Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Beltrami County cybersecurity chief warns commissioners: '9 out of 10' attacks begin with phishing
Summary
Network administrator Jared Lotte told commissioners that most county cyber incidents begin with phishing, described common tactics and urged staff to use the email 'phish' alert, enable multifactor authentication and follow a reporting and password-reset protocol if compromised.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Beltrami County's network administrator, Jared Lotte, briefed commissioners on the county’s phishing and social-engineering threat landscape and recommended concrete steps to reduce risk.
"Nine out of 10 of your cybersecurity threats start with a phishing attack," Lotte told the board, describing common techniques including email impersonation, spear-phishing, SMS 'smishing,' voice 'vishing' and counterfeit legitimate messages with replaced links.
Lotte urged staff to "hover over" hyperlinks to check destinations, report suspicious messages using the mail ‘fish alert’ button and treat urgency cues with suspicion. He explained the county runs monthly phishing training and has multifactor authentication in place; the county’s automated reporting system can quarantine malicious messages across recipients’ inboxes once identified.
If a user believes they have been phished, Lotte advised immediate reporting to IT, changing affected passwords and determining what credentials or data may have been disclosed. Commissioners practiced by asking about the reporting button and whether the county uses a third-party training vendor; Lotte declined to name vendors in public to avoid revealing threat-mitigation details, but confirmed the county performs simulated phishing and remediation training.
No immediate policy changes were proposed; Lotte asked commissioners to encourage staff to report suspicious messages promptly.

