Comment Submitted by Costa Mesa Sanitary District

AnonymousOtherGovernment
Summary: The Costa Mesa Sanitary District provides a response to a request for information regarding the State and Local Cybersecurity Grant Program (SLCGP). They describe how they have used the funding to implement security technologies like XDR, DNS filtering, and security awareness training, while noting staffing and supply chain issues as primary barriers.
3. How have SLT government recipients leveraged new technology and cybersecurity tools to mitigate cybersecurity threats and incidents? The Costa Mesa Sanitary District has leveraged SLCGP funding to significantly strengthen its cybersecurity posture through the implementation of multiple layered security technologies. Most notably, the District expanded its Extended Detection and Response (XDR) capabilities to provide continuous monitoring and advanced threat detection across endpoints, email, cloud applications, and mobile devices. These enhancements improve the District's ability to identify, investigate, and respond to malicious activity before it can disrupt operations. 4. What SLCGP-funded interventions were most effective at mitigating threats and ensuring continuity of SLT government operations? Several SLCGP-funded initiatives have significantly improved the District's cybersecurity maturity and operational resilience. The expansion of our XDR platform has provided enhanced visibility, real-time threat detection, and faster incident response across our environment. The implementation of DNS filtering has reduced exposure to malicious websites, phishing attacks, and command-and-control communications by blocking access to known malicious domains before connections can be established. Dark web credential monitoring has enabled proactive identification of compromised user credentials, allowing the District to reset passwords and mitigate account compromise before unauthorized access occurs. In addition, the implementation of a more comprehensive security awareness training program has strengthened our human firewall by increasing employee awareness of phishing, social engineering, and other cyber threats. Strategic cloud migrations have improved system resilience, security, and recoverability while reducing reliance on aging on-premises infrastructure. Finally, upgrading endpoints to Windows 11 has enhanced security through modern operating system protections, improved compatibility with current cybersecurity tools, and continued vendor support. 5. What barriers, if any, are preventing the entities from utilizing the grant funds? The primary barriers to fully utilizing SLCGP grant funding have been staffing limitations and supply chain constraints. During the grant period, the District experienced some turnover in key IT personnel, which reduced our capacity to manage and oversee multiple cybersecurity projects simultaneously. Additionally, procurement delays and backorders for hardware extended implementation timelines for some initiatives. Despite these challenges, the District has continued to make steady progress and adjusted implementation schedules to ensure grant objectives continue to be met. 6. To what extent are SLT grant recipients using the knowledge gained from SLCGP technical assistance and/or products to prevent cybersecurity incidents? The District has actively incorporated the knowledge and best practices gained through SLCGP technical assistance into its long-term cybersecurity strategy. These resources have informed the development of a more mature, risk-based cybersecurity program focused on implementing layered security controls, strengthening governance, and aligning with recognized cybersecurity frameworks and best practices. As foundational security capabilities are established, the District is shifting its focus toward validating the effectiveness of those controls through testing, continuous monitoring, incident response planning, and ongoing security improvements. This progression enables the District to move beyond reactive cybersecurity measures toward a proactive and resilient security program designed to prevent, detect, and respond to evolving cyber threats. 7. To what extent do regular ongoing phishing training, awareness campaigns, and role-based cybersecurity training for SLT government employees contribute to a reduction in cybersecurity incidents? These are among the most effective administrative controls for reducing cybersecurity incidents. Because employees are frequently targeted through phishing emails, business email compromise attempts, and other forms of social engineering, ongoing education significantly increases their ability to recognize suspicious activity and respond appropriately. Combined with technical security controls, these efforts serve as a critical layer of defense that strengthens the District's overall cybersecurity posture and supports uninterrupted delivery of our essential public services.

View on Regulations.gov