AI & AUTOMATION MASTER CLASS WORKSHOP
 JUL 23 | AUG 13 | AUG 27
Municipal Government It Support

24x7 Connection Safeguards Citizens and Keeps Government Running

eMazzanti

How Does a New Jersey Township Protect 35,000 Citizens and Critical Police Infrastructure on a Government Budget?

"eMazzanti is my backup, my sixth man. When push comes to shove, with their expertise I know I can make everything work. I can't think of anyone else I would go to!" — Joe Varalli, IT Manager, Monroe Township, New Jersey

Monroe Township, New Jersey faces a challenge common to local governments everywhere: protecting 35,000 citizens and critical public safety infrastructure with limited budget flexibility and no room for downtime. When Gloucester County transferred responsibility for connecting the township's police headquarters to the county dispatch system, IT Manager Joe Varalli needed a high-availability, secure solution quickly — and affordably. For local government agencies, municipalities, and public safety organizations across New Jersey seeking enterprise-grade security within government budget constraints, eMazzanti Technologies provides the WatchGuard firewall implementations, managed security services, and specialized support that keep public infrastructure secure and operational.

What Network Security Challenge Did Monroe Township Need to Solve?

The township's challenge crystallized when the county communications department, which had managed point-to-point connections with its municipalities, decided to shift those to VPN connections and transfer management responsibility to local IT departments.

For Varalli, this meant supplying a fully available, 24×7 internet and VPN connection for the chief of police, administrative staff, and the police department. Each police desktop needed to connect with portions of the police system still maintained by the county — specifically the dispatch system and laptops in patrol cars. A communications failure in a police environment is not an operational inconvenience; it is a public safety crisis.

The connectivity challenge coincided with other long-overdue upgrades. "I had a Symantec server for antivirus, and we were getting too much spam and multiple complaints," Varalli explained. "It was time for a new firewall, and I needed to do it within budget." The scope of Varalli's responsibility extended beyond the police department to include township administration, two fire departments across three buildings, public works, and the ambulance hall — all of which funneled back to approximately a dozen servers at town hall.

How Did eMazzanti Design a Cost-Effective Solution for Police and Government Security?

Varalli brought in eMazzanti early in the planning process. The firm developed a cost-effective architecture centered on the WatchGuard Firebox X Core 750e — a Unified Threat Management device that addressed multiple requirements simultaneously.

The solution augmented the existing T1 connection with a Comcast business network line for redundancy, routed through the WatchGuard firewall for security and automatic failover. The configuration included failover connections, back-office VPN for the police department's connection to the county dispatch system, and comprehensive border security. Traffic ran through WatchGuard's UTM bundle incorporating spamBlocker, WebBlocker, Gateway AntiVirus, and Intrusion Prevention Service.

The result protected the entire township government through a single, centrally managed security platform. Point-to-point connections extending to the fire departments, public works, and ambulance hall all funneled through the WatchGuard firewall at town hall.

"The move to bring in the eMazzanti team and WatchGuard was fantastic," stated Varalli. "It encompassed not only the security, but a lot of needed changes I had identified over the last three years. Things have improved 1,000 percent. And as for meeting the budget requirements, the CFO will attest to it."

What Operational Improvements Did the WatchGuard Implementation Deliver?

The security upgrade translated into concrete operational improvements that affected daily work across the entire township government.

Restored Local Control:

Before the WatchGuard implementation, web-blocking was managed by the county, meaning that every time any township employee needed to access a blocked site for legitimate purposes, the request took days or weeks to process. The WatchGuard unit returned that control to Varalli. "If there's anything I don't know how to do, I give the eMazzanti support people a call and it's done. They've been so accommodating, and I've never had an issue."

Varalli accesses that support through eMazzanti's eCare services — a fixed-fee arrangement that keeps costs predictable within the township's budget, providing support, remote management, central logging and reporting, and proactive 24×7 monitoring.

An End to System Rebuilds:

The virus protection impact was immediate. "I was rebuilding systems on a regular basis," explained Varalli. "Somebody was always blowing something up with some email virus. Now, the Gateway AntiVirus strips the attachment right out. And having WatchGuard reduced the spam load, too. That's reduced the time lost for employees, and the money and time spent rebooting and rebuilding systems. The complaints have dropped way down. I don't even have to worry about it anymore."

How Has the eMazzanti Partnership Evolved to Address New Threats?

The relationship between Monroe Township and eMazzanti has grown significantly since the initial WatchGuard implementation — adapting to new state requirements and evolving security threats.

2020: Police Department Exchange Migration:

When New Jersey state directives required separating the police department's email infrastructure, Varalli called on eMazzanti's Messaging Architects division. The project required extracting 75 police officers from the existing Exchange server and establishing a separate domain on the police network — a complex migration with significant operational dependencies.

"They had always done a good job for me, so I called eMazzanti," he related. "They did the extraction and set up a separate domain on the Police network. I couldn't have done it without them." eMazzanti also migrated the department from Exchange 2013 to 2019 and configured the domain controller. "eMazzanti was there with the planning from the jump. They made the job seamless without a problem. It works beautifully!"

Blocking Foreign Security Threats:

Shortly after the email migration, Varalli received an FBI report indicating that servers on the internal network had been compromised. He scanned 33 servers, identifying two RDP-related viruses, then engaged eMazzanti's CISO.

"Almi did a great job for me. He set up a geo-location in the firewall that blocked every IP worldwide except Great Britain and Canada. Once we did that, it prevented four different access attempts from Czechoslovakia and Russia." The police domain was also added to eMazzanti's MXInspect email filtering for protection against viruses and spam.

"When push comes to shove and I need that expertise, they've been there for me. I have confidence in eMazzanti and the people that do the job. That means everything to me!"

A Relationship Built on Trust:

The depth of the relationship goes beyond technical capability to the qualities that matter most in a long-term government IT partnership. "In our field, it's relationship building. I always get honest answers from Carl and his people. I feel way more secure having someone in my back court. If I'm not available, I say call eMazzanti and they'll take care of it."

When asked what he would tell another township, Varalli's response was unequivocal: "It's a no brainer. You should definitely go with them. In fact, I just recommended eMazzanti to a South Jersey township. I told them I couldn't do it without them — setting up the email, doing the migration, the firewall support, and spam filter. That's my life blood. They keep me going."

For local government agencies facing the challenge of protecting critical public safety infrastructure and citizen data within constrained government budgets, organizations like eMazzanti Technologies bring the security expertise, managed services infrastructure, and long-term partnership approach that public sector IT requires.


FAQ: IT Security and Managed Services for Local Government

Q: What are the most critical IT security requirements for local government and municipal networks?

A: Local government networks face security requirements that combine the sensitivity of public sector data with the critical nature of public safety infrastructure. Essential controls include network segmentation that isolates police and emergency services systems from general government networks, high-availability internet connections with automatic failover to prevent public safety communication disruptions, unified threat management combining firewall, intrusion prevention, antivirus, and web filtering, VPN infrastructure for secure connections to county and state systems, email security to protect against phishing and business email compromise targeting government employees, and centralized logging and monitoring to meet public records requirements and detect threats proactively. Government networks are frequent targets for nation-state actors and ransomware groups — geographic IP blocking has proven effective at reducing attack surface from known high-threat regions.

Q: How does eCare managed security differ from break-fix IT support for government agencies?

A: Government agencies face specific challenges with break-fix IT support: budget unpredictability, lengthy procurement processes for emergency services, and the operational reality that public safety systems cannot wait for standard support timelines. eCare managed security provides fixed-fee, proactive monitoring and support that addresses all three challenges simultaneously. The fixed fee converts variable security costs to predictable budget line items — essential for government fiscal planning. Proactive monitoring identifies threats before they cause disruptions, reducing the emergency situations that force costly expedited responses. Established vendor relationships mean that when issues do arise, the support team already knows the environment and can act immediately rather than spending time on discovery. For IT managers responsible for both police and general government infrastructure, proactive management reduces the reactive burden that prevents strategic improvements.

Q: What should government IT managers do when they receive an FBI notification about network compromise?

A: An FBI compromise notification should trigger immediate, systematic response. First, scan all systems for indicators of compromise — the FBI notification will typically include specific indicators to search for. Isolate affected systems from the network to prevent lateral movement while maintaining critical operational systems. Engage cybersecurity expertise immediately — government IT managers are generally not incident response specialists, and time-critical decisions about evidence preservation, system isolation scope, and remediation sequencing require specialized knowledge. Implement additional detective controls (enhanced logging, network monitoring) to identify ongoing attacker activity. Coordinate with relevant government agencies — state cybersecurity agencies and law enforcement have specific notification requirements and may provide assistance. Document all actions taken for legal and regulatory purposes. After containment, conduct a thorough root cause analysis to understand the initial access vector and address it before returning systems to operation.

Q: How can small government agencies like townships justify enterprise-grade security investment?

A: The business case for enterprise-grade security in government agencies rests on several foundations. Public safety consequences: municipalities that operate police dispatch, emergency communications, and payroll systems cannot afford the operational disruptions that inadequate security enables. Regulatory exposure: government agencies face specific legal and regulatory obligations around data protection for law enforcement records, personnel data, and citizen information — non-compliance creates liability. Ransomware risk: local governments have become frequent ransomware targets precisely because their operational dependencies create pressure to pay and their security investments have historically lagged. Cost comparison: the cost of a ransomware incident — recovery, potential payment, reputational damage, and lost operational time — routinely exceeds years of managed security service fees. Nonprofit and government pricing from security vendors and managed service providers typically makes enterprise-grade security accessible within government budget constraints when procured through appropriate channels.

Q: What is geographic IP blocking and when is it appropriate for network security?

A: Geographic IP blocking (geo-blocking) configures firewall rules to deny network access from internet addresses associated with specific countries or regions. It is most appropriate when an organization has no legitimate business reason to accept connections from certain regions and faces known threat actors operating from those regions. For local government agencies in the United States that do not conduct international operations, blocking connection attempts from high-threat regions — while maintaining access from the US, UK, Canada, and other countries with legitimate reasons to connect — reduces attack surface substantially without meaningful operational impact. As Varalli's experience demonstrated, implementing geo-blocking on a compromised network immediately stopped active attack attempts from identified threat countries. Geo-blocking is not a complete security solution — sophisticated attackers route through proxies — but it eliminates opportunistic attacks from high-threat regions that represent a significant proportion of total attack volume.