Current Work
I am following Town information-technology and cybersecurity practices after the recent cyberattack, with attention to recovery, written policies, backups, access controls, continuity planning, and steps needed to reduce future risk.
Scope / Key Items
- Review backup, restoration, and continuity practices for critical municipal systems.
- Review written IT and cybersecurity policies, user access, account controls, and administrative responsibilities.
- Assess incident-response procedures and documentation.
- Identify dependencies on vendors and systems that could interrupt public services if unavailable.
- Include an independent IT and cybersecurity assessment within the broader third-party governance review where appropriate.
Why It Matters
Municipal systems support public safety, finance, records, and everyday Town services. Strong recovery procedures and documented security practices reduce operational risk and help protect public information and essential services.
Latest Update
The proposed independent governance review now includes assessment of IT policies and cybersecurity practices as a specific area of work.
Next Step
Continue documenting the Town’s current policies and recovery status and identify the areas that should receive independent technical assessment.