Comment Submitted by City of Santa Rosa
AnonymousSupportGovernment
Summary: A local government entity (city) provides feedback on the State and Local Cybersecurity Grant Program (SLCGP), highlighting how the funds helped them acquire patch management solutions, vulnerability scanners, and network hardware. They express support for the program while noting the need for sustained funding and more eligibility opportunities for cities to maintain their cybersecurity posture.
3. How have SLT government recipients leveraged new technology and cybersecurity tools to mitigate cybersecurity threats and incidents?
The city's cybersecurity program has been extremely underfunded, preventing the advancement and implementation of new controls and refreshing aging equipment. Some of the biggest highlights of the grant's impact has been helping the city acquire and operationalize a patch management solution, acquire a vulnerability scanner and establish regular scans and also refresh EOL/EOS switches while migrating to a new platform that will allow the city to move to a new level of segmentation. These highlighted solutions the grant funded will help reduce the city's overall attack surface and also the span of an attack.
4. What SLCGP funded interventions were most effective at mitigating threats and ensuring continuity of SLT government operations?
So far, the patch management solution has been fully operationalized and has allowed the city to bring operating systems to current and effectively managing 3rd party patches. These processes have eliminated thousands of medium and high severity vulnerabilities.
5. What barriers, if any, are preventing the entities from utilizing the grant funds?
No barriers for the received grant, we have already exhausted all the funds. This being said, it's very difficult to find one-time / CapEx cybersecurity solutions to purchase so without sustaining future budget the grant's value could be limited. This caused us to carefully think the solutions selected to ensure we could long-term sustain the capabilities. Also, the city could definitely use more grants to continue progressing its cyber posture but it seems like the city is no longer eligible since it received one award.
6. To what extent are SLT grant recipients using the knowledge gained from SLCGP technical assistance and/or products to prevent cybersecurity incidents?
Addressing countless vulnerabilities across the network leveraging the newly acquired patch management solution is definitely preventing cyber incidents. One the new switches and new segmentation is fully implemented, this solution will also help minimize the spread of an incident should one take place.
7. To what extent do regular ongoing phishing training, awareness campaigns; and role-based cybersecurity training for SLT government employees contribute to a reduction in cybersecurity incidents?
With a limited cybersecurity budget, continual training and testing of the city's end-user population has been a critical component to raise awareness and help turn all city users into frontline defenders. Attacks targeting users have increased and with elevated awareness, we have also seen an increase in emails reported as suspicious allowing us to investigate and address similar occurrences across the city.