Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

County hears warning about stealthy cyberattacks, advised to improve visibility

3675489 · June 5, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

OTM Cyber founder Jamie told Marion County commissioners that small counties are prime targets for long-term, low‑visibility cyber intrusions and recommended visibility, segmentation and email monitoring. He described specific software vulnerabilities and gave a pricing range for an initial monitoring service.

Jamie, founder of OTM Cyber, told Marion County commissioners during a presentation that counties and small agencies are being targeted by what he called “lay of the land” attacks — stealthy intrusions that embed in networks and wait to be weaponized.

Jamie said such intrusions often do not cause immediate outages and therefore can go unnoticed for months or years. “Most of the cyber attacks you hear about today are the ones that make the news because it was obvious,” he said. He said the larger worry is attackers who “sit on their hands and they wait” until they can use the access to disrupt critical services.

The presentation cited recent incidents that affected 911 operations and municipal communications, and described one commonly used piece of CCTV-management software (identified by Jamie as “NVMS 5000”) that, he said, contained code that “phoned home” once a month and could act as a backdoor if weaponized. Jamie said federal agencies including the FBI and CISA contacted him after the discovery because the software was widely used across both local and federal systems.

Why it matters: Jamie said small counties are attractive targets because they often have limited cybersecurity visibility and legacy systems. He recommended starting with a service to provide network visibility, then adding targeted protections based on what the county’s asset inventory shows.

What commissioners and staff asked: Commissioners and staff discussed specific local risks, including whether utility partners and equipment with over‑the‑air updates (for example, agriculture and construction equipment) could be leveraged by attackers. Jamie said approaches differ by manufacturer and recommended first gaining visibility of what devices and services are communicating on county networks.

Service details and costs Jamie provided: He described a core monitoring service his firm calls Vanguard and said pricing varies by size: “Tier 4 is the smallest, and that would be by your neighbors…that could be anywhere from 15,000 a year to 20,000 a year,” he said. He added that endpoint agents are an add‑on (he cited a figure of about $5 per device per month) and that email filtering and monitoring is a separate add‑on to detect phishing and malicious mail.

Jamie said training and simulated phishing tests are also available from his firm; he described a service that reports who clicked simulated phishing emails so the county can target training. He cautioned that there is no single “silver bullet” and that improving security is an ongoing, multi‑layered effort.

Participants and attribution: The presentation was led by Jamie of OTM Cyber and included questions from county commissioners and staff. Commissioners thanked Jamie for the briefing and asked county staff to follow up about creating a package for further review.

Ending: Commissioners agreed to continue the discussion with county staff to evaluate options and costs. Jamie offered to follow up with county staff to assemble a proposal.