Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Lane County IT leaders report progress on cybersecurity, warn federal funding cuts will raise local costs
Summary
Kim Morgan, Lane County information security officer, briefed the Board of County Commissioners on March 18 about the county’s cybersecurity and compliance program and warned that cuts to federally funded threat‑sharing services will increase local costs for monitoring and endpoint protection.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Kim Morgan, Lane County information security officer, briefed the Board of County Commissioners on March 18 about the county’s cybersecurity and compliance program, the department’s recent operational changes and an emerging federal funding gap for multi‑jurisdiction threat services.
Morgan summarized a 10‑year timeline of actions taken: device encryption and remote‑access controls, creation of HIPAA and criminal‑justice information policies, a county‑wide multifactor authentication rollout (MFA) and the 2024 migration of shared files to Microsoft OneDrive to reduce legacy server exposure. “It isn’t a matter of if, it is when” an organization experiences a major cyber incident, Morgan told the board, arguing the county must continue to invest in technical controls and processes to reduce risk.
Key points presented
- Operational milestones: Morgan and director Michael Finch (Technology Services) said the county has implemented laptop encryption, multifactor authentication for external access since 2018, and is finishing an internal MFA rollout that staff said covered roughly 85–90% of accounts. Staff reported a new engineering/operations emphasis on intake and front‑line checks so incomplete or risky requests are caught at submission.
- OneDrive migration and modern controls: staff described moving file storage off older on‑prem servers to Microsoft 365 OneDrive to enable modern patching, centralized security controls and remote access with MFA.
- MS‑ISAC changes and cost risk: Morgan explained that the Multi‑State Information Sharing and Analysis Center (MS‑ISAC) — which for years provided threat intelligence and services such as the Albert sensor and malicious‑domain blocking at little or no direct cost — faces federal funding reductions. Morgan reported a vendor quote of approximately $39,000 for an Albert sensor replacement and an estimate near $100,000 for endpoint security services if procured outside the MS‑ISAC model. The county plans to subscribe to a minimal MS‑ISAC membership package this fiscal year to preserve critical visibility, Morgan said, and to re‑use updated firewall capabilities to replicate some blocking functions in‑house.
- Grants and capabilities: staff noted a prior $100,000 Homeland Security Grant used for risk assessments and cyber planning and said continued grant eligibility may depend on participation in certain resilience reviews the state and federal partners administer.
- Staffing and coverage: Morgan said the cybersecurity team is a small unit of roughly four staff in the cybersecurity and compliance division and handles a broad set of responsibilities including badge provisioning, software vetting, audit tasks, Microsoft 365 security management and incident triage. The county currently lacks 24/7 security‑operations staffing; Morgan described daily prioritization of alerts rather than round‑the‑clock monitoring.
Board discussion and next steps
Commissioners asked for briefings to the county’s federal‑policy transition team and coordination with county clerks and other partners on elections‑security implications. Morgan and Finch asked for board support to pursue a limited MS‑ISAC subscription by September 1 so the county can lock in an 18‑month membership term under current pricing and avoid a potential service gap. Staff also requested direction on balancing modest subscription costs against internal technical mitigations (reprogrammed firewalls, continued MFA and standard‑user account rollouts).
Morgan and Finch said they would return with a fiscal estimate for the minimal membership and with a more detailed schedule for finishing the internal MFA, Windows Hello work and the standard‑user configuration that limits local administrative rights.

