My WebLink
|
Help
|
About
|
Sign Out
Browse
Search
AgdaPkt 2020-12-21 Amended Joint SA PFA
RedwoodCity
>
City Clerk
>
Agenda Packets
>
2020-2029
>
2020
>
AgdaPkt 2020-12-21 Amended Joint SA PFA
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
1/5/2021 12:51:59 PM
Creation date
12/18/2020 5:45:35 PM
Metadata
Fields
Template:
CC Index
CC Index - Document Type
Agenda Packet
Meeting Type
Joint
Agency Type
City Council and Successor Agency and Public Financing Authority
Date
12/21/2020
Jump to thumbnail
< previous set
next set >
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
1000
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
Show annotations
View images
View plain text
6.D. - Page 9 of 33 <br />IT <br />1.4 Ransomware: <br />It Is Not Enough To Think You Are Protected <br />ISSUE <br />City and county government computer systems are at risk of Ransomware attacks. Are adequate <br />measures being taken by local government agencies to mitigate the risks and provide recovery <br />options? <br />SUMMARY <br />Ransomware has already hit many governmental Information Technology (IT) systems in San <br />Mateo County. In December 2019 the Grand Jury sent an online survey to all 68 public entities <br />in San Mateo County,' received 37 survey responses (a 54% response rate), and interviewed <br />several responders including one IT Manager (who had refused to respond to the survey for fear <br />of being successfully attacked once again), for a total of 38 responses via survey and interview. <br />More than 25% (10 of 38) of the public entities responding to the Grand Jury reported that they <br />have been a victim of one or more Ransomware attacks. More concerning is the certainty that <br />there will be more attempts to violate the integrity of our local governments' electronic <br />infrastructure. <br />This report is intended to present "best practices" in developing a Cybersecurity strategy, then <br />implementing and testing that plan. It addresses actions that can be taken (and have been taken, <br />in some cases) in order to guard against Ransomware attacks, recover from an attack and the <br />additional measures that can be taken to reduce the possibility of an attack. However, it is not an <br />expose with details of potential system weaknesses, in light of the need for Cybersecurity <br />strategies and practices to be highly confidential. As such, this report walks the line between <br />providing an informed discussion of potential concerns without providing a road map of how to <br />breach public government IT systems. <br />The single largest exposure every organization has to cyber -thieves is phishing, the illegal <br />practice of sending legitimate -looking emails to an organization's employees. These emails may <br />contain malware or links that, when clicked, infect the computer with a virus that can spread to <br />the entire information systems network. <br />Although many email software programs include some level of protection against Ransomware <br />attacks, such protections require customization and activation, and it is not clear that local public <br />entity IT departments are undertaking these necessary customization and activation steps. In <br />addition, training for new employees and recurring training for existing employees is critical to <br />dramatically reducing the probability of a Ransomware infection. In some agencies, it appears <br />' See Appendix F: Public Entities in San Mateo County (Cities, County, School Districts, Special Districts) <br />2019-2020 San Mateo County Civil Grand Jury <br />130 <br />
The URL can be used to link to this page
Your browser does not support the video tag.