From MSSP to MCOP, Part 2: The Aurora Story
with Michael Pegues, former CIO, City of Aurora
How the City of Aurora, Illinois moved from alert-driven support to continuous cybersecurity operations under the MCOP model — and what it saved.
The second part looks at the MCOP model in practice at the City of Aurora, Illinois, the state’s second-largest city. Michael Pegues describes what the partnership with Data Defenders changed — the city kept accountability while the heavy lift moved off its staff — and the savings, risk reduction and public trust that followed. Cyrus Walker explains why the government cybersecurity workforce has become a revolving door and how an MCOP provides staffing stability, and the two discuss how the same model scales down to smaller villages and townships.
Welcome to part two. In this segment, we move from the big picture MCOP model to what it looks like when it's actually deployed. You'll hear how Aurora, Illinois, the second largest city in the state, shifted from alert-driven MSSP support to true continuous operations, from governance and compliance to 24 by7 threat response and public trust. This part breaks down the real operational lift an MCOP model creates for a city's critical services. So, let's step into the Aurora story.
Now, Mike, you've had firstirhand experience working with an MCOP provider, Data Defenders, during your time as CIO for the city of Aurora, Illinois. Can you walk us through what that partnership looked like in practice and what kind of operational lift it created for your team? Well, I mean that was one of the benefits as well that that lift it didn't go away in terms of the accountability that the city maintained, but it took the heavy lift off the staff trying to develop something from scratch. Right. I know Cyrus talked about the key difference.
I totally agree that that MSSP is more like bringing in an outsource security operation team in a proactive manner to monitor, detect and respond where that MCOP is more of that broader cyber security partner that helped us to build frameworks, governance, compliance and operational maturity. I used to like to think of it as that MSSP is like hiring a security guard service to watch the city of Aurora 24 by7. The MCOP with Data Defenders provided is like hiring a chief security officer and their team to help design the security program, help train staff, to set policies also to basically to run the guards to make sure that that threat vector is minimized as much as possible. Right? So those benefits actually ended up showing in terms of stronger cyber resilience, reducing that risk around ransomware or fishing or any type of data breaches or compromise.
You know, you talked a little bit about the cost effectiveness piece and that was huge because even at the time, and I might even get this number wrong, when we implemented that capability at city, I could say at a minimum yearly, we saved about $5 million was probably that total cost of savings at least in the first year. It probably was more than that. Not probably. It definitely was more than that through year one, two, three and on as we move forward because obviously the cost goes up when you start to look at enterprisegrade capabilities and that's just not the capabilities that's the talent that's the tools right so you know you kind of remove in a sense that cost of hiring and especially in government it's almost next to impossible to hire industrywide cyber security talent in a government because the budgets are not there within government to pay for those, right? So, you know, bringing that model in, that subscriptionbased model helped us do a lot of like budget planning, but at the same time reduce the risk and protect our critical assets and services in the city.
Whether it's 911 dispatch, whether it was utilities, the water treatment plant, whether it's our permitting, payroll, public safety systems, right? It helped to ensure that continuity of services and also and and also more importantly, it helped us to gain public trust and maintain a solid reputation within the city of Aurora. Yeah. Well, I think one one thing to note when you talk about the the staffing aspect of it, uh just in this country alone, there's a shortage of about 500,000 skilled cyber security professionals around the world, that's in the millions. And imagine a a highly soughtafter cyber security professional or even an entry- level person looking for a job. they they in some cases look to the government for that initial opportunity, but once they get that training, they then leave for higher paying roles in the private sector uh or at the federal level.
And and so what that did was it created a a a revolving door of talent uh out of in and out of the the government sector which which totally destroyed any potential for continuity, any potential for maintaining and growing a cyber security operation. That basically when you had that talent leave, you had to start back at square one trying to find the the talent to replace what you lost. And so what an MCOP model does or vendor does is they bring all that staff and they create that stability right right off the bat. So you don't have to worry about the instability in in the staffing in the workforce and and depending on the type of MCOP that's brought in like for instance us Data Defenders a lot of that information is captured in our DataShield Analytics tool which allows for that continuity of knowledge and information uh that uh anybody can then plug into in order to get a sense of the the historical context to get a sense of where the organization is at the at the current moment in time uh and to help to get their arms around how the organization is functioning from a cyber security perspective. So there there is a a great benefit from working with uh an MCOP vendor like Data Defenders because we we we address those seven challenges that we've identified uh in the municipal space you know related to cost related to workforce related to relying on the human element to to deal with all that information that's being generated on a daily basis.
There's there's major benefits there that outweigh any MSSP or build it on your own kind of scenario. Yeah. And the results of the MCOP model speak for themselves. I'm pulling these numbers from the Aurora case study which at the time, Mike, you were the current CIO. 35, 331 threats detected, 351 high severity attacks blocked, and zero major incidents. even to this day, zero major incidents, which is quite an accomplishment. Um, so from looking at the survey from our SLTT leaders, most are within small municipalities.
They're not as large as the city of Aurora, which is the second largest city in the state of Illinois. So, Mike, as president of Aurora Dynamic Solution, can you speak to how effectively the MCOP model will work for all sizes of municipalities, especially the smaller municipalities? Well, absolutely because you're talking about scale and also as I mentioned earlier, it's typically the midsize or the metropolitan size cities that have say more robust or mature cyber security capability. Now, if the MCOP capability is already built and it's already scaled to manage a city like the city of Chicago or Cook County to bring in a smaller village, right, that's under say maybe 200,000 or 150,000 or even 100,000 population is simple, right? The capabilities are there. the impact to the MCOP is I would say smaller or more minute than trying to just set it up from scratch.
So you know this particular framework or model is basically built that way to actually what's the word I'm looking for? It's basically to look at it as almost like a shared service model where if you set something up more in a you set it up like city of Aurora in a regional framework. If you have the surrounding suburbs or villages or townships, it's easy to get them on board. It's typically not a challenge to onboard those from an MCOP perspective. The challenge is more around budget and bureaucracy at the government level.
Right. I think that's the challenge in terms of the procurement aspect uh and budget uh bringing those uh smaller villages or townships or cities on. It's a scalable partnership right you know that adapts to you know city sizes or needs whether it's a small municipality or a large metro. So you know and it basically the MCOP provides that flexibility to expand those services as the city adopts new technology because that's what we did at the city of Aurora. First it was really focused just on the enterprise but then we also expanded that to focus on the water treatment plant.
We started to looking at the IoT space that segmented network right and infrastructure or cloud or whatever it may be. That wraps up part two where we saw how the MCOP model moved Aurora from building everything alone to partnering for continuous operations, stabilizing staff, reducing risk, and protecting critical services like 911, water, and public safety. But Aurora is just the starting point. In part three, we step up to the regional level and unpack how the same model evolves into a regional security operations center or RSOC, a shared utility where municipalities pull costs, share threat intelligence, and strengthen each other's defenses in real time. Tune in to part three to hear how the RSOC utility turns one city's success into regional resilience.
Key takeaways
- An MSSP is like hiring a security guard service. An MCOP is like hiring a chief security officer and their team to design the program, train staff, set policy and run the guards.
- Aurora saved at least $5 million in the first year after adopting the MCOP model, with savings continuing in the years after.
- The Aurora case study reports 35,331 threats detected, 351 high-severity attacks blocked, and zero major incidents.
- Governments train cybersecurity staff who then leave for better-paid private-sector or federal roles. An MCOP brings its own staff, which ends that revolving door and keeps institutional knowledge in place.
- Once an MCOP is built for a large city, adding a smaller village is simple. The real obstacles are budget, procurement and bureaucracy, not the technology.