Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the IT And Disaster Recovery topic
No spam. Unsubscribe anytime.
Morrow County reviews ERP hosting, ransomware liability and disaster‑recovery gaps
Summary
Board heard questions about who hosts county ERP data (Univeris/Blue Ocean, SAP, PDS) and whether contracts and the master services agreement specify vendor responsibility for ransomware or data loss; consultants presented a business‑impact analysis that identified single points of failure and recommended updated intergovernmental agreements, documented processes and contract management.
Get email alerts on the IT And Disaster Recovery topic
No spam. Unsubscribe anytime.
County staff and vendors fielded commissioner questions about an enterprise resource planning (ERP) master services contract and data hosting arrangements, while consultants presented a business‑impact analysis and recommended steps to reduce the county’s exposure.
During public and staff discussion about the ERP procurement and integrations, staff named multiple hosting parties: "It'll be Univeris or Blue Ocean Systems themselves, and then SAP, which is the core financials package, and then PDS, which is the HR package," a county project representative said, adding that licensing and data‑processing agreements referenced in the master services contract require security compliance and that SOC 2 was one of the referenced standards.
Commissioners asked who bears liability and recovery costs in the event of ransomware or vendor data loss. The staff reply: contractual remedies may exist if vendors fail to meet contract terms, but because county data is ultimately the county’s data, operational decisions in a ransomware event would rest with the county. "If they reach the con terms of the agreement, then there may potentially be legal recourse for the county," staff said during the meeting.
Separately, consultants contracted to develop a technology business continuity and disaster‑recovery plan (BerryDunn) presented a phase‑two business‑impact analysis. Erin Provazic summarized the key themes: the county has strong backup practices and access to backup workstations via the City of Hermiston, but the analysis identified risks including limited written documentation of operational procedures, a high level (vague) intergovernmental agreement with the City of Hermiston for IT services, co‑located backup infrastructure that could be vulnerable to a single incident, single points of network failure across disparate sites, decentralized procurement and contract management that can leave vendor disaster‑recovery obligations unspecified, and paper‑file dependencies.
Provazic said short‑term mitigations already underway include network upgrades and backup infrastructure work in cooperation with the City of Hermiston. Long‑term recommendations include formalizing an IT procurement approval process, expanding digitization of paper records, clarifying the intergovernmental agreement to define service levels and disaster roles, and developing documented departmental process and contingency plans. The consulting team expects to finish the formal business‑continuity and disaster‑recovery strategy document in January and recommended governance, testing and prioritized recovery objectives be included.
Action and follow‑up: commissioners asked staff to spell out in county policies how to handle monetary loss and ransomware incidents in the county’s theft/loss reporting policy and to ensure the new ERP contracts and vendor licenses explicitly address vendor disaster‑recovery responsibilities. The board also directed staff to coordinate next steps for implementation items identified in the business‑impact analysis, including planned projects for network redundancy and contract standardization.
What’s next: BerryDunn will deliver the final strategy and recommended recovery point/time objectives; staff will work with counsel to revise the theft/loss policy to explicitly include cash and cyber incidents and return to the board with contract and procurement improvements for county IT acquisitions.

