Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Finance—Taxonomy topic

No spam. Unsubscribe anytime.

Treasurer's planned detailed fund posting drew cybersecurity warnings; office contracted consultants and crisis communications

2420688 · February 18, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Committee reviewed a treasurer's office plan to publish a detailed fund report and a Department of Administration cybersecurity memo that recommended against publication; the treasurer's office also retained outside consultants, including a GASB expert and a communications firm.

During the same subcommittee hearing, members pressed the Office of the State Treasurer about a letter the treasurer had sent saying the office would post a detailed fund report online and about subsequent advice from the Department of Administration cautioning against that publication for cybersecurity reasons.

The issue matters because the proposed detailed fund report listed general ledger account numbers, fund names and other granular information that Department of Administration cyber experts warned could increase the state's exposure to fraud or social‑engineering attacks, the department wrote in a contemporaneous memo the treasurer's chief of staff read into the record.

Clarissa Adams, chief of staff for the treasurer, read a letter the treasurer had sent the committee and described follow‑up communications with the Department of Administration. The Department of Administration responded the same day and "strongly recommend[ed] that the detailed fund report attached ... not be published," the letter read, citing advice from outside cybersecurity specialists who reviewed the proposed report and warned that the level of identifying data could aid attackers.

Committee members also asked the treasurer's office about its use of outside consultants. Clarissa Adams said the office had engaged William Holder, a former GASB board member and university accounting professor, to advise on ACFR/ACFAR presentation questions; she said the treasurer's office paid an invoice to Mr. Holder (approximately $14,800). She also confirmed the office had engaged a communications firm, Infinity Marketing Services, for communications support; she said the firm provided assistance with messaging and crisis communications but said she would confirm payment sources and fees for the committee.

Senators asked whether public funds had paid the consultants and whether the communications work included coaching witnesses for committee testimony. Clarissa Adams said she hired Mr. Holder and that the Holder invoice was directed to her attention; she acknowledged Infinity provided communications assistance and said she would get the committee a clearer record on invoices and who paid them. At times she said she did not have immediate invoicing details and that staff would follow up with specifics.

The Department of Administration told the committee it had consulted outside cybersecurity experts before advising against publication. In a letter read into the record the department's counsel wrote that the proposed detailed fund report contained identifiers — ledger account numbers, software types and fund account names — beyond what the department believed was required by statute and that releasing such detail would "give potential hackers more ability to triangulate and map their way to improper access." The department recommended limiting published information to what is statutorily required.

The committee requested copies of the correspondence, the consultant invoices and any records showing who paid for outside communications support. Members said they expect the treasurer and his staff to return with those materials and, if appropriate, bring the treasurer back to testify in person.

Ending: The treasurer's office said it would provide the committee the requested invoices and correspondence and the Department of Administration said it would supply its cybersecurity analysis; the committee signaled it will review whether published statutory disclosures need updated guidance to balance transparency and operational security.