Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Commissioners authorize cybersecurity audit but pause broader IT assessment after elected officials object

2792513 · March 27, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Boone County commissioners allowed a contracted cybersecurity assessment to proceed but agreed to suspend the wider IT assessment portion of the same contract until elected officeholders and county staff can meet to clarify scope, access and confidentiality concerns.

Boone County commissioners voted on March 10, 2025 to permit a cybersecurity assessment to continue while postponing a broader IT-assessment component after multiple elected officials and department heads raised concerns about scope and access.

The cybersecurity audit — intended to identify network vulnerabilities and recommend hardening measures — was described at the meeting as acceptable to the board and to outside technology advisers. But several elected officials said they had not been consulted and were worried that a broader IT assessment could involve direct access to confidential or sealed records maintained by offices such as the prosecutor, auditor and clerk.

Why it matters: Elected officials and department heads told the board they want written clarity about what contractors will inspect, how access will be granted, and what nondisclosure protections will apply before any on-site review beyond network- and infrastructure-level examination proceeds.

At the meeting, technology committee member Aaron Williams, speaking as an elected official with IT committee experience, said the cybersecurity work normally does not require access to personal case files and instead examines infrastructure. “In an assessment of this nature, there's no need for anyone to access any kind of information from the prosecutor's office, the sheriff's office,” Williams said. He described typical safeguards, including vendor confidentiality agreements and indemnifications, that accompany these engagements.

Multiple elected officials disagreed about how the contracted assessment had been scheduled and executed. Auditor Debbie Grama and several other elected officeholders said they were not notified in advance when vendor staff visited offices, and they asked for a joint meeting so elected officials can review the planned scope and any proposed access procedures before countywide IT work proceeds.

County staff and vendors said the recent site visits focused on physical infrastructure — server and switch rooms — and escorted vendor personnel had gone through background checks where required. Sean Graham of Boone County IT said the intent was to evaluate county network equipment and identify cybersecurity gaps. Representatives of the county's long‑time IT vendor (referred to in public comments) described their ongoing support and expressed concern about replacing existing vendor relationships without further review.

After extended discussion, a commissioner moved that the board allow the cybersecurity assessment to proceed but table or suspend any broader IT-assessment work until an additional meeting with elected officials and affected departments can occur. That motion was seconded and carried on a voice vote; the board recorded the action as permitting the cybersecurity portion to proceed while holding the IT-assessment component for further discussion and possible amendment.

Next steps: Commissioners directed staff to schedule a focused session with elected officials and IT leadership to clarify the IT-assessment scope, list specific systems that would be examined, and confirm nondisclosure and access procedures. The board said the cyber assessment can continue under the existing contract terms for that portion of the work but that no on-site IT work beyond infrastructure inspection should proceed until the follow-up meeting.

The decision follows earlier board votes in December and January authorizing related cybersecurity work and allocating ARPA funds; several speakers asked that past approvals and the current motion be reconciled with clearer communications to elected offices going forward.