Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Daytona Beach Commission tables cybersecurity ordinance after legal and practical concerns
Summary
Commissioners paused a second-reading ordinance to require cybersecurity training and give designation authority to the city manager after debate over charter limits, insurance exposure and how emergency access should be handled.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
The Daytona Beach City Commission on Feb. 19 voted to table a second-reading ordinance that would establish a cybersecurity-related acceptable-use policy for elected officials, following a lengthy public discussion and testimony from cybersecurity professionals and lawyers.
The item, introduced as an ordinance to codify an acceptable-use and cybersecurity policy for elected officials, was the subject of public comment from two local cybersecurity practitioners who told the commission the draft aligns with best practices but must evolve as threats change. Pierre Lewis, who described himself as a retired cybersecurity officer, said, “it's always about the data,” and recommended focusing the policy on protecting networked data and devices. Anne Ruby, another public commenter with cybersecurity experience, said the proposed measures were “a very sound policy” and urged adoption as prevention against costly breaches.
Commission debate centered on whether the ordinance would unlawfully elevate executive administrative authority over the elected commission. Commissioner Cantu said she was "not against any kind of cybersecurity policy" but argued the draft may violate the city charter by giving the manager unilateral authority to suspend access for elected officials; she said she had consulted outside counsel and asked whether delegating that authority to the manager would constitute an impermissible transfer of the commission's powers. Cantu invited discussion of an alternative in which the mayor’s emergency powers would be used instead.
City Attorney Ben Gross responded at length that the charter vests the commission with authority to delegate administrative powers, that the ordinance ties any temporary suspension to narrowly defined circumstances (imminent threats to network resources or to comply with cybersecurity best practices) and that failure to follow best practices could risk the city’s insurance coverage in a future ransomware or breach event. Gross said the draft had been intentionally written to reference generally accepted frameworks such as the National Institute of Standards and Technology (NIST) cybersecurity framework.
Commissioners and the city attorney discussed possible redrafts: several commissioners said they would accept narrower language that limited manager authority to immediate or imminent threats, with non-imminent compliance issues routed to the commission for a decision. The commission asked staff to research whether the mayor’s emergency-declaration authority could be used in the way some commissioners preferred and to obtain insurance-policy language showing whether failure to comply with “best management practices” could void coverage.
No final ordinance vote occurred. The commission ultimately voted to table the measure for further study; the motion to table carried unanimously, 7-0.

