Laserfiche WebLink
6.D. - Page 13 of 33 <br />o Paying for enrollments in credit reporting bureaus to stop or correct identity thefts <br />(from the release of previously confidential or secure personal information) for <br />client/customers. <br />o Replacing hardware and/or software. <br />• Indirect Costs: <br />o Operations efforts to restore systems and data; <br />o Organizational downtime as well as employee overtime; <br />o Reputation loss including negative public relations and loss of confidence by the <br />organizations' constituents; <br />o Liabilities for legal costs, including defense of lawsuits for breach of private and <br />confidential information and poor handling of personal data. <br />According to the Coveware Report, 17 the median ransom payment in the first quarter of 2020 <br />was $44,021. This was an increase of roughly 10% over the last quarter of 2019. Public sector <br />entities represented 12% of attacks, about half of which were school systems. The average days <br />of downtime was 15 representing an alarming number of days of inability to service <br />constituents. 18 This underlines an urgent need to understand and evaluate current local <br />governments' Cybersecurity strategies. <br />The discussion that follows is intended to encourage local public agencies and their IT staff to <br />confidentially evaluate their respective Cybersecurity plans, software and prevention strategies. <br />Since data and systems security are essential to the operation of every public entity in the <br />County, the discussion will not present a specific road map for potential Ransomware-prevention <br />actions but rather establish a "best practice model" that will enhance understanding of the <br />elements essential for an adequate protection plan. <br />DISCUSSION <br />In December 2019, the Grand Jury developed an online survey that was sent to all 68 public <br />entities in San Mateo County. 19 Responses were received from 37 of the entities (a 54% <br />response rate). Additionally, follow-up interviews were conducted with three local public IT <br />Managers, one of whom had refused to complete the online survey for fear of disclosing <br />confidential information that could lead to a successful malware or Ransomware attack. These <br />interviewees were questioned regarding the adequacy of Cybersecurity planning and execution. <br />Following a general analysis of local government practices, this report concludes with a review <br />of Cybersecurity best practices which local agencies should consider adopting. <br />Two Ransomware Attacks Derailed: Best Practices in Action <br />In order to better understand how to successfully defeat a Ransomware attack, the Grand Jury <br />interviewed an IT Manager of a private enterprise that was attacked twice by Ransomware and <br />was able to fully restore the environment and re-establish workflow within just a few hours. <br />17 https://%%ww.coveware.com/blog/gi-2030-ransomware-marketplace-report <br />18 Ii tips://www.msspalert.com/Cybersecurity-research/average-ransomware-aaymeiit-rises-main-research/ <br />19 Appendix F <br />2019-2020 San Mateo County Civil Grand Jury <br />134 <br />