The county’s IT/treasury representative briefed the committee on information‑security practices and an emerging approach to artificial‑intelligence tools.
The speaker said backups are stored offsite and that the county follows incident‑response procedures when staff inadvertently open suspicious messages. He described a recent incident that was contained because the exploit targeted software the county does not use. The county uses multifactor authentication in several areas and plans to expand MFA in 2027.
On AI, the IT speaker said the county currently does not have an AI policy and that access to public AI platforms is blocked to reduce the risk of exposing protected health or other sensitive data. "We do not currently have an AI policy. Um, we are blocking access to all AI," he said, adding that the county administrator has proposed forming an AI committee of staff to determine departmental needs and risks before adopting a policy.
The committee asked whether routine cybersecurity training, phishing tests and offsite backups are in place; the speaker confirmed backups are stored offsite and said policy details and incident procedures are available to supervisors in offline briefings to avoid exposing security details in a public session.
Next steps: IT staff will continue to roll out MFA, pursue careful policy development for AI use, and offer one‑on‑one discussions about incident response and sensitive‑data handling.