Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Fraud Cybersecurity topic
No spam. Unsubscribe anytime.
Woodland Hills gets fraud and cybersecurity briefing from state municipal insurer
Summary
On July 14 the city received a training from the Utah Local Government Trust on fraud prevention and cyber risks, including a live demo of a social‑engineering takeover and recommended controls such as segregation of duties, fraud risk assessments and vendor verification.
Get email alerts on the Fraud Cybersecurity topic
No spam. Unsubscribe anytime.
On July 14, Woodland Hills city council received a training session from the Utah Local Government Trust intended to help elected officials and staff reduce fraud and cybersecurity risk.
Josh McHale, identified himself as the Trust’s risk finance consultant, opened the session and introduced Mike Stack, the Trust’s loss‑prevention manager and the city’s assigned risk manager. Stack told the council that fraud often follows a predictable pattern — the "fraud triangle" of opportunity, pressure and rationalization — and that local governments are vulnerable when internal controls are weak.
"Public trust is the foundation of effective government," Stack said. "Any kind of fraud within the organization is going to divert funds away from services and projects you want to do." He listed common municipal schemes, including payroll manipulation, vendor procurement fraud, expense‑reimbursement abuse and IT/data compromises, and said the state auditor’s fraud‑risk assessment is a useful baseline tool.
The presenters demonstrated how quickly an attacker can gain access if a user clicks a malicious link. In a role play shown to the council, a staffer clicked a prompt and presenters said an attacker could take control of a computer in under two minutes. The Trust recommended that vendors be verified by a single, trusted city contact and that staff use phone verification rather than relying solely on email.
"Trust, but verify," Stack said, urging officials to call a vendor contact directly before moving money or changing payment instructions.
McHale said the Trust insures the majority of Utah cities and aims to help members shore up controls before claims occur. He described programs the Trust uses for members that show frequent claims and recommended the council consider a formal fraud‑risk assessment, better segregation of duties, whistleblower protections and an incident response plan.
Council members asked about AI‑enabled voice spoofing and other modern tactics; Stack said the answer remains vigilance and verification, and recommended designating a single staff member with strong vendor relationships who can make confirmation calls.
The council and staff said they will follow up: the city’s internal controls and an auditor presentation are expected on a future agenda to continue the work raised in the Trust briefing.

