Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity And It Assessment topic

No spam. Unsubscribe anytime.

Consultants warn of inactive devices, unsupported software and external vulnerabilities in Bourbon County and Fort Scott IT systems

5436481 · July 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

An IT assessment presented to Bourbon County and the City of Fort Scott identified housekeeping gaps—inactive devices, missing patches, inconsistent password policies and external vulnerabilities—and recommended a phased cleanup, Microsoft 365 hardening and network segmentation to reduce cyber risk.

A Stronghold Data representative told Bourbon County officials and Fort Scott staff during a work session that a joint IT assessment found numerous maintenance and security gaps, including inactive devices, unsupported software, missing patches and external vulnerabilities that increase the risk of a cyber incident.

The assessment, described by the Stronghold Data representative as “just a starting point,” recommended a structured cleanup of inactive devices and network closets, enforcement of password and screen‑lock policies, routine patch testing, deployment of Microsoft 365 anti‑phishing and impersonation protections, and a longer project to segment county and city networks.

The consultant said the problems are largely labor and housekeeping rather than large hardware purchases. “A lot of our risk could be mitigated by some health checks, some proper maintenance,” the Stronghold Data representative said, urging the entities to standardize device lifecycles and apply technical enforcement where policies exist only on paper.

Why it matters: the consultant flagged sensitive personally identifiable information (PII) found on county machines and a preliminary liability estimate tied to potential data exposure. The report showed a Microsoft cloud security profile score of 8.2 (indicating gaps to address) and identified roughly 19,000 counts of sensitive data in the county scan, though the presenter said that number likely includes duplication and would require further analysis.

Key findings the consultant highlighted included a high volume of inactive or unmanaged devices, unsupported Microsoft operating system versions on some active machines, inconsistent patching that has previously caused operational problems (the presenter cited a past payroll disruption after a Windows patch), and external router/OS exposures tied to on‑site equipment such as Palo Alto devices.

On network performance, the consultant said the county and city currently share a primary circuit and that traffic is carved into slices as it’s routed to different buildings, which reduces throughput to end users. He recommended optimizing wired connections and addressing unmanaged switches and isolated wireless use that are creating choke points.

On user behavior and training, the consultant recommended quarterly phishing simulations and remedial training for staff who click simulated phishing links. He said anti‑phishing and anti‑spam settings in Microsoft 365 should be consistently enforced and that services exist to simulate phishing campaigns (for example, providers such as KnowBe4), which insurers commonly require for cyber liability coverage.

Remediation planning and cost: the presentation included a phased remediation timeline (months 1–3 for immediate housekeeping, months 4–6 for wireless and point‑to‑point link remediation, and later months for segmentation). The consultant gave a preliminary partial cost estimate of about $189,000 for items still being compiled and cautioned that the figure was not final. He emphasized some tasks would be straightforward cleanup that can be specified in requests for proposals while others—such as a full segmentation project—would require a fuller statement of work.

The consultant repeatedly cautioned against publishing detailed findings that name specific vulnerable machines or exact configuration details, calling that information sensitive because it could be used by attackers.

Next steps discussed included providing the full, more detailed reports (the presenter said hundreds of pages of data exist), refining cost estimates, and drafting a statement of work for remediation and potential separation of county and city networks. The consultant invited follow‑up questions from both city and county staff and offered to remain available during the executive session to discuss sensitive items.

Ending: officials said they would digest the executive summary and follow up with questions. The consultant noted many of the recommended fixes do not require large capital expenditures but do require a sustained, proactive maintenance and lifecycle management approach.