Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
San Dimas reviews cybersecurity posture, schedules CISA assessment
Summary
IT Manager John Lee briefed the council on the city's cybersecurity measures, citing NIST and CIS frameworks, ongoing training and partnerships, and a CISA assessment and penetration test scheduled for March; council voted to receive and file the report.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
San Dimas IT Manager John Lee presented an overview of the city's cybersecurity posture and planned improvements, telling the City Council the city follows National Institute of Standards and Technology (NIST) and Center for Internet Security (CIS) controls and has partnered with external monitoring firms since 2019.
John Lee described current tools and practices — multi‑factor authentication, rule‑based access controls, simulated phishing tests and a 3‑2‑1 backup strategy — and said the city completed a cybersecurity maturity assessment in 2024 with a California joint powers authority. "To ensure the city's cybersecurity remains strong, we have adopted industry leading framework, tools, and best practices," Lee said. He also noted a CISA cyber assessment and penetration test scheduled for March to identify vulnerabilities and provide recommendations.
Lee outlined current cybersecurity budget lines that support ongoing services: $115,000 for security technology subscriptions and licenses, $43,000 for computer professional services and $38,000 for IT managed services. He said any further upgrade costs will depend on the CISA assessment findings and that staff will present cost estimates for the 2025–26 fiscal year budget.
Councilmembers thanked Lee for the briefing and emphasized continued prioritization of cybersecurity. A councilmember moved to receive and file the staff report; the motion passed on a voice vote reported as unanimous.

