Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Information Security topic
No spam. Unsubscribe anytime.
Town attorney says vendor review found no IT wrongdoing; vendor recommends shared mailboxes and clearer transition policies
Summary
At a Belgrade Select Board meeting, a town attorney statement said a review with the town’s IT contractor found no evidence of misconduct in prior handling of the town’s IT systems; the contractor recommended role‑based shared mailboxes, clearer credential‑removal procedures, and selective PC backups.
Get email alerts on the Information Security topic
No spam. Unsubscribe anytime.
The Belgrade Select Board heard a statement from the town attorney and a presentation from the town’s IT contractor about the town’s information systems, including a review prompted by allegations at a previous meeting. The attorney’s statement said the issues involved allegations directed at an identifiable employee that should have been discussed in executive session and reported that the town’s review with its IT vendor “found no evidence of wrongdoing.”
The IT contractor summarized steps to reduce transition risks and improve continuity. The vendor emphasized using role‑based shared mailboxes (for example, townclerk@ or townmanager@) so that named employees keep a personal account while the shared mailbox remains assigned to the role. The contractor said shared mailboxes do not consume additional named‑user licenses and simplify deactivation when employees depart.
The contractor also reported that the town’s server is backed up and that most town machines follow a recommended four‑to‑five‑year replacement cycle; the contractor identified two older machines with limited use. On credential removal, the vendor said deactivation must be coordinated: the town should notify the vendor when an employee leaves so the vendor can trigger access restrictions promptly. The presenter recommended the board adopt clearer written policies for transition and computer use and offered sample policy language and implementation support.
Board members asked whether the server had capacity to stop staff from saving files locally and whether the vendor could back up individual PCs for critical town roles; the vendor said both are feasible, that some public PCs can be reset nightly, and that backing up a small set of key desktops is technically straightforward. The contractor noted a tradeoff between security and day‑to‑day efficiency and recommended the select board identify who is authorized to request changes or authorizations in writing.
The meeting’s public record also included procedural remarks that the town will treat the previously discussed personnel allegations as confidential and handle them in personnel processes; the attorney’s statement emphasized the confidentiality requirement and the plan to develop policies to clarify expectations during staff transitions.
The board did not vote on policy changes at the meeting; the contractor said they would provide quotes and sample policies to the board for consideration at a future meeting.

