Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Williamsburg IT director reports 1.3 million monthly messages and active defenses against malicious traffic
Summary
IT Director Mark Barham told council the city handles about 1.3 million Office365 messages monthly (roughly 1,000 malicious), blocks large volumes of external URLs daily, uses a 24/7 third‑party security operations center (Cybereason), maintains immutable backups and runs regular employee cybersecurity training and phishing tests.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Mark Barham, the city’s IT lead, briefed the council on cybersecurity operations and threats during the Nov. 14 meeting. He said the city processes roughly 1.3 million Office365 messages per month; about 1,000 of those are classified as malicious, 13,000 as spam and roughly 31,000 as gray mail (annoyances but not immediate threats).
Barham described firewall activity that blocks approximately 1.3 million external domains per month and highlighted roughly 2,400 critical‑severity firewall blocks — categories judged easily exploitable by threat actors. The city limits internal network access from outside the continental U.S., scans all inbound and outbound emails and internet traffic for malicious payloads, and monitors for outgoing exfiltration of personally identifiable information.
To detect and respond, the city runs a 24/7 security operations center operated by its endpoint protection vendor, Cybereason, which monitors logs and alerts staff to anomalies for triage. Barham emphasized immutable backups (on‑site and off‑site) as essential to defend against ransomware, and described weekly vulnerability scanning and an ongoing employee security training program that includes monthly simulated tests.
Barham said endpoint protection and vendor monitoring keep the city current on threat signatures and mitigation; he noted staff test employees monthly and require additional training when users fail phishing tests. Councilmembers praised the department’s work and asked about vendor access and data protections; Barham said vendor access flows through the same monitored systems and is controlled by the city.

