Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

West Chester CISO reports jail camera outage, large political email attack in quarterly IT briefing

2092515 · January 8, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The borough’s chief information security officer (CISO) told the ACT Committee on Jan. 7 that the IT department’s quarterly report (covering October through December 2024) documented an unusual volume of unscheduled incidents and ongoing cybersecurity work.

The borough’s chief information security officer (CISO) told the ACT Committee on Jan. 7 that the IT department’s quarterly report (covering October through December 2024) documented an unusual volume of unscheduled incidents and ongoing cybersecurity work.

The CISO said an early-morning equipment failure on Dec. 15 knocked out cameras in the borough holding cells after one domain controller failed; staff paused one controller to restore service and later identified a faulty integrated lights-out interface (iLO) on a host server. The outage left officers without camera views of some cells for about two hours before systems were restored and repaired the following Monday.

The CISO also reported a sustained political-volume email attack that began Dec. 18 and continued intermittently through Dec. 21. “About an hour, 3,314 messages” were sent toward elected-official inboxes, the CISO said, and staff worked with the borough’s email vendor (identified in the meeting as Veracruiter) and Barracuda support to stop the flow; the messages were described as nuisance political content rather than ransomware or malware. The officer said the attack functioned like a denial-of-service on mailboxes and required manual and vendor intervention to prevent messages from landing in inboxes.

Other operational items in the quarterly briefing included replacing a door-locking mechanism in a cell block, adding a Wi-Fi access point to the police holding area to support live-scan fingerprinting equipment, moving digital screens and computing equipment after personnel shifts in the police department, and work to refresh the Building & Housing pages on the borough website.

On routine cybersecurity work, the CISO said the borough logged about 766 help-desk tickets in the year, conducts monthly phishing tests and biannual classroom training, and is moving to two-to-three penetration tests per year. The CISO said staff will roll out seven new cybersecurity policies this month covering topics such as email confidentiality, use of personal email and bring-your-own-device rules. He also noted two attempted account-takeovers in the year that were not successful.

The CISO said the 2024 IT budget “performed as expected” and that the 2025 budget is set; planned projects for 2025 include more frequent penetration testing, an agenda/meeting-center purchase (purchase order on the finance agenda), audio upgrades in council chambers, and regular workstation replacement and host-server leases.

On emerging technology, the CISO said the team is testing Microsoft Copilot and studying AI policy and use cases; transcription and recording add-ons were described as available from vendors but were not included in the purchase discussed for this committee meeting.

The CISO closed by underscoring ongoing staff training and awareness programs, including a weekly cybersecurity newsletter and short daily videos to reinforce social-engineering defenses.

Ending: The IT official said incident-response changes and more frequent third-party testing are intended to reduce future outages and speed response to high-volume email attacks; no further action or formal vote on IT policy changes was taken at the Jan. 7 ACT Committee meeting.