Audit Objective
Did City of Oneonta (City) officials provide adequate governance to safeguard information technology (IT) assets from cybersecurity threats?
Audit Period
January 1, 2024 – November 7, 2025
Understanding the Audit Area
City officials should provide adequate cybersecurity governance to protect IT assets, ensure operational continuity, safeguard personal, private or sensitive information (PPSI),1 reduce the risk of cyber incidents and financial losses, comply with legal obligations and maintain public confidence.
During the audit period, the City paid an external IT service provider $222,752 to perform various IT services, including hardware maintenance and repair, security services and other IT support services. The City had 188 employees and 106 computers as of July 2025.
Audit Summary
City officials did not provide adequate governance to safeguard IT assets from cybersecurity threats. While the City’s third-party IT vendor created several cybersecurity policies, standards and guidelines, the City’s Common Council (Council) did not formally adopt the policies and City officials did not review, enforce or monitor employee compliance with the policies. In addition, officials did not communicate the policies to City employees in a timely manner, and they did not clearly document cybersecurity roles and responsibilities in City employees’ job descriptions. As a result, policy violations occurred, including officials not documenting risk assessment activities and employees not completing cybersecurity awareness training within 30 days of hire.
Without effective cybersecurity governance, including Council-adopted and enforced policies, clearly documented roles and responsibilities, risk assessment documentation and cybersecurity awareness training, the City is at an increased risk of a successful cyberattack. Cyberattack effects can include IT system downtime and disruption, the inability to provide services reliant on IT assets, data exfiltration or corruption by malicious actors, and increased remediation and recovery costs. In addition, unclear job descriptions may lead to decreased efficiency of cybersecurity efforts, overreliance on individuals and inadequate segregation of duties. Cybersecurity governance weaknesses may also lead to ineffective cybersecurity risk management and inefficient incident response, which could potentially result in unauthorized access to City IT assets and data.
Sensitive IT control weaknesses were communicated confidentially to officials.
The report includes seven recommendations that, if implemented, will improve the City’s cybersecurity governance, improve accountability for cybersecurity responsibilities, enhance compliance with adopted policies and reduce the risk of unauthorized access, data loss and disruption of critical IT services. City officials disagreed with certain aspects of our findings, and their response is included in Appendix B. Our comments on the City’s response are included in Appendix C.
This audit was conducted pursuant to Article V, Section 1 of the State Constitution and the Office of the New York State Comptroller’s (OSC’s) authority as set forth in Article 3 of the New York State General Municipal Law (GML). The audit’s methodology and standards are included in Appendix D.
The Council has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report should be prepared and provided to OSC within 90 days, pursuant to Section 35 of GML. For more information on preparing and filing the CAP, please refer to the OSC brochure, Responding to an OSC Audit Report, which was provided with the draft audit report. The Council is encouraged to make the CAP available for public review in the City Clerk’s (Clerk's) office.
1 PPSI is any information to which unauthorized access, disclosure, modification, destruction or use – or disruption of access or use – could have or cause a severe impact on critical functions, employees, customers, third-parties or other individuals or entities.