How Technology, Collaboration and Public-Private Partnerships Are Transforming Urban Security

Cities are moving beyond connected infrastructure toward predictive resilience—but AI, public-private data sharing and ubiquitous sensors will only make communities safer when cybersecurity, governance and public trust are built in from the start.

When Maria Sumnicht arrived at the newly formed New York City Cyber Command in 2018, she inherited a problem nobody could fully describe. City agencies, more than 60 of them, had spent years connecting sensors, cameras, transponders, and access points to municipal networks with little coordination and less oversight. Nobody knew how many devices were out there. Nobody knew who had installed them, whether they were still supported, or whether they had ever been tested for basic security flaws.

"It was the wild, wild west," Sumnicht said. "Everyone was just bringing in whatever they needed, putting it on their networks, and really not thinking about the cyber hygiene behind the solution."

What Sumnicht and her team built from that starting point, a proactive endpoint security program that would go on to uncover 159 previously unknown vulnerabilities, offers a blueprint for how American cities are rethinking what it means to be smart. The lesson isn't just about better sensors or faster analytics. It's about resilience, and about who cities trust to help build it.

From Connected to Resilient

For most of the past decade, the smart city conversation centered on connectivity and efficiency: traffic sensors, digital kiosks, cashless parking. That conversation has shifted. Cities today are contending with violent crime, cyberattacks on critical infrastructure, severe weather, civil unrest and geopolitical instability, often at the same time. Technology alone can't solve that. What's emerging instead is a model some in the industry call Safe Cities 2.0, where public agencies, private security leaders, utilities, transportation authorities and technology providers share data and coordinate response rather than operating in isolation.

The trajectory is fairly clear: Smart City 1.0 was about efficiency and automation. Smart City 2.0, where most major cities sit today, is about integrated safety, unified platforms and AI-assisted operations. Smart City 3.0, still emerging, points toward predictive resilience, where AI agents, digital twins and autonomous systems help cities anticipate disruption before it happens rather than simply respond to it.

Public-private partnerships for security, or P3S, sit at the center of that shift. No single city agency owns all the relevant data or expertise anymore. Utilities, telecom providers, hospitals, universities and commercial real estate operators increasingly hold pieces of the picture, and the cities making the most progress are the ones that have found ways to share it.

A Blueprint Born from a Blank Slate

Sumnicht's team at NYC Cyber Command, then a brand-new agency with fewer than 50 employees, was tasked with proactively securing the Internet of Things (IoT) before it ever connected to a city network. She built the effort around four pillars: legal, policy and standards, procurement and metrics.

 

Legal came first. Sumnicht worked with the city's technology attorneys to fold IoT and industrial control systems into New York's existing licensing agreements, and to require that any critical, high or medium vulnerability be remediated before a device could be deployed, with payment withheld from vendors who refused. On the policy side, her team developed threat models, reference architectures and hardening guidance that vendors could be measured against before a contract was ever signed.

Procurement closed the loop. By working with the city's Office of Management and Budget, Sumnicht's group ensured that every new IoT purchase and every license renewal or upgrade of existing technology automatically triggered a cybersecurity review. The city's Department of Transportation, New York's second-largest transportation agency in the country, went a step further by incorporating Cyber Command's requirements directly into its RFP and RFI processes.

"When you can write cybersecurity into the RFP RFI process, many of the bottom IoT manufacturers will drop off because they can't meet the requirements," Sumnicht said. "What you're going to wind up with is sound companies bidding for these contracts."

The results, tracked through the fourth pillar metrics, were striking. Between 2019 and 2022, the team ran 67 full-stack penetration tests, tearing devices down to the board- and chipset-level rather than simply scanning for known flaws, and found 159 zero-day vulnerabilities across routers, GPS transponders, police radios, body-worn cameras, traffic controllers and parking meters. The program was funded largely through a little-known Department of Homeland Security grant called the Urban Area Security Initiative, which Sumnicht said municipalities still underuse to this day.

"If it can be implemented in NYC, it can be implemented in any American city," she wrote in a white paper detailing the program.

AI Becomes the City's Intelligence Layer

If the last several years were about connecting sensors, the next phase is about making sense of what they collect. Interest in AI among physical security leaders more than doubled between 2025 and 2026, from 21% to 45%, according to the Security Industry Association's 2026 Security Megatrends report. Nearly nine in 10 public safety professionals surveyed said integrated security data helps keep officers safer, and 81% said it improves real-time situational awareness.

Some of the clearest examples of this shift are also the least glamorous. Paul Benne, founder and CEO of Sentinel Consulting in New York City, points to municipal code enforcement, where AI-equipped cameras mounted on routine trash trucks now flag potential violations as they pass every residence in a city each week.

"All of this automation now allows a code enforcement agency to police a very large geographic area with a very low amount of effort," Benne said.

Other cities are applying similar principles to infrastructure. Tucson's water department uses AI software to analyze more than 4,600 miles of pipe, assigning risk scores based on patterns from past failures so crews can prioritize repairs before a line breaks rather than after. Warner Robins, Georgia, has built a digital twin that pairs AI-driven crime data analysis with camera placement and gunshot detection, allowing dispatchers to begin responding before a 911 call comes in.

For most of the past decade, the smart city conversation centered on connectivity and efficiency: traffic sensors, digital kiosks, cashless parking. That conversation has shifted. Cities today are contending with violent crime, cyberattacks on critical infrastructure, severe weather, civil unrest and geopolitical instability, often at the same time.

The pattern across these examples is consistent. AI isn't replacing human judgment so much as compressing the time between a problem occurring and a city knowing about it.

Where the Partnerships Are Actually Built

Public-private partnerships are frequently discussed in the abstract. In practice, they run on paperwork and on trust that has to be negotiated in advance.

New York's Lower Manhattan Security Initiative, a joint effort between the NYPD and private building owners, is one of the longer-running examples. Under a memorandum of understanding, participating buildings grant police access to their cameras for rapid-response investigations, but the boundaries of that access are carefully drawn.

"Most of the time, private parties are going to agree to give the police access to a camera that watches the street in front of the building," Benne said. "What they're concerned about is giving access to the lobby, or a stairwell. Typically, the limitation on that public-private partnership happens at the building line. It doesn't come into the building. It stays on the exterior."

The payoff shows up in dispatch. When someone calls 911 to report a shooting, the city's computer-aided dispatch system can pull the nearest camera feeds and roll them back 15 to 20 seconds, roughly the time between an incident and the call reporting it. Dispatchers can then watch events unfold in near real time and relay details to responding officers before they arrive.

That kind of coordination is exactly what industry guidelines mean when they call for unified command-and-control centers, security operations centers, or real-time crime centers. New York's dispatch model functions as an informal RTCC: a common operating picture, built from private camera feeds and public dispatch data, that didn't require a single new building or a massive capital outlay. It's a reminder that the "command center of the future" isn't necessarily a room full of monitors. Increasingly, it's a data-sharing agreement.

That kind of integration doesn't happen without sustained investment. Market forecasts cited in industry research put the global smart-city economy somewhere between $700 billion and $2.25 trillion today, with projections exceeding $1.4 trillion by 2030 and potentially reaching $8 trillion or more by the early 2030s. The fastest growth isn't in standalone devices. It's in platforms that integrate transportation, utilities, emergency management and public safety data into a single operating picture, exactly the kind of infrastructure that P3S agreements make possible.

Governance Hasn't Caught Up

Both Sumnicht and Benne, working from very different vantage points, independently arrived at the same warning: the technology is moving faster than the legal and regulatory frameworks meant to govern it.

Benne compares the current moment in smart cities to what happened with airport drone detection. Airports, as regulated entities, often held off adopting the technology, only for the FAA to introduce new rules years later, after other operators had already invested millions in systems that didn't meet the emerging standard. Cities, by contrast, face far less regulatory friction today, which Benne argues is setting up a similar reckoning later.

"Right now, most of the guardrails are off, and a lot of the technologies that are being used really without regulation," Benne said. "I think that's going to change, but it probably will change too late. A lot of this stuff is going to be out there and operational."

The patchwork nature of current privacy law compounds the problem. Some states, including California and Illinois, have enacted their own biometric and data privacy protections. There is no comparable federal standard in the U.S., unlike the European Union's GDPR framework. Sumnicht raised a related concern after returning from a law enforcement technology conference this fall: many of the same IoT vendors who never built cybersecurity hygiene into their original products are now bolting AI onto those devices, potentially opening new attack vectors.

None of this works without public buy-in. Cities that treat transparency as an afterthought risk losing residents' trust, even when the underlying technology performs exactly as intended, particularly regarding facial recognition, data retention, and who ultimately has access to footage collected from private property. Cities that get this right tend to publish plain-language explanations of what they're collecting and why, and build in a public feedback channel before deployment rather than after a controversy forces one.

Sumnicht ran into this tension directly in New York. One city agency wanted to deploy temperature sensors in Central Park to monitor horses used for mounted patrols and carriage rides, making sure the animals weren't overheating. On its face, the request was straightforward. But Cyber Command's review didn't stop at the stated purpose.

Market forecasts cited in industry research put the global smart-city economy somewhere between $700 billion and $2.25 trillion today, with projections exceeding $1.4 trillion by 2030 and potentially reaching $8 trillion or more by the early 2030s.

"Our concern was also that they were not doing this to the general public, and monitoring persons and their temperatures," Sumnicht said. "This became an extreme issue with personal information, right, during COVID."

The sensors were approved, but only after her team confirmed the technology was scoped narrowly enough that it couldn't be repurposed, intentionally or not, to track people. It's a small example, but it illustrates a habit worth building into any city's review process: asking not just whether a technology works as advertised, but what else it can do once it's on the network.

Benne has written about this exact tension in his own work. License plate recognition, once confined to patrol cars and toll booths, has expanded into retail centers, gated communities and logistics hubs, generating structured, searchable records tied to identifiable vehicles and, by extension, the people who drive them. Unlike a security camera's raw video feed, that data can be queried, cross-referenced and retained indefinitely if a city or vendor doesn't define limits up front.

"Clients must define retention policies, access controls and audit logging procedures," Benne said, stressing that integrators are increasingly expected to guide clients toward sound data governance even when it falls outside their traditional scope of work.

Federal guidance does exist to help close that gap. A joint advisory from CISA, the NSA, the FBI and international cybersecurity partners recommends that cities implement zero-trust architecture, apply the principle of least privilege across networks, and require secure-by-design practices from vendors before technology is ever deployed, essentially the same proactive posture Sumnicht's team built in New York years earlier.

The Takeaway

The safe city of the next decade won't be defined by how many sensors it has deployed. It will be defined by how well those sensors, the agencies that manage them and the private partners that help operate them work together, and by how much of that work happens before an incident occurs rather than after.

The pattern holds across every source consulted for this piece. Sumnicht built her program on four unglamorous pillars: legal, policy, procurement and metrics. Benne's clients rely on the same basic discipline: formal agreements that spell out exactly what data changes hands and where the boundaries sit, long before a camera or sensor goes live. And the market data tells a consistent story too: the cities and companies seeing the strongest returns aren't the ones chasing the newest technology. They're the ones treating governance, funding, and public trust as core infrastructure rather than afterthoughts bolted on only after something goes wrong.

That discipline matters more now, not less. AI is accelerating what cities can detect and predict, but it's also raising the stakes on every gap in oversight, funding and public communication that a city leaves unaddressed. The smart cities that thrive over the next decade won't be the ones with the most sensors or the most advanced algorithms. They'll be the ones that treated security, transparency and collaboration as the foundation, not an add-on, from the very beginning.

 

About the Author

Howard Carder

Howard Carder

freelance writer specializing in the physical security and professional audio/video industries

Howard Carder is a seasoned freelance writer specializing in the physical security and professional audio/video industries. With over 30 years of experience, including a long tenure at a large, global video security company, Howard has crafted compelling content for leading brands and publications across the industry. His expertise spans video security and Pro AV technologies, allowing him to distill complex topics into engaging narratives. Howard's work includes hundreds of case studies, white papers, and thought leadership articles. When not writing, he enjoys playing music and exploring healthy cooking. Learn more at www.hcwriter.com.

Sign up for our eNewsletters
Get the latest news and updates