New York State Audit Is Critical of City’s Cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


(TNS) — An audit conducted by the office of state Comptroller Thomas DiNapoli found that the city of Oneonta did not provide adequate governance to safeguard information technology assets from cybersecurity threats, according to a report issued Oct. 2.

As a result, policy violations occurred, including officials not documenting risk assessment activities and employees not completing cybersecurity awareness training within 30 days of hire, a summary of the report stated.

The audit period covered Jan. 1, 2024 to Nov. 7, 2025.


“City officials should provide adequate cybersecurity governance to protect IT assets, ensure operational continuity, safeguard personal, private or sensitive information (PPSI), reduce the risk of cyber incidents and financial losses, comply with legal obligations and maintain public confidence,” the summary stated. “Without effective cybersecurity governance, including Council-adopted and enforced policies, clearly documented roles and responsibilities, risk assessment documentation and cybersecurity awareness training, the City is at an increased risk of a successful cyber attack.”

During the audit period, the city paid an external IT service provider — which was not identified in the report — $222,752 to perform various IT services, including hardware maintenance and repair, security services and other IT support services. The city had 188 employees and 106 computers as of July 2025.

While the city’s third-party IT vendor created several cybersecurity policies, standards and guidelines, the Common Council did not formally adopt the policies, and city officials did not review, enforce or monitor employee compliance with the policies, the summary stated.

In addition, officials did not communicate the policies to city employees in a timely manner, and they did not clearly document cybersecurity roles and responsibilities in city employees’ job descriptions.

Sensitive IT control weaknesses were communicated confidentially to officials, the summary stated.

RECOMMENDATIONS FOR IMPROVEMENT

The report included seven recommendations to improve the city’s cybersecurity governance. The council has the responsibility to initiate corrective action, and written corrective action plan should be prepared and provided to the comptroller’s office within 90 days, the summary stated.

City officials disagreed with some aspects of the audit report findings.

A letter dated Aug. 6 from City Clerk Kerri Harrington acknowledged that some cybersecurity practices could have been better documented, centralized and communicated, and stated that the city has started to address those issues. However, she disagreed with the draft report’s suggestion that weak documentation meant that the underlying cybersecurity activities did not occur.

She said that the audit team was going to review the city’s cybersecurity policy requirements from the 2022 policy, but the draft report relied on provisions or wording from the 2025 policy, which had not been placed into effect or enforced yet.

In response, the audit stated that the report was updated to more clearly identify the applicable criteria for the findings, but noted that “because the Council did not adopt policies, some City departments were unclear about which policies to follow, which could lead to inconsistent cybersecurity practices among City staff.”

“The City’s response is not intended to minimize the importance of formal governance, complete documentation, explicit communication, or accountability,” the letter stated. “Rather, it asks that the final report accurately distinguish among: (1) activities that did not occur; (2) activities that occurred but were not centrally or sufficiently documented; and (3) practices that were operationally implemented but not authorized through the particular approval or job description mechanism OSC expected.”

The full audit report and summary can be found at https://tinyurl.com/mr3ayy7h.

©2026 The Daily Star, Distributed by Tribune Content Agency, LLC.



——————————————————-


Click Here For The Original Source.