Laserfiche WebLink
6.D. - Page 15 of 33 <br />This detailed example represents a well thought out and highly prepared plan, executed with <br />precision. The first breach resulted in 41/2 hours of downtime as 12 servers were infected. The <br />second breach resulted in 6 1I2 hours of downtime to recover 19 affected servers. The IT team <br />was able to recover the servers and their data both times, become fully operational within hours, <br />and the organization did not pay any ransom demands. <br />Grand Jury Cybersecurity Survey and Follow-up Interviews <br />Survey question:23 "Has your Organization had a Ransomware attack? Specifically, has there <br />been an instance or multiple instances when an attack has locked up a computer or computers <br />and presented a demand for ransom to unlock the infection?" <br />Nine survey responders and one non -survey responder interviewee, a total of 10 of 38 (37 <br />responders to the online survey and one non -survey responder) affirmed an attack had occurred <br />or had possibly occurred in their organization, a 26% "hit" rate. The circumstances of their <br />attacks were reviewed.24 The non -survey interviewee was the IT manager from a public entity in <br />the County who was unwilling to complete the survey because they did not want to reveal that <br />their organization had been subject to "one or more" Ransomware attacks. Nor were they <br />willing to disclose how successful the Ransomware attack(s) were for fear that they would open <br />themselves up to more attacks. <br />Survey Question:25 <br />"Is your Information Systems Budget adequate to secure your network properly from malicious <br />attack? " <br />Thirty-two of the 37 survey respondents, or 86%, answered Yes to this question. This high <br />percentage of "Yes" responses either indicates a high level of confidence in their defense setup, a <br />reluctance to complain about their IT budget, or as two of our follow-up interviewees revealed26, <br />a lack of understanding of the complexity of a well-written, well -executed Cybersecurity P1an.27 <br />Suggesting the latter, The National League of Cities conducted a similar survey of 165 city <br />governments nationwide and asked the same question, ("Is your budget adequate enough to <br />secure your networkproperly?'): 67% replied "No". 28 <br />Investigation Results Regarding Backup/Restore/Maintenance <br />The Grand Jury survey and follow-up interviews revealed that, while many local agencies have <br />backup plans,29 only a portion of those same agencies had successfully recovered lost files from <br />backups and none of the survey responders had ever done a full restore of a server.30 When an <br />23 Appendix A — Question #1 <br />24 Grand Jury Interview <br />25 Appendix A — Question #2 <br />26 Grand Jury Interviews <br />27 Federal Communications Commission, Cyber Security Planning Guide, October 2012. <br />28 National League of Cities report, Protecting Our Data: What Cities Should Know About Cybersecurity, page 8 <br />29 Appendix A — Question 93 <br />30 Appendix A — Question #4 <br />2019-2020 San Mateo County Civil Grand Jury 7 <br />136 <br />