Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Briefing topic
No spam. Unsubscribe anytime.
Ogden IT warns council: most breaches rely on user behavior, urges stronger passphrases and two-factor security
Summary
Barry Chapman, Ogden City’s network operations manager, told the March 4 work session that the majority of cybersecurity incidents originate with end-user actions and urged council members to adopt longer passphrases, two-factor authentication and cautious AI use; staff said city backups follow a 3-2-1 rule to mitigate ransomware risk.
Get email alerts on the Cybersecurity Briefing topic
No spam. Unsubscribe anytime.
Barry Chapman, network operations manager for Ogden City, briefed council members at the March 4 joint work session on cybersecurity threats, city protections and recommended user practices.
Chapman said the primary vulnerability in most breaches is the human user. “Most of the breaches, most of the incidents that occur is from end users,” he told the council, and noted that attackers increasingly target mobile devices and use social engineering and AI-based tools to impersonate people and harvest personally identifiable information.
Chapman described the city’s technical defenses—firewalls, filtered email services, Microsoft 365 protections and layered backups—and said the city follows an industry “3-2-1” backup rule (three copies of data on two different media with one copy stored off-site) to reduce the risk of irrecoverable ransomware damage. He said ransomware is a major threat and that paying ransoms seldom restores usable data.
Chapman urged council members to use long passphrases (rather than short passwords), employ a password manager to avoid reuse across accounts and enable two-factor authentication; the city has implemented Duo for 2FA. He warned that AI tools can amplify attackers’ capabilities and advised against entering confidential or personally identifiable information into public AI services such as current public ChatGPT instances.
Council members asked procedural questions about Duo setup, password policies and city training. Chapman said a cybersecurity/AI training session will be scheduled and recorded for council and staff and reiterated that IT is available to help confirm suspicious messages or logins.
Ending: City IT asked council members to treat cybersecurity as an ongoing responsibility, adopt recommended passphrases and two-factor authentication, and participate in scheduled training to mitigate social-engineering and ransomware risks.

