The increasing digitalization of local government services in South Africa has led the country to experience a series of significant cyber-attacks. This study examines South African local government’s preparedness for addressing cybersecurity risks. Qualitative data was collected from participants who work in the South African local municipalities in their capacity as IT practitioners, Financial Officers and Municipal Managers. Findings show that cybersecurity preparedness from the technical front was constrained by the current use of legacy and obsolete systems, limited connectivity and infrastructure, and from the organizational front, workforce deficit, financial constraints, weak security culture and the lack of effective governance, particularly management support in prioritising cybersecurity. These constraints should be understood in the realm of the external pressures of compliance reporting and external regulation. Compliance reporting as an external pressure forced municipalities into a compliance-driven approach towards cybersecurity, where action is initiated only when mandated by external authorities.