Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity It Recovery topic
No spam. Unsubscribe anytime.
Abilene council approves emergency IT purchases after cyberattack; staff say insurance and reserves will cover costs
Summary
The council approved one‑time purchases to restore critical computer and phone systems damaged in a recent cyberattack. City staff said purchases will be initially funded through the city's MIP reserve and that insurance claims are expected to reimburse the cost; staff described purchases and plans to expand monitoring and cybersecurity tools.
Get email alerts on the Cybersecurity It Recovery topic
No spam. Unsubscribe anytime.
The Abilene City Council voted to approve a set of emergency information‑technology purchases to restore computer, phone and server capacity damaged in a recent cyber intrusion.
Troy Swanson, the city's IT director, described the purchases during council discussion: the city bought peripherals and miscellaneous items from CDW, a piece of software from Ceridian, and a variety of Dell equipment including "approximately 200 MDCs" (mobile data terminals used by emergency services) and "approximately 300 desktops." Server Supply provided memory modules to restore servers; Simuri supplied devices used by the cybercrimes initiative; and telecom purchases included about 100 phones and hosted phone services to restore the phone system.
Swanson said most contracts were one‑time purchases to replace damaged equipment; telecom includes a hosted monthly subscription while the city recovers phone service. On procurement timing, Swanson said the city will follow normal procurement channels for any additional requirements as recovery continues.
Council members asked about funding and long‑term cybersecurity plans. The city manager's office said emergency purchases "will be initially funded through the MIP" (municipal insurance program/reserve) and the city is working with its insurance representative on claims to reimburse the MIP. The city has not yet finalized the total recovery cost. Public commenters and council members noted prior estimates that the total financial impact of the incident could be as high as $15,000,000; staff said the ultimate claimable amount will depend on the insurance process.
Swanson described detection and response: IT staff noticed "characteristics of how the servers were running that were not appropriate" within about 30 minutes and, between roughly 4 a.m. and 7 a.m., identified the problem and shut systems down to mitigate damage. He said the city had prevention tools in place before the incident but fewer monitoring tools; staff are now acquiring enhanced monitoring and three separate prevention/protection tools and intend to "employ a new monitoring service that would allow us to monitor the environment proactively," so suspicious activity can be detected sooner.
Joshua Farrow, who said he works in cybersecurity, urged the council to clarify staffing and oversight: "If we're not actively figuring out staffing for this and training, or at the very least outsourcing this to someone like an MSSP, you're asking to get hit again," Farrow said.
The council voted to approve the purchases and recovery actions. The motion carried by recorded voice vote with all members present voting yes.
Council members and staff said they will continue daily briefings with cybersecurity consultants and the city's insurance agent, and that further procurement requests will come back to council for approval when additional needs are identified.
