Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Finance Manual topic

No spam. Unsubscribe anytime.

Commission reviews finance manual updates; staff flags $1.7 million in water arrears and advances IT security upgrades

South Pasadena Finance Commission · November 25, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Staff presented a revised finance manual to strengthen internal controls and procurement, noted about $1.7 million in outstanding water-billing balances, and Tim Schallfield, the city's new IT manager, outlined a cybersecurity program including a January assessment, immutable cloud backups and multifactor authentication.

Commissioners reviewed an updated finance manual and internal-control framework that staff plans to present to the city council for adoption in early 2026. The manual reorganizes duties, clarifies procurement and reserve policies, and formalizes monthly financial reporting to improve transparency.

Staff noted the manual also functions as a reminder to follow basic controls that were relaxed during the pandemic; the document consolidates roles and procedures and adds a designated IT management position under the finance department for vendor oversight.

Commissioners questioned several operational matters, including an outstanding water-billing balance staff described as roughly $1.7 million. Staff said about $900,000 of that total related to active accounts overdue between one and five years and discussed options including payment plans, low-income assistance, targeted outreach and the possible use of collections for long-inactive accounts.

The meeting also featured a separate presentation by Tim Schallfield, the city's new information technology and systems manager, who laid out a cybersecurity agenda that pairs policy updates with operational safeguards. Schallfield said staff will align policies to NIST/CIS standards, require stronger vendor security language in agreements (encryption, incident response and data disposal terms), and complete a citywide cybersecurity assessment by January 2026.

"Secure systems protect public ops," Schallfield said, noting that a recent phishing campaign produced a 2.6% click rate while 57% of staff flagged suspicious messages. He described planned steps including multifactor authentication, immutable cloud backups for critical systems, a hardware-refresh cycle (roughly 20'5% annually) and migration of the financial ERP to the cloud under contractual safeguards.

Staff requested that commissioners submit written comments on the manual by the second week of January so staff can compile changes and present a cleaned draft at the January meeting before forwarding to council.