Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Security Training topic

No spam. Unsubscribe anytime.

Okaloosa County IT Council reviews security-awareness training after state breach-law changes

Okaloosa County Information Technology Council · April 21, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Okaloosa County Information Technology Council reviewed draft policies to formalize security-awareness training after a change to the Oklahoma Security Breach Notification Act; staff said the law and federal grant rules make written policies and training a priority and the council voted to receive the report.

The Okaloosa County Information Technology Council met April 20 and reviewed a proposed county policy package to formalize security-awareness training across county offices, prompted by a recent amendment to the state’s Security Breach Notification Act.

John Lacey, who presented the packet, said the amended law requires ‘‘reasonable safeguards’’ — including risk assessments, layered technical and physical defenses, employee training and an incident‑response plan — and warned that failure to adopt such safeguards could expose the county to liability. Lacey cited a civil‑penalty figure mentioned in the discussion of about $75,000 and said enforcement could be pursued by a district attorney’s office or the attorney general.

Lacey also told the council that federal funding programs, including the CISA state and local cybersecurity grant program and the FEMA Homeland Security grant program, include eligibility requirements for written policies; those grants, he said, can help counties that lack existing policies to implement them.

Council members asked whether departments that already run comparable training (for example, CJIS awareness for sheriff’s staff or state training used by court clerks) would be exempt. Lacey said the draft currently requires MIS‑provided training for all users but that an exemption provision could be added and that a central reporting mechanism for completed training would aid audits and oversight.

Members also sought timing details. Lacey identified the state bill referenced in the meeting as Senate Bill 626 (2025 session) and said he believes some provisions took effect Jan. 1; he committed to confirming exact statutory effective dates and grant deadlines so the council can prioritize implementation.

After discussion, a member moved to receive Lacey’s report covering agenda items 2 through 11; the motion was seconded and approved by voice vote. The council did not adopt the draft policies at the meeting, and Lacey and members said further department review and edits are expected before any formal adoption vote.

The council’s next steps are to clarify statutory deadlines, firm up grant timing and circulate the draft policies for department comment and redlines prior to a future meeting.