Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Commissioners adopt county cybersecurity program as official framework; report of suspicious county-branded emails
Summary
The board approved a Trumbull County cybersecurity program aligning with NIST guidance and several state and federal policies; a commissioner reported emails appearing to come from a county address that asked recipients to sign in using a code, and asked IT to investigate.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The Trumbull County Board of Commissioners approved a countywide cybersecurity program intended to establish a framework to protect county information systems, data and services against evolving threats. The program, described during the meeting, aligns with the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2 and referenced Ohio Revised Code 9.64, House Bill 96, and applicable FBI Criminal Justice Information Services (CJIS) security policy provisions.
During discussion, a commissioner reported that a township trustee had notified him about emails that appeared to be sent "from my email, at least my county email" and that the messages, titled "Trumbull County officials," were asking trustees to sign in with a code to receive a message. The commissioner told IT to investigate whether the messages originated from county systems.
The board approved the cybersecurity program by motion. Commissioners emphasized the need to "kick in quick" security measures in light of the reported suspicious emails and asked for IT follow-up.
The program adoption was recorded as part of the formal agenda and the vote carried with the commissioners present voting in favor. The meeting record did not include technical details of incident investigation or a timeline for IT response; county IT and law-enforcement security partners were identified in the agenda materials as potential implementation contacts.
The board did not specify public disclosure steps or a timeline for notifying affected recipients beyond the request for IT to investigate the reported email activity.

