Melrose Council Search

← Appropriations & Oversight Committee · 2018-09-06 · Appropriations and Oversight Committee Meeting

ORDER-2019-5 : Acceptance of a Cyber Security Grant in the amount of $20,000.

Passed · OUGHT TO PASS [7 TO 0] Yes: Jennifer L. Lemmerman, Scott M. Forbes, Peter D. Mortimer, John N. Tramontozzi, Manisha Bewtra, Kate Lipper-Garabedian, Shawn M. MacMaster. Absent: Robert A. Boisselle, Francis X. Wright Jr., Monica C. Medeiros.

Agenda original PDF

No further agenda text.

Minutes original PDF

ORDER-2019-5 Grant Acceptance of a Cyber Security Grant in the amount of $20,000. Recommend Passage Board of Aldermen City of Melrose Page 1 Updated 9/12/2018 9:35 AM

All documents for this meeting on the city portal

Transcript (~18 min @ 1:07:42)

Speakers identified by voice; unnamed voices are numbered within this recording. Auto-caption text — verify against the video.

▶ 1:07:42 Scott M. Forbes: passing this resolution this evening i appreciate it thank you

▶ 1:07:46 Jennifer L. Lemmerman: we have a motion made and seconded all in favor aye aye aye any opposed this order will be recommended to the full board meeting later this evening the next item on our agenda this evening

▶ 1:07:57 Jennifer L. Lemmerman: is order 2019-5 acceptance of a cyber security grant in the amount of twenty thousand dollars

▶ 1:08:05 Peter D. Mortimer: Motion to suspend the rules that we may hear from our Director of Informational Services.

▶ 1:08:10 Speaker 4: Second the motion.

▶ 1:08:11 Jennifer L. Lemmerman: We have a motion to suspend the rules made by Alderman Mortimer, that's seconded by Alderman Forbes. All in favor of suspension? Aye. Any opposed? We are now under suspension of the rules and we are joined this evening by our Information Technology Director, Mr. Ellis. Thank you for being here. Would you like to give us just a brief rundown of this grant before we move to questions?

▶ 1:08:30 Speaker 4: Sure. So the grant was initially The George Pazos, my predecessor, initially found the grant and worked with Mike Lindstrom to get it moving and I kept it going. I furthered the paperwork and what not. We recently undertook a whole cyber security

▶ 1:08:58 Speaker 4: assessment of the entire network inside and out. And this grant accepted would pay for that cyber security assessment. It's incredibly comprehensive. They really, really get down to the nitty gritty. It's really granular. They found things that we knew they would find. Things that we didn't think they would, well, we didn't know that they were out there. So they found them. It was basically broken down into a few phases. The first was the open source intelligence reconnaissance. Basically, they scanned the dark web for usernames and passwords that may have been picked up by employees of the city. And they did find quite a few for different platforms, like Facebook or Twitter or they may have logged into something at some point in an insecure network that something was picked up and then in they know that people use the same passwords across the board that they if they would use them for Facebook they might use it for their account here thankfully they weren't successful in getting into our network using any of those passwords and username so that was good but as a result of that we could step up our game on the password complexity move toward password phrase is just more complexity in that the second thing was external vulnerability trying to get in from the outside they did a penetration test that came out

▶ 1:10:52 Speaker 4: well as well the the one caveat on that is that they couldn't do like a really brutal attack on us given that they didn't want to disrupt our network or any of our services in-house by really you know going for broke so what they could do in normal testing they couldn't they couldn't get in but they did find some vulnerabilities that we can we can work on the phase four was wireless security they did a wireless security they only find one with two flaws that we've already fixed that were kind of minor social engineering was the basically was a phishing test I don't know if you know what phishing is basically send emails to people that look like they're from me really what they did they said they made a new web a new you a new domain on the on the internet basically that was called city of and they made it our nl rose org so that they are in the end if you look at it quickly looks like an M so they sent an email for me to people I know it's sneaky but I mean that's what that's real that's real life you know so saying that they needed to log in to a website uh and they mocked up a website that looked like it would be our a website for us or whatever and they needed to log in with their username and password uh i think 15 people responded i don't know if they were able to get any passwords out of that we rated really highly on that uh so that was that was that was basically the the top five they gave us a you know comparative results to other towns and cities or municipalities that were similar in size and number of employees and that kind of thing and the write-up was quite extensive and you know there were definitely definitely things that that they found that we're gonna need to put a lot of effort into possibly funding I don't know how we would fix all right to give you an example I mean and it gets really nitty-gritty but there were 8,000 pages of things to look at and read I mean it wasn't 8,000 pages of specifically specific vulnerabilities was a lot of it was descriptions on what they found why it can be and that could go for pages but it was 8,000 pages I mean to try to and it's growing you know every day every day we have somebody finds another vulnerability in our software you know every day we have software not every day but very often we

▶ 1:13:47 Speaker 4: have software that goes out of out of maintenance so their end-of-life programs even Microsoft Office our server we have servers that run still have servers that we need to change over from 2000 2003 2008 2008 is still under um it's not end of life but it's 10 years out of date we're constantly patching it so uh you know we can't really afford at the moment to upgrade a lot of those servers because you know we just don't have the funds to pay for a new license um or hardware to put them on so from that standpoint we're kind of in trouble but uh yeah it was a great eye-opening project to go through the entire

▶ 1:14:38 Speaker 4: process so any questions does anyone have any questions so this was a state

▶ 1:14:46 Kate Lipper-Garabedian: grant that we received and I'm just when you were referring to they who who was

▶ 1:14:54 Speaker 4: doing all of these different okay so so he plus was the hired contractor there are a state vendor they have a subcontractor they have a person in in-house who does, who's actually a Melrose resident. Very highly credentialed and he worked with us to try to figure out what we wanted to kind of see. We're looking for what to attack. They do the regular attacks if there's anything specific that we want to have looked at. And they subcontract with a security vendor who can, who has all the tools and staff to really attack it. Because a company like E-plus might not have, really that doesn't make sense for them to have all these people because they don't do security every day, all day long, and these companies do so, yeah.

▶ 1:15:49 Kate Lipper-Garabedian: And was this a competitive grant that we were awarded or was this something that the state agency provided to municipalities on the common law?

▶ 1:15:58 Speaker 4: It was a competitive grant as far as I know from the, from the, like I said I wasn't there at the outset. I believe it was a, a, a community, um, uh, competitive grantor, a community, yeah.

▶ 1:16:12 Speaker 4: Okay.

▶ 1:16:17 Speaker 4: Uh, I can tell you in a second, is a community compact, best practice program.

▶ 1:16:20 Kate Lipper-Garabedian: Great. Well, um, I'm glad that we were a recipient of a competitive award and, um, it sounds like there we got some real value out of the work that we we had done so thank

▶ 1:16:37 Manisha Bewtra: you for presenting that just curious what kind of like training did any training come with this for staff or other training that you have available to city employees and others who use the city network in terms of recognizing increasing security risks, things like that.

▶ 1:16:56 Speaker 4: That's a good question. No, we did the, I thought that it might. But when we actually got down to what the money would cover from the process of just getting through the network and seeing what we had for vulnerabilities, it ate up the whole $20,000 and the subsequent report that they created for us.

▶ 1:17:25 Speaker 4: So I guess in order to do that, we could do in-house training based on the things. One of the things that I'm definitely going to do here in the city and for the schools, because a lot of the stuff that they found on the city side transfers over to the schools. It's basically the same network, is create policies for security. And that can get into other things. I've written a policy that we need to, for the fobs and just physical security that we need to get through other things like things we should and shouldn't do. I think we need a policy like we do on the schools that I wrote this year for social media and use because a lot of that comes into how do you how do you use your electronics in-house and out again passwords make sure you don't use the same password change your passwords often even for things outside here because they do impact us inside so definitely policies I'm gonna be working on a lot of policies for security and we'll try to get some training in there as well thank

▶ 1:18:41 Manisha Bewtra: you just curious I mean I it's been amazing to see how more clever and sneaky some of these emails are so even those of us who might consider ourselves savvy fall for it sometimes so it's good to know some of those tips and tricks just like what you should look for when you open up your inbox that kind of

▶ 1:19:06 Peter D. Mortimer: thing but thank you I will yield to all of them look at reading okay thank you very much so this $20,000 has been spent yes so this is just pro forma for us to be making a recommendation for passage and then passage later on at the full board of acceptance of this grant yes I apologize that it's it's it's all right

▶ 1:19:33 Speaker 4: I'm just late I in and others when I took the role of CIO from what I was told the money was already accepted in an account and then when i went looking for it to pay for when we were in the process and doing the and i was talking to the state as well and they were like oh no you need to you need to get this going you need to have a contract in order to keep this going for another two years if you want to renew it because i had started in in the it you know we hadn't done the grant and it needed to be done so i didn't need to elongate it and uh I assume that the money was already in our coffers, but essentially that stuff had never been done before, so yeah, I apologize that it's-

▶ 1:20:20 Peter D. Mortimer: That's all right. No, it's all right. I can understand how the situation occurred, but essentially it's pro forma. We're just going through some motions here tonight on the financial side. It's nice to get the explanation for the benefit of the public, and there's no matching on this. There's no matching on that.

▶ 1:20:42 Peter D. Mortimer: they did guarantee us the funds though right so we don't have to dip into the city coffers to match anything and uh just so people might realize i mean obviously this is a very serious issue in terms of security and i'm not sure whether or not it was before you arrived to work at the city of melrose but and i'm not telling tales out of school because it was in the newspaper but there was a time and i think it was about five or six years ago when some cyber gangsters hacked into our system and demanded to be paid off to the tune of $5,000 in Bitcoin, and we paid them. We paid them. And that's no joke. They shook us down, and they got us.

▶ 1:21:26 Speaker 4: It has happened.

▶ 1:21:27 Peter D. Mortimer: And in Bitcoin, too. Yeah, Bitcoin. It's pretty... Thankfully, it was only $5,000, but on the other hand, it was $5,000. Oh, yeah, I know.

▶ 1:21:43 Speaker 4: it's you don't want to it has uh it basically what happened there uh in that case was that it was loaded into an email and it was clicked on which which unloaded a payload into the system that has happened twice again thankfully when i started i stepped up the backup process So that when it occurred, again, through the police department, we were able to go back about a half hour before the attack and roll all of those files back to wipe out what was infected. And we couldn't get access to those files. So we were able to just roll it back a half hour, clean everything. And then we made, we kind of got ahead of the process by locking down all the files and folders to individual people in departments so that whoever, if the person is part of a department, whatever they have access to will get affected. So say it's the police department, only the police department files will get affected and not the whole entire city's files. that's also true of locking down user users to like specific folders what they have access to

▶ 1:23:10 Speaker 4: computers making sure that they don't have administrative rights to other things that they they don't need to as long as they're a user it shouldn't spread beyond what they

▶ 1:23:25 Peter D. Mortimer: have access to so and just so the public can see where all this good work went on those two subsequent attempts no extortionate demands were paid off no so burn me one shame on me burn me twice and they didn't burn us twice no we took care of it excellent excellent job thank you very much madam chair that's all I have

▶ 1:23:52 Jennifer L. Lemmerman: motion recommend second sure I just and thinking about the conversation you had

▶ 1:23:57 Kate Lipper-Garabedian: with Alderman Bewtra I'm sure you're aware that the governor created a new executive office of technology services and security and I just returned to work from maternity leave yesterday and found that I needed to do a new cybersecurity training that had a lot of really good videos and questions and I expect that EOTS is also creating some model templates of policies so perhaps that would be a point that you don't have to recreate the wheel you might I'm happy to follow up with you on that but you also could probably find some things on

▶ 1:24:34 Speaker 4: their website there is a home there is a a matching grant program that's not cybersecurity but it's physical security that we're looking into at the schools

▶ 1:24:50 Speaker 4: that's that's another Baker started a program for a matching grant for scary So, we'll try to apply for that as well. Thank you.

▶ 1:25:01 Jennifer L. Lemmerman: Seconded to recommend this order for passage.

▶ 1:25:02 Speaker 6: Any further discussion?

▶ 1:25:06 Speaker 5: All in favor? Aye. Any opposed?

▶ 1:25:12 Jennifer L. Lemmerman: This order will be recommended for passage in just a few moments in our full board meeting. And you're welcome to stay. You don't have to.