Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
County IT director warns of rising ransomware and outlines defenses; supervisors question use of county email
Summary
Polk County’s IT director warned the Board of Supervisors on Sept. 16 that ransomware and phishing attacks targeting government entities have risen sharply and outlined layered security measures the county uses to reduce risk.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Scott Goode, Polk County IT director, told the board Sept. 16 that government-targeted ransomware and phishing attacks have risen sharply and described the county’s security posture, training and incident-response measures.
Goode said Polk County recorded roughly 788 advanced malware detections and identified about 7,000 phishing and business-email-compromise attempts the previous six months; he also reported the county received about 1.2 million incoming emails over the same interval and delivered roughly 579,000 after filtering. ‘‘All it does take is one,’’ he warned, noting most breaches begin with a human clicking a link.
Goode summarized the county’s layered defenses: information-security policy and annual risk assessments (including third-party and Center for Internet Security reviews), CJIS audits, monthly security-awareness training and phishing simulations, least-privilege access controls, multifactor authentication (MFA), encryption of data at rest and in transit, a contracted 24/7 security operations center (managed detection and response), logging and monitoring, tabletop incident-response testing, and vendor security reviews for third parties that handle Polk County data. He said the county had a ‘‘close call’’ in April that was determined not to be a breach after a coordinated response with the county’s insurer.
Several supervisors asked about the county email accounts that are issued to supervisors and whether the board could opt to receive official materials on personal email. Goode and county staff emphasized that county-issued addresses are the formal channel for county business and that using personal email could create open-records complications and higher risk: ‘‘If you use your personal email, your personal email is entirely open for open records request,’’ a county official said. Goode added that personal accounts, if compromised, could be used by attackers to send messages that would appear to come from an elected official and spread malware.
Supervisors and staff discussed practical barriers for some supervisors (passwords, MFA tokens, device issues). Goode said the county will work with supervisors on individual device or account problems but recommended continuing use of county accounts because they allow controlled access to sensitive packet material and simplify compliance with records requests.
When asked whether Polk County is ‘‘doing enough,’’ Goode said the county has ‘‘all of the pieces in place’’ for a reasonable defense at this size and that the principal shortcoming other counties address is hiring a dedicated cybersecurity analyst. He estimated the market salary for a cybersecurity analyst would range from roughly $80,000–$100,000 per year (Goode and one supervisor also referenced lower figures near $50,000 but noted benefits and market variation).
Goode concluded that while no program is foolproof, Polk County’s combination of technology, monitoring and regular training offers a substantive defense against the most common and damaging attacks.

