Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Loeffler consultant lays out Minnetrista cybersecurity posture, urges pen tests and incident planning

Minnetrista City Council (work session) · April 7, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A Loeffler consultant told the Minnetrista City Council on April 6 that existing protections — firewalls, endpoint detection (SentinelOne) and a managed detection service (Arctic Wolf) — are strong but recommended annual penetration tests, an incident-response plan and budgeted upgrades for 2027.

At a Minnetrista City Council work session on April 6, a vendor consultant from Loeffler gave a detailed briefing on the city’s current cybersecurity controls and a menu of recommended next steps, and staff asked the council to consider budgeting for new measures in 2027.

Jeff (Loeffler) told the council the city’s two internet connections (city hall/PD and another for the water/treatment group) are protected by firewalls with active gateway security services that scan traffic for malware and intrusions. “SentinelOne is an EDR which is called endpoint detection and response,” Jeff said, describing the city’s endpoint protection as an “AI powered” layer aimed at preventing ransomware. He added the city uses a managed detection and response (MDR) service from Arctic Wolf Networks that combines automated monitoring with human analysts.

Jeff described other operational controls currently in place: monthly end-user awareness training with phishing simulations; external vulnerability scans of firewalls; quarterly manual firewall inspections to detect unauthorized changes; 24/7 “dark web” monitoring to detect exposed credentials; and email threat scanning that removes spam and messages with malicious links or attachments before they reach users.

On recommended actions, Jeff proposed several items for the council to consider budgeting for in coming years: annual third‑party penetration testing against the city’s defenses; a formal incident‑response plan and annual tabletop exercises involving staff; expanded internal vulnerability scanning and fuller security assessments that include physical access and administrative controls; managed policy documents (acceptable‑use, incident response, clean‑desk); and regular backup‑recovery testing. He also flagged newer identity protections — “risky login” detection and conditional multifactor authentication (Microsoft Authenticator and geofencing) — as emerging capabilities to watch.

Council members asked how the city is handling recent spoofed emails and bogus invoices reported by residents. Staff said they have looked into adding CAPTCHA or recaptcha on download pages and have asked CivicPlus (the website vendor) for the feature; staff also said they have been buying confusingly similar domains to reduce impersonation. Staff reported residents who received bogus invoices had contacted the city and, to staff’s knowledge, none had paid. Staff said many of the spoofing sources traced to overseas actors and that investigations beyond that were limited.

Mayor (speaker 1) asked staff to return later this year with prioritized recommendations and cost estimates so the council can consider additions to the 2027 budget; Jeff agreed to provide follow‑up numbers. The council did not take any immediate formal action on the recommendations during the work session.