Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Utah County seeks three cybersecurity hires and proposes per‑FTE security charge after sustained alerts
Summary
Information-technology leaders reported large volumes of security telemetry and recent incidents, and proposed three new security positions plus a per‑employee security charge (about $100 per FTE) to fund a roughly $1.2 million security program for FY26.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Utah County IT and information-security staff told commissioners on Sept. 4 that cyber threats are constant and increasing, and presented a personnel and funding proposal to expand the county—s security capacity.
Brandon Wong, who led the information-security portion of the presentation, said the county began forwarding logs to a security information and event management system (AdLumen) in March. "We're averaging over 30 detections every single day," Brandon said, and he summarized the MarchSeptember dataset as more than 815,000,000 logs ingested, roughly 5,200 detections and more than 340 escalated alerts in six months.
Brandon said those alerts have produced recent incidents: a phishing campaign that reached about 100 county accounts, 25 clicks and roughly 10 to 11 accounts compromised; and a vendor-email compromise event in the weeks before the meeting. Each incident required full-day remediation efforts, he said, and the county—s current security staffing model (one person responsible for security) makes it difficult to respond while also improving proactive defenses.
To strengthen defenses, Brandon proposed adding three positions: an information-security analyst (to handle alerts and phishing response), a junior information-security engineer (to tune security tools, run vulnerability scans and support incident response) and a senior information-security engineer (to lead major incidents, run vulnerability-management and set technical strategy). Brandon said the roles would increase detection and response capacity and support a shift from reaction to prevention.
County administration said the proposed security program cost is roughly $1.2 million and recommended funding it via a new security charge assessed across departments. The county proposed charging on a per-FTE basis, which Brandon and staff described as "just over $100 per employee" (presenters discussed a figure in the neighborhood of $100 per FTE during the meeting; staff noted the per-FTE charge will change if the denominator of covered employees changes). The county did not take a vote; the request was presented as part of the FY26 budget discussions.
Brandon and IT staff also noted broader drivers of risk: government entities hold sensitive health, CJIS and financial data; attackers use AI-enabled phishing to make messages more convincing; and nation-state actors and criminals exploit windows when staff are offline (holidays or overnight). Brandon recommended a mix of staffing, tool consolidation and ongoing vulnerability management to lower risk.
No formal action was taken at the work session; staff said the proposal will be included in FY26 budget materials for commission consideration.
