IT Audit
New York State Comptroller Releases New Municipal Cybersecurity Audits Highlighting Local Deficiencies
A series of municipal IT audits released by the New York State Comptroller spotlights recurring gaps in local government cybersecurity posture. Organizations must implement standard access controls and routine risk assessments to prevent unauthorized access.
Background and Audit Findings
New York State Comptroller Thomas P. DiNapoli has published a fresh batch of municipal audit reports, focusing specifically on cybersecurity controls in local government entities such as the Town of Wilton. Across several jurisdictions, the audits examined access control mechanisms, user account lifecycle management, disaster recovery readiness, and employee security awareness training covering operational periods through mid-2025.
The findings point out persistent weaknesses that frequently afflict municipal and public sector entities. Common oversights include unmanaged administrator privileges, lack of multi-factor authentication (MFA) across internal systems, outdated software inventories, and inconsistent data backup testing. Without adequate controls, these municipal systems remain susceptible to ransomware deployment and data exfiltration.
FORTSECURE GLOBAL Recommendations for Local Governments
To remediate these compliance gaps and lower exposure to cyber threats, municipal IT teams should take the following strategic steps:
- Implement the Principle of Least Privilege: Regularly audit privileged active directory accounts and decommission inactive accounts immediately upon employee departure.
- Mandate Multi-Factor Authentication: Enforce MFA across all administrative consoles, remote access pathways, and email services to mitigate credential-based intrusions.
- Establish Routine Internal Audits: Adopt standardized frameworks such as the NIST Cybersecurity Framework (CSF) or CIS Critical Security Controls to systematically evaluate infrastructure resilience.
- Conduct Disaster Recovery Exercises: Test offline and cloud backups quarterly to guarantee business continuity during a ransomware emergency.
แหล่งที่มา: DataBreaches.net เผยแพร่ครั้งแรก: Sun, 06 Sep 2026 11:54:51 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: DataBreaches.net
เผยแพร่ครั้งแรก: Sun, 06 Sep 2026 11:54:51 +0000
บทความต้นฉบับ: https://databreaches.net/2026/09/06/nys-comptroller-dinapoli-releases-more-municipal-cybersecurity-audits/
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
