Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Internal Controls topic

No spam. Unsubscribe anytime.

Lenox council hears internal-controls update, then moves to executive session on cybersecurity

Lenox City Council · January 27, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Following recent invoice fraud and control failures in the region, city finance staff reviewed invoice and payment procedures; the council then entered executive session under transcript-cited authority to discuss cybersecurity details.

The Lenox City Council received an internal-controls and cybersecurity update after staff reported multiple cybersecurity incidents and payment-fraud cases in neighboring jurisdictions.

Finance officer Tyson (Unidentified Speaker 6) described the city’s invoice-to-payment workflow: department purchase requests generate purchase orders, invoices are attached to POs, the finance officer reviews and signs vouchers, and council signs checks before final administrative review. Tyson noted recurring ACH items (payroll, loan payments) and said most major payments remain checked and require multiple reviewers.

Council members asked about safeguards for ACH and vendor-account changes, signature-card processes at banks, and who approves transfers between accounts. Staff described controls including bank-certified contacts for loan payments and in-person verification for employee direct-deposit changes. The council discussed a recent regional spoofed-invoice fraud that cost a nearby county hundreds of thousands of dollars and emphasized the need for vigilance.

Because some cybersecurity details were sensitive, the council voted to enter executive session citing the transcript reference “1Dash252Sub 6A.” The meeting moved into executive session at 09:36 PM to discuss protected information related to cybersecurity and internal controls.

Council asked staff to return to open session with recommendations as appropriate following confidential deliberations.