Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Greenwich IT officials say cybersecurity spending rose to support remediation, upgrades and 24/7 monitoring
Summary
Town of Greenwich IT leaders told budget reviewers the town’s cybersecurity budget has grown sharply in recent years to fund remediation work, new resiliency projects and an around-the-clock security operations service, and they said any significant breaches were discussed previously in executive session.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
At a budget-review meeting, Tom Klein, the Town of Greenwich chief information officer, told committee members that the town’s cybersecurity spending has increased substantially in recent years as the IT department scales remediation, resiliency upgrades and incident response.
"We're remediating and bringing cyber security into pretty much everything we're doing," Klein said, describing three spending buckets: ongoing remediation work, upgrades to resiliency (for example additional VPNs and disaster‑recovery improvements), and incident-response activity tied to the town’s security operations center (SOC) vendor.
Committee members noted that combining two cyber-related budget lines (51460 and 51461) showed an increase from about $180,000 in fiscal 2022 to roughly $855,000 for fiscal 2027. A committee member asked whether that five-fold rise reflected reclassification from capital to operations or new vendor hours; Klein said the increase is a mixture of both and that the department has shifted some cyber work from capital to operational spending while also absorbing more vendor and engineering hours.
Klein said the town uses a vendor-supplied 24/7 SOC that raises alerts and requires the town’s cyber engineers to respond. "We have a 7 by 24, 365 SOC our vendor supplies," he said, adding the vendor’s monitoring activity can consume engineering time when events must be investigated.
When committee members asked whether any significant security breaches had occurred, Klein said any incidents had been handled and discussed in the audit committee’s executive session and were not being briefed in the public session.
Klein also told the committee the town uses cooperative purchasing vehicles (state and federal cooperative contracts such as TIPS) to buy cyber services and that, while he expects activity to remain elevated, he does not anticipate asking for substantially more funds next year beyond the current plan.
The discussion underscored three practical consequences: (1) cyber considerations now factor into most infrastructure changes, which increases project labor and review time; (2) the town is relying on third-party SOC services that shift costs toward recurring vendor monitoring and engineering response; and (3) public disclosure about specific incidents is limited because some matters were reviewed in executive session.
Next steps discussed at the meeting included continued tracking of cyber spend by line item, using cooperative contracting where possible, and further departmental coordination to prioritize remediation and resiliency work.

