Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Kentucky National Guard urges Boyle County to standardize IT controls after cyber assessment

Boyle County Fiscal Court · March 10, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Lieutenant Colonel Dana Sanders told the Boyle County Fiscal Court that a Kentucky National Guard assessment found inconsistent device configurations, legacy hardware and exposed web services; the team recommended authentication, inventories, patching and pursuing state/federal grants to fund work.

Lieutenant Colonel Dana Sanders of the Kentucky National Guard told the Boyle County Fiscal Court on March 10 that a no-cost cyber assessment found a mix of strengths and weaknesses in the county's network and recommended immediate, low-cost steps to reduce risk.

"The purpose of the assessment was to come in and provide a baseline assessment of all of your internet connected devices," Sanders said, describing how the team mapped the county's attack surface and scoped recommendations to county priorities. Staff Sergeant Billy Pinley accompanied Sanders and the county's IT director, Bill Nichols, introduced the visit.

Sanders said the team found a lack of standardized configurations and policies across county offices, multiple end-of-life devices, and web-facing services with "unnecessary open ports and protocols." The report recommended domain authentication and asset inventories so the county can distinguish authorized devices from personal ones and then prioritize patching and replacement of routers and switches closest to the internet.

"One easy thing...is outdated software. Each router or switch typically reaches end-of-life around five to seven years," Sanders said, urging the court to plan lifecycle replacements and to limit externally exposed services.

Sanders also pointed the court to potential funding sources, including the State and Local Cybersecurity Grant Program and the National Guard's Innovative Readiness Training, and offered continued technical support and follow-up assessments. He stressed that findings were covered by a non-disclosure agreement and that operational details would be shared with county service providers, not broadcast publicly.

County officials asked about vendor management and how to write enforceable standards into contracts; Sanders recommended including baselines and service-level agreements and conducting periodic independent penetration testing.

The briefing concluded with Sanders proposing short-term actions the county could begin immediately—implementing username-unique authentication, documenting hardware and software inventories, and limiting externally exposed services—followed by a long-term plan for lifecycle management and a scheduled follow-up the next year.