Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Records And Cybersecurity topic
No spam. Unsubscribe anytime.
County staff report heavy public‑records workload and highlight lessons from recent cybersecurity exercise
Summary
County staff provided an update on two related information‑management topics: the volume and cost of public‑records requests in 2024, and the results of a recent county‑wide cybersecurity exercise.
Get email alerts on the Records And Cybersecurity topic
No spam. Unsubscribe anytime.
County staff provided an update on two related information‑management topics: the volume and cost of public‑records requests in 2024, and the results of a recent county‑wide cybersecurity exercise.
Public records: County staff reported that the county received and completed 693 public‑records requests in the reporting year and that fulfilling those requests consumed approximately 803.5 staff hours. Staff noted the county must retain certain records for statutory retention periods (two years for some holdings), which can increase storage needs; to support access and quality assurance the county purchased an additional five terabytes of storage before the end of 2024. Staff also said one litigation matter related to records was settled for $60,000 and that the county is preparing data summaries for legislators and JLARC as part of ongoing reporting.
Cybersecurity exercise: IT staff described a multi‑department cyber exercise conducted on January 15 that intentionally tested outage procedures. The exercise caused a temporary loss of service to MaceComm (the county’s dispatch partner) because of a programming issue that was subsequently fixed; it also exposed practical vulnerabilities such as building HVAC controls entering safe mode during an outage. IT requested after‑action reports from elected officials and department managers and said it will follow up to collect complete responses; staff said 13 departmental reports had been received and that additional follow‑up was underway.
Lessons and next steps: County IT and emergency management staff said the exercise was valuable for identifying gaps in backups, communications and business‑continuity procedures. Recommendations discussed include: - Improving department‑level continuity plans and ensuring after‑action reports are completed by managers; several departments had not yet returned reports at the time of the briefing. - Evaluating parallel communications and resilience strategies (separate state connections, radio/walkie‑talkie alternatives and other non‑internet backups) to avoid single points of failure for critical services. - Tightening internal controls for payment and cash handling during outages (some parts of solid waste operations used hand receipts during the exercise) and continuing tests of those contingencies.
Speakers referenced - County records staff (Cammy/Cammie) prepared the public‑records briefing; county staff presented the totals. - County IT staff (PJ) and administration presented the cyber exercise results.
Ending: County staff will continue to collect after‑action reports from departments, provide the data to legislative reviewers as part of regular reporting, and pursue IT resilience steps identified by the exercise. Commissioners asked staff to follow up with departments that had not returned reports and to compile a complete after‑action summary for distribution.

