Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Mount Vernon considers mandatory cyber training and AUP to qualify for MMA insurance

Mount Vernon Select Board · June 16, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Town IT presented a draft acceptable‑use policy and proposed phishing‑simulation training, recommending the town complete MMA cybersecurity eligibility steps and consider a paid training platform to reduce vulnerability and gain insurance coverage.

Mount Vernon’s IT presenter outlined a draft acceptable‑use policy (AUP) and urged the Select Board to adopt staff training and testing to reduce cybersecurity risk and secure MMA cyber‑insurance.

Presenter Scott recommended a program that combines short online training with periodic simulated phishing emails. He noted low per‑user subscription costs and a larger first‑year rollout could be affordable: "It's not if we get hacked, it's when it is," he told the board, framing training as a preventive measure.

Scott described KnowBe4 as an example phishing‑simulation platform and said the platform runs about $3.75 per user per month; he also provided an early, higher aggregate estimate for budgeting and suggested a quarterly refresh and phishing tests to measure improvement. The town discussed alternatives including using MMA resources, federal guidance, or managing training internally to reduce recurring subscription costs.

The presenter also recommended pursuing MMA’s cyber‑insurance by completing MMA’s qualification checklist; if the town meets MMA’s controls, cyber coverage is often available as part of MMA membership. Board members asked for cost and migration estimates for a possible email domain change and asked staff to return with a draft AUP, a recommended training cadence, and an estimate for any software or administrative costs.

Next steps: IT will draft a policy for board review, obtain MMA’s cyber‑insurance form, and return with cost estimates and an implementation plan for training and any required IT changes.