Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

County IT staff warns of steady stream of malicious domains, outlines weekly defenses

2203456 · January 30, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

An update from county IT staff described frequent malicious domain activity, a weekly blocking feed, vulnerability scans and a pen test report; staff said the county lacks internal capacity to ingest all threat data and is pursuing third‑party services and cloud options.

Strafford County IT staff gave the Board of Commissioners an overview of ongoing cybersecurity threats and the county’s current defenses during the Jan. 16 meeting.

The briefing laid out weekly telemetry that county staff said shows thousands of suspicious domains, hundreds of malware or spam sites and several hundred high‑severity indicators. The county’s current approach, staff said, relies on a contractor-provided malicious‑domain blocking service and periodic vulnerability scanning and penetration testing.

County staff explained why the volume of threat data creates operational limits. “So for us to secure that, we would have to put all of that into our firewall every week. We don't have the staff that could ever do that,” the presenter said, describing why the county points its DNS to a contractor’s blocklist server that returns “site unavailable” when a user attempts to load a flagged domain.

Staff described three core elements of the program: a weekly malicious‑domain blocklist, automated vulnerability scans that report open ports and other findings, and a set of CIS control checks used to prioritize remediation. A recent external penetration test of the county website produced no major findings, staff said, though it flagged items for follow‑up.

Officials also recounted concrete phishing and impersonation attempts aimed at county payroll and payables. One example presented to the board showed an email purporting to be an internal invoice for $37,800; staff described the message as “very clever” and said it mimicked an internal chain of messages. Staff reiterated that direct‑deposit changes must be made in person on a signed form and not by email.

County staff said they are pursuing several next steps: continued use of the third‑party domain‑blocking feed, carrying out weekly vulnerability remediation identified by scans, and ongoing conversations with federal partners about adopting .gov email addresses and possibly migrating services to cloud platforms under a state bid to reduce the county’s on‑premises attack surface.

The board did not take formal action during the briefing but thanked IT staff for the update and requested follow‑up materials and the full vulnerability report be shared with designated staff.