Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Polk County IT director warns of rising ransomware risk, outlines defenses and staff training
Summary
IT Director Scott Goode told the board that government-targeted ransomware and phishing attacks have surged and described Polk County’s current security posture, recent near-miss, and ongoing measures including phishing simulations, multifactor authentication, encryption, a 24/7 security operations center and monthly awareness training.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Scott Goode, Polk County's information technology director, told the Board of Supervisors on Sept. 16 that ransomware and other cyberattacks concentrated on government agencies have increased substantially and described the county's defensive program and recent incidents.
"We've got greater than 235% rise in government ransomware attacks over the period of April 2024 to 2025," Goode said, and added that the average cost of a data breach can reach about $4,000,000 while the average ransom demand is nearer $500,000. "Eighty-eight percent of breaches are happening from your human factor," he said, stressing that user behavior — clicking malicious links, responding to spear-phishing or smishing attacks — is the most common way attackers gain a foothold.
Goode reviewed national and state incidents to illustrate potential impacts, referencing a prolonged ransomware outage in St. Paul and other county-level incidents that disrupted land records and public services. He also reported Polk County's own near-miss: an April incident investigated with Wisconsin County Mutual that the county treated as a coordinated response and, after review, did not classify as a breach. He said Polk County's defenses had identified and blocked many threats over the preceding six months, reporting "788 advanced malware threats were identified and avoided" and about "7,000 phishing and business email compromise attempts" that were filtered.
Goode outlined the county's current security and preparedness measures:
- Information security policy and regular third-party risk assessments, plus CJIS audits where applicable. - Monthly security awareness: two short trainings per month and phishing simulations that track staff responses and trigger remedial training for clickers. - Least-privilege account controls and multifactor authentication (MFA) for county accounts. - Encryption at rest and in transit and off-site backups for critical services. - A contracted 24/7 security operations center and managed detection and response to monitor telemetry and provide alerts. - Security reviews of third-party vendors and contract protections for county data.
Board members raised questions about county email use by supervisors. Goode and other staff explained the county assigns government email addresses and that using a personal email address for county business can complicate open-records compliance and increase exposure if a personal account is compromised. Staff also discussed the cost and potential value of adding a dedicated cybersecurity analyst; Goode said such a position could cost on the order of $80,000–$100,000 a year including benefits, though an offhand lower estimate of $50,000 was mentioned earlier in the discussion.
Goode said the county uses layered defenses and continuous improvement but acknowledged that human error will remain the primary residual risk and recommended continued investment in training and targeted staff capacity to accelerate remediation work.
The board did not take formal action on the cybersecurity presentation; it was presented for information and direction.

