification law, not PCI DSS.

What does PCI DSS 4.0.1 require that the older standard didn't?

PCI DSS 4.0.1 became the only accepted version as of March 31, 2025. For agencies taking card payments online, the two additions that matter most are Requirement 6.4.3, which requires inventorying and authorizing every script running on a payment page, and Requirement 11.6.1, which requires a weekly check for unauthorized changes to that page as the resident's browser actually receives it. Requirement 8 also expanded multi-factor authentication to everyone accessing systems that touch card data, not just remote users.

How likely is my agency to actually get fined for PCI non-compliance?

Less likely than the headline numbers suggest, and the risk isn't evenly distributed. Card brands don't fine merchants directly. They fine the acquiring bank or processor, who decides whether and how much to pass down, so real-world penalties vary widely and are often far smaller than the $5,000 to $100,000 per month figure commonly cited. That range represents the outer ceiling for sustained non-compliance or a large merchant, not a typical bill. The realistic risk for most small agencies is more mundane: letting the annual SAQ lapse, or not being able to answer basic questions about your setup if your processor asks. The risk that actually matters is a data breach itself, not a routine compliance fine, and that's the scenario a Level 1 hosted processor is built to make far less likely in the first place.

Who in our agency is actually responsible for PCI compliance if we don't have a dedicated IT department?

In practice, nobody, until someone claims it. PCI compliance responsibility doesn't come with a job title. It defaults to whoever signed the merchant services agreement, usually the finance director, treasurer, or city clerk, but signing that agreement and actually knowing what it requires are two different things. The fix is naming the role in writing, even as a part-time responsibility layered onto someone's existing job, and documenting a backup person in case that individual leaves.

Is PCI compliance a capital expense or an operating expense for budgeting purposes?

Mostly operating, with one common exception. Staff time, password manager subscriptions, security awareness training, and your processor's fees are all recurring operating costs. The exception is hardware: replacing outdated card terminals or upgrading network equipment specifically to meet compliance requirements may cross your agency's capitalization threshold and need to go through your capital budget or CIP process instead.

What should we get in writing before signing with a new payment processor?

Four things, minimum: which PCI compliance model applies to your agency under that processor's setup, which SAQ type you'll be responsible for filing, whether the processor's hosted page or terminal keeps you out of scope for Requirements 6.4.3 and 11.6.1, and a current copy of the processor's own Attestation of Compliance. Ask for all four before you sign, not after, and put the request in writing.

Do we need to budget for PCI compliance every year, or is it a one-time cost?

Every year. The annual SAQ isn't a one-time filing, it's a yearly requirement for as long as you accept card payments, and most of the real costs, password manager subscriptions, staff training, MFA licensing where it isn't free, are recurring by nature. Treat PCI compliance the same way you'd treat insurance or an annual software renewal: a fixed line in your operating budget, not a project that gets finished once and forgotten.

Is my agency liable for fraudulent transactions on an outdated card terminal?

Yes, in the specific case of counterfeit card fraud. Since the EMV liability shift took effect for U.S. retail terminals in October 2015, whichever party is using the less secure technology absorbs the loss. If a terminal only swipes a card's magnetic stripe instead of reading its chip, and that card turns out to be counterfeit, the loss falls on the merchant, in this case, the agency, rather than the card networks. Before 2015, the card networks generally covered that loss.

What can a small agency realistically do this month?

Schedule phishing training on the three common patterns, twice a year, fifteen minutes each time. Switch every staff account to a passphrase in a password manager and turn on multi-factor authentication wherever it's offered. Confirm automatic updates are turned on for every device used for agency business, phones included. Ask your IT contractor for a written list of what's connected to the network and who updates each device. And call your payment provider to ask whether your setup meets the current PCI DSS 4.0.1 requirements and what, if anything, you need to do on your end.

Sources

Disclaimer: This article is for general educational purposes only and does not constitute legal, cybersecurity, or compliance advice. PCI DSS scope, SAQ eligibility, and validation requirements depend on your agency's payment environment, acquirer, service providers, and card brand program. Your acquirer, payment facilitator, payment provider, or other compliance-enforcing entity determines the applicable validation approach. PCI DSS compliance is not a guarantee of security. Consult that entity, a Qualified Security Assessor, legal counsel, or another qualified advisor about your agency's obligations. Last reviewed: September 2026.

author avatar
Dale Erling
Dale Erling is a veteran fintech leader with over 15 years of experience in banking and payment processing. Specializing in PCI compliance and interchange cost reduction, Dale helps organizations navigate complex financial landscapes with transparency and security. He is a recognized voice in utility fee architecture and a former strategist for Prosper Healthcare Lending.