The recent Granicus govService security advisory – what you can do to ensure you are protected

On Friday 5th June, the MHCLG sent out a notice to authorities regarding a security advisory identified on the Granicus govService platform.

The main issue surrounding this security advisory is due to the way councils have configured their platform. We periodically monitor these types of mis-configurations for our clients to ensure they are not at risk.

In the interest of protecting the specific details of the advisory and the steps we are advising our clients to take (along with the wider public sector), this article does not detail what you must do.

However, our nonprofit member only forum the Government Developers Association (GDA) has information available to councils who use the Granicus govService platform on what they can do to ensure they are secure.

It is free to join (and always will be), which you can do so at https://digitalgov.org/join/ – our team is actively processing requests as a priority to ensure you can access this vital information.

Our security reviews – how we can help

If you are concerned you may be affected in other ways, Optima can help. The recent vulnerability is not the only way you may be exposed to attacks and leaked credentials on the Granicus govService platform.

There are ways that solutions created on the Granicus govService platforms can accidentally expose API credentials, alongside incorrect platform configuration. At Optima, we know the correct way you can secure your data and build low-code solutions securely on the Granicus govService platform.