By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Denver lacks comprehensive approach to cybersecurity risks, city auditor says
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Politics > Denver lacks comprehensive approach to cybersecurity risks, city auditor says
Politics

Denver lacks comprehensive approach to cybersecurity risks, city auditor says

By admin 5 Min Read
Share
SHARE

Denver lacks a comprehensive program to assess potentially disastrous cybersecurity risks, City Auditor Tim O’Brien said in a new report.

The city’s current approach can best be described as “informal,” O’Brien said, particularly when it comes to oversight of independent city agencies or cultural facilities — like the Denver Art Museum and Denver Zoo — that operate on subnetworks tied into the city’s broader system.

O’Brien cataloged his office’s findings in an audit report released Thursday.

The report is the product of a review of city data, processes and planning efforts over two years — from Jan. 1, 2022, through Dec. 31, 2023.

The audit team found that city staff did not consistently complete quarterly mandatory cybersecurity training. The city also lacks a specific training regime for employees responsible for citywide information technology risk management.

O’Brien is urging Denver Technology Services — the city department tasked with overseeing and managing all physical and virtual technology that touches the city’s network — to overhaul its approach and create clear guidelines for how every wing of city government handles data and technology risks.

“Through awareness of cybersecurity risks and clear expectation-setting for appropriate use of technology, the city can trust its employees to do their part in protecting data and information,” O’Brien said in a statement.

The auditor’s office recommended seven steps that Technology Services should take to remedy Denver’s shortcomings.

Those include:

  • Developing a citywide risk assessment process
  • Developing risk management training
  • Creating information-exchange agreements that would require independent agencies and facilities to share information about high-level technology risks with the department

Sumana Nallapati, Denver’s chief information officer, accepted all seven recommendations in a response letter sent to the auditor’s office on June 7. Mayor Mike Johnston hired her in September.

Many facets of what O’Brien recommends are already underway, Nallapati wrote in her response letter.

“(Technology Services) intends to create a robust and holistic organizational risk management structure identifying roles, responsibilities, documentation, risk assumption, identification of training for necessary roles and escalation processes associated to technical risk,” Nallapati wrote in part.

Her letter acknowledged the administration’s limited power to influence independent city agencies. While Technology Services accepted the recommendation to pursue information exchange agreements, Nallapati wrote that her department plans to reach out to independent agencies to see whether they would be willing to sign memorandums of understanding — or MOUs — focused on risk assessment.

“(Technology Services) cannot commit to a completion date for any such efforts, or that a successful MOU will ever be reached,” she wrote.

The audit report cites officials with Denver County Court as specifically asserting that they have the legal authority to operate independently as the judicial branch of city government. Court officials argue that they should not be required to formally communicate potential cyber security risks to Technology Services, the report says.

“But this assertion of independence with limited collaboration undermines the greater good of protecting the city from costly and damaging cyberattacks…” the audit team wrote.

Denver’s approach leaves the city more vulnerable to equipment failures, service disruptions and cyberattacks, the auditor’s office found. Those risk factors could cost Denver millions of dollars per day if any of them were ever to lead to full city network failure, according to the report.

In a statement to The Denver Post, Nallapati said her department is “committed to working across the city enterprise on continuous improvement of technology risk management strategies.”

Colorado has seen its share of high-profile cyberattacks in recent years.

In 2018, a ransomware attack temporarily knocked the Colorado Department of Transportation’s back-end operations offline. It cost the state between $1 million and $1.5 million just to bring the agency’s functionality back to 80% of normal in the months that followed.

Earlier this year, a cyberattack hobbled the Office of the Colorado State Public Defender and delayed hundreds of court hearings. The agency acknowledged that personal data including clients’ Social Security numbers may have been compromised during that episode.

Stay up-to-date with Colorado Politics by signing up for our weekly newsletter, The Spot.

You Might Also Like

US Allows Sanctions Waiver on Russian Oil to Expire

Illinois Health Officials Investigate Possible Hantavirus Case Not Linked to Cruise Ship

‘Perverted’ Forced Organ Harvesting Gets Spotlight in Congress

Trump Says China Giving ‘Serious Consideration’ to Free Pastor

House Ties 212–212 on Iran War Powers Resolution

TAGGED: Politics
Share This Article
Facebook Twitter Copy Link
Previous Article One dead and hundreds of homes destroyed in US Midwest floods
Next Article Ease the Burden with AI-Driven Threat Intelligence Reporting
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
Tech News
Markets supported by liquidity, but valuations running ahead of fundamentals: Sameer Dalal
Business
ECHO token plunges after $76M admin key exploit hits protocol
Crypto
Malaysia seeks €216m compensation from Norwegian firm over scrapped missile deal
World News
Crypto Hack Hits Echo As Monad’s eBTC Market Faces Fallout
Crypto
The Blood of Dawnwalker Promises A “Lot of Reactivity” to Player Choices in Quests
Gaming News
Gas Networks Ireland to connect Cork waste-to-energy plant to national gas grid
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?