Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Daytona Beach commission debates cybersecurity ordinance that would let manager suspend elected officials' network access

2231077 · February 5, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Daytona Beach — Commissioners on the Daytona Beach City Commission spent more than two hours Feb. 5 debating an ordinance to adopt a cybersecurity policy for elected officials that, as drafted, would allow the city manager or a designee to remove an official’s access to the city’s information-technology network if the official “fails to comply with the policy.”

Daytona Beach — Commissioners on the Daytona Beach City Commission spent more than two hours Feb. 5 debating an ordinance to adopt a cybersecurity policy for elected officials that, as drafted, would allow the city manager or a designee to remove an official’s access to the city’s information-technology network if the official “fails to comply with the policy.”

Supporters framed the proposal as a narrowly tailored safety measure. Hassan Rezika, the city’s chief information officer, told commissioners, “Should we see that an account is compromised, we would certainly first reach out to the city manager to get his approval to be able to stop the accounts ... and then, until the account is remediated, we provide access back.”

The ordinance was introduced on first reading; the commission set final action for Feb. 19. The first-reading discussion exposed deep divisions among commissioners about delegation of authority, the scope of state law and the privacy implications for officials using city email on personal devices.

Why it matters: City staff and the mayor said the policy closes a legal gap because state cybersecurity training and reporting requirements are written for employees and do not clearly extend to elected officials. Administration officials pointed to high-profile ransomware losses in other cities and said local IT needs explicit policy backing to act quickly when accounts or systems are under attack.

What happened at the meeting: Rezika described technical indicators that prompt action and said the recommended practice follows standard incident-response steps: isolate the compromised account, stop further damage and then triage. He said the city uses layered protections beyond Microsoft 365’s email filters and that the proposed policy would allow staff to secure systems quickly.

Commissioner Cantu led the opposition, repeatedly saying she would not accept a delegation that, in her view, places the city manager above the elected body. “I personally can’t do it, and I will not do it,” she said, adding that the state law she cited to staff applies to employees and not to elected officials. The city attorney and the city manager both said they had reviewed the legal authority and did not identify a charter impediment to delegating temporary suspension authority by ordinance; the city attorney said the commission retains final authority to determine compliance in disputed cases.

Several commissioners urged compromise language. Commissioner Megan Strickland and others suggested edits that would require advance notice “where practical” and require the city manager to advise the official of steps to restore access. Mayor Derek L. Henry said he supported a policy that protects residents’ data and the city’s infrastructure while preserving the commission’s authority to change the policy.

What the ordinance says (as introduced): The draft ordinance would adopt a cybersecurity policy for elected officials specifying acceptable use of city IT systems. Section 2 of the policy says the city manager or designee is authorized to remove access to the network for any elected official who fails to comply; the policy language also says, “where practical, prior to removing such access, the city manager or designee shall provide the elected official advance notice and advise the elected official of the steps needed to correct the failure.” The ordinance was presented as a first reading; the administration said changes requested by commissioners can be incorporated before second reading.

Unresolved questions and next steps: Commissioners asked staff to return with clarified language on who has authority in what circumstances, what data IT can see when officials use personal devices, and whether the mayor or IT director could be named in place of the city manager. The commission scheduled the public hearing and final action for Feb. 19. Staff said they would also provide a redline that indicates the portions of the policy that apply to city-issued devices versus bring-your-own-device scenarios.

Ending: The Feb. 19 hearing will be the commission’s next opportunity to revise or reject the ordinance. Supporters say the policy is needed to respond quickly to active incidents; opponents said they want clearer limits on managerial authority and stronger protections for elected officials’ personal devices.