Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Columbus officials update council on cyber intrusion, authorize CJIS security addendum and move to executive session

2216043 · February 4, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

City technology officials told Columbus City Council on Feb. 5 that the city has remediated the bulk of systems affected by a recent cyber intrusion but that the investigation is ongoing and requires special legal and security steps to complete.

City technology officials told Columbus City Council on Feb. 5 that the city has remediated the bulk of systems affected by a recent cyber intrusion but that the investigation is ongoing and requires special legal and security steps to complete.

Director Nasco, the city————————director of technology, said investigators have remediated 94% of affected systems and that 22,173 people had signed up for identity-protection services the city is offering after the breach. He said the city————————has identified approximately four databases that may contain criminal-justice information that would require CJIS certification to review, and that one database tied to the Division of Fire contained protected health information for fewer than 1,000 people.

The update came before council passed Ordinance 0297-2025, which authorizes the city attorney to modify outside counsel and cybersecurity consultant contracts to incorporate an FBI CJIS security addendum and proceed with the certification process. Council then voted to enter executive session to consult with legal counsel about litigation arising from the intrusion.

Why it matters: The city————————is continuing an investigation into a large cyber intrusion that may involve criminal-justice information and limited protected health information (PHI). Completing the investigation requires certified reviewers and legal steps that the city says cannot be completed without contract modifications and security addenda.

What officials said

"As of last Friday, the vast majority of our systems have been remediated, 94% with just 24 remaining," Director Nasco told council. He added that the city's review so far had identified "approximately 4 databases" that may contain CJIS information and that the fire-division database contained PHI for "fewer than 1,000 individuals," including names, addresses, dates of birth and brief EMS notes.

City Attorney Laura Baker Morris said the contract modifications are a precaution: "Out of an abundance of caution, it was determined that all those who during the course of the investigation may come upon such data for review will need to be certified as a practitioner under state law." The ordinance approved by council allows those outside counsel and consultants to begin the certification process.

Council action and confidentiality

Council passed Ordinance 0297-2025 to permit contract modifications that incorporate the CJIS-security addendum and enable outside counsel and cybersecurity experts to seek the necessary practitioner certification. Council member Bankston moved for passage; the clerk called the roll and the ordinance passed.

Immediately after that vote, Council Member Bankston moved that council enter executive session "to confer with the attorney for the city concerning disputes involving the city pertaining to the cyber intrusion" that are the subject of pending court action, citing the Columbus City Charter and state law. The roll-call motion to go into executive session carried; council recessed for a closed, privileged discussion with outside and in-house counsel. Council stated on the record that no formal votes or actions would occur during the executive session and that any votes would be recorded after reconvening.

What the city is offering affected residents

The city said the limited group of individuals whose PHI was in the impacted fire-division database were notified and qualified for two years of free Experian credit- and dark-web-monitoring services, which include up to $1,000,000 in fraud protection. Enrollment is available for those individuals for 90 days from notification; Experian monitoring remains available through March 31, 2025, to any Columbus resident who shared personal information with the city.

Remaining uncertainties

Officials said the list of databases potentially containing CJIS is subject to change as the investigation proceeds, and that there is currently no evidence the encrypted electronic medical-record system used by the Division of Fire was compromised or that financial-account data were involved. The city said it is unaware of any attempted misuse of personal information for identity theft or fraud to date.

Council indicated it will continue oversight as the civil litigation and criminal investigations proceed but said details are limited in open session because of ongoing proceedings.

Ending

Council reconvened in open session later in the meeting; officials said they would continue to update council and the public as appropriate subject to the limits imposed by active investigations and litigation.