Connect with us

Denver, CO

Denver lacks comprehensive approach to cybersecurity risks, city auditor says

Published

on

Denver lacks comprehensive approach to cybersecurity risks, city auditor says


Denver lacks a comprehensive program to assess potentially disastrous cybersecurity risks, City Auditor Tim O’Brien said in a new report.

The city’s current approach can best be described as “informal,” O’Brien said, particularly when it comes to oversight of independent city agencies or cultural facilities — like the Denver Art Museum and Denver Zoo — that operate on subnetworks tied into the city’s broader system.

O’Brien cataloged his office’s findings in an audit report released Thursday.

The report is the product of a review of city data, processes and planning efforts over two years — from Jan. 1, 2022, through Dec. 31, 2023.

Advertisement

The audit team found that city staff did not consistently complete quarterly mandatory cybersecurity training. The city also lacks a specific training regime for employees responsible for citywide information technology risk management.

O’Brien is urging Denver Technology Services — the city department tasked with overseeing and managing all physical and virtual technology that touches the city’s network — to overhaul its approach and create clear guidelines for how every wing of city government handles data and technology risks.

“Through awareness of cybersecurity risks and clear expectation-setting for appropriate use of technology, the city can trust its employees to do their part in protecting data and information,” O’Brien said in a statement.

The auditor’s office recommended seven steps that Technology Services should take to remedy Denver’s shortcomings.

Those include:

Advertisement
  • Developing a citywide risk assessment process
  • Developing risk management training
  • Creating information-exchange agreements that would require independent agencies and facilities to share information about high-level technology risks with the department

Sumana Nallapati, Denver’s chief information officer, accepted all seven recommendations in a response letter sent to the auditor’s office on June 7. Mayor Mike Johnston hired her in September.

Many facets of what O’Brien recommends are already underway, Nallapati wrote in her response letter.

“(Technology Services) intends to create a robust and holistic organizational risk management structure identifying roles, responsibilities, documentation, risk assumption, identification of training for necessary roles and escalation processes associated to technical risk,” Nallapati wrote in part.

Her letter acknowledged the administration’s limited power to influence independent city agencies. While Technology Services accepted the recommendation to pursue information exchange agreements, Nallapati wrote that her department plans to reach out to independent agencies to see whether they would be willing to sign memorandums of understanding — or MOUs — focused on risk assessment.

“(Technology Services) cannot commit to a completion date for any such efforts, or that a successful MOU will ever be reached,” she wrote.

The audit report cites officials with Denver County Court as specifically asserting that they have the legal authority to operate independently as the judicial branch of city government. Court officials argue that they should not be required to formally communicate potential cyber security risks to Technology Services, the report says.

Advertisement

“But this assertion of independence with limited collaboration undermines the greater good of protecting the city from costly and damaging cyberattacks…” the audit team wrote.

Denver’s approach leaves the city more vulnerable to equipment failures, service disruptions and cyberattacks, the auditor’s office found. Those risk factors could cost Denver millions of dollars per day if any of them were ever to lead to full city network failure, according to the report.

In a statement to The Denver Post, Nallapati said her department is “committed to working across the city enterprise on continuous improvement of technology risk management strategies.”

Colorado has seen its share of high-profile cyberattacks in recent years.

In 2018, a ransomware attack temporarily knocked the Colorado Department of Transportation’s back-end operations offline. It cost the state between $1 million and $1.5 million just to bring the agency’s functionality back to 80% of normal in the months that followed.

Advertisement

Earlier this year, a cyberattack hobbled the Office of the Colorado State Public Defender and delayed hundreds of court hearings. The agency acknowledged that personal data including clients’ Social Security numbers may have been compromised during that episode.

Stay up-to-date with Colorado Politics by signing up for our weekly newsletter, The Spot.



Source link

Denver, CO

Pedestrian fatally hit by Frontier airplane departing Denver for Los Angeles, flight canceled after

Published

on

Pedestrian fatally hit by Frontier airplane departing Denver for Los Angeles, flight canceled after


A Frontier plane fatally struck a pedestrian in Denver as it was taking off for Los Angeles Friday night, according to the airline and Denver International Airport. Authorities say the pedestrian jumped the fence and crossed the active runway where they were pulled into the aircraft’s engine.



Source link

Continue Reading

Denver, CO

A Frontier plane hits a pedestrian during takeoff at Denver airport

Published

on

A Frontier plane hits a pedestrian during takeoff at Denver airport


Posted:

Updated:

Advertisement

DENVER (AP) — A Frontier Airlines plane hit a pedestrian on the runway of the Denver International Airport during takeoff, airport authorities said, sparking an engine fire and forcing passengers to evacuate.

The plane, on route from Denver to Los Angeles International Airport, “reported striking a pedestrian during takeoff at DEN at approximately 11:19 p.m. on Friday,” the airport’s official X account wrote.

Neither the airport nor the airline has disclosed the pedestrian’s condition.

“We’re stopping on the runway,” the pilot tells the control tower according to the site ATC.com. “We just hit somebody. We have an engine fire.”

The pilot tells the air traffic controller they have “231 souls” on board and that and “individual was walking across the runway.”

Advertisement

The air traffic controller responds that they are “rolling the trucks now” before the pilot tells the tower they “have smoke in the aircraft. We are going to evacuate on the runway.”

Frontier Airlines said in a statement flight 4345 was the one involved in the collision and that “smoke was reported in the cabin and the pilots aborted takeoff.” It was not clear whether the smoke was linked to the crash with the pedestrian.

“The Airbus A321 was carrying 224 passengers and seven crew members,” the airline said. “We are investigating this incident and gathering more information in coordination with the airport and other safety authorities.”

Passengers were then evacuated via slides and the emergency crew bused them to the terminal.

Denver Airport said the National Transportation Safety Board had been notified and that runway 17L, where the incident took place, will remain closed while an investigation is conducted.

Advertisement



Source link

Continue Reading

Denver, CO

Denver’s playoff flop didn’t cost David Adelman. The roster, though, could be wide open

Published

on

Denver’s playoff flop didn’t cost David Adelman. The roster, though, could be wide open


The president and governor of the Denver Nuggets said Friday his faith in coach David Adelman remains strong despite the team’s first-round flop in the playoffs but he indicated a roster overhaul could happen just as much as the team running it back largely intact. “I have full faith in Coach Adelman,” Josh Kroenke said at a news conference at Ball Arena. The Nuggets finished third in the Western Conference at 54-38, behind Oklahoma City and San Antonio.



Source link

Continue Reading
Advertisement

Trending