Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Commissioners decline CISA cyber hygiene scanning pilot after debate over scope and risk

2387847 · February 24, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The court considered signing a CISA cyber hygiene acceptance letter for monthly external vulnerability scanning. Commissioners and members of the public raised concerns about scope, external access and recent CISA controversies; the motion to accept the service failed on a recorded vote.

Kerr County staff proposed accepting a free CISA (Cybersecurity and Infrastructure Security Agency) cyber hygiene service that would run scheduled external vulnerability scans of county network endpoints and produce monthly advisories.

Corey (IT director) explained the service is advisory and external only: ‘‘they're just looking for holes in our network’’ and the scans are automated monthly snapshots that produce reports the county can use to remediate exposures. He described the service as free and noted the scans would not be penetration tests and would not provide internal access.

Several commissioners and a public speaker expressed concern. Alicia Bell (identified as Precinct 1) asked the court to hold off and cited recent controversies involving CISA; she urged delay while DHS performed an assessment. Commissioners asked whether the scans could degrade performance (staff said they could impose a short, minimal load) and whether the county could terminate the arrangement at any time (staff said yes). One commissioner described apprehension about external entities identifying vulnerabilities in public meeting settings.

After motion and second, the court voted. The motion to accept the CISA cyber hygiene scanning letter failed; the chair announced the motion failed on the record.

Why it matters: external vulnerability scanning can help agencies identify publicly visible weaknesses, but county leaders weighed the perceived security benefits against concerns about third‑party access, recent federal agency controversies, and the need for internal safeguards. The county will continue other in‑house and regional cybersecurity steps, including ARSOC collaboration and internal scanning tools.

Next steps: staff said the first CISA scans would not begin until April if accepted; because the motion failed, the county will not implement that CISA scanning pilot via a signed acceptance letter and will continue pursuing other internal and regional cybersecurity partnerships.