San Mateo County Logo
File #: 20-962    Version: 1 Name:
Type: Memo Status: Passed
File created: 11/2/2020 Departments: COUNTY MANAGER
On agenda: 12/8/2020 Final action: 12/8/2020
Title: Approve the Board of Supervisors' response to the 2019-2020 Civil Grand Jury Report, "Ransomware: It is Not Enough to Think You Are Protected"
Special Notice / Hearing: None__
Vote Required: Majority

To: Honorable Board of Supervisors
From: Michael P. Callagy, County Manager
Subject: Board of Supervisors' Response to the 2019-2020 Civil Grand Jury Report "Ransomware: It is Not Enough to Think You Are Protected"

RECOMMENDATION:
title
Approve the Board of Supervisors' response to the 2019-2020 Civil Grand Jury Report, "Ransomware: It is Not Enough to Think You Are Protected"

body
BACKGROUND:
On October 7, 2020, the 2019-2020 San Mateo County Civil Grand Jury issued a report titled "Ransomware: It is Not Enough to Think You Are Protected." The Board of Supervisors is required to submit comments on the findings and recommendations pertaining to the matters over which it has some decision-making authority within 90 days. The Board's response to the report is due to the Honorable Danny Y. Chou no later than January 5, 2021.

DISCUSSION:
The Grand Jury made 8 findings and 4 recommendations in its report. The Board responses follow each finding and the 4 recommendations that the Grand Jury requested that the Board respond to within 90 days.


FINDINGS

Finding 1:
Ransomware is a real and growing threat to public entities including those in San Mateo County.

Response: The respondent agrees with the finding.

Finding 2:
Across the country, local governments and schools represent 12% of all Ransomware attacks.

Response: The respondent agrees with the finding.

Finding 3:
The direct and indirect costs of Ransomware can be significant.

Response: The respondent agrees with the finding.

Finding 4:
Cybersecurity reviews and assessments, and an updated, well-executed Cybersecurity plan are critical components of IT security strategy.

Response: The respondent agrees with the finding.

Finding 5:
A comprehensive Cybersecurity plan should include, at a minimum, information concerning prevention steps, spam and malware software, and backups and full recovery te...

Click here for full text