Audit Objective
Did the Town of Wilton (Town) Town Comptroller (Comptroller) adequately safeguard network and cloud-based user account access from cybersecurity threats?
Audit Period
January 1, 2024 – August 8, 2025
Understanding the Audit Area
Adequate user account access safeguards are essential to ensuring that only authorized individuals can access town systems and data. Weak safeguards increase the risk of unauthorized access and activity, data loss, operational disruptions, financial loss, compromise of personal, private or sensitive information (PPSI),1 and legal and reputational repercussions.
The Town had 56 full-time and 13 part-time employees during the audit period. The Town’s network environment consisted of 77 enabled user accounts and 132 computer accounts. In addition, the Town had 110 enabled cloud user accounts which are used for email access. The Town uses a third-party IT vendor to help oversee the IT environment. The Comptroller is responsible for the Town's website, and ensuring the services provided by the IT vendor are performed adequately in accordance with the vendor contract. The Comptroller, along with the IT vendor, is also responsible for establishing controls over network and cloud-based user account access.
Audit Summary
Town officials did not adequately safeguard network and cloud-based user account access from cybersecurity threats. As a result, Town officials cannot be assured that IT systems are secured and protected against unauthorized use, access, manipulation and loss.
The Comptroller did not ensure that user accounts across the Town’s network and cloud environments were adequately monitored. We determined that 18 employee accounts and four service2 and shared accounts were unnecessary and should have been disabled. These accounts exposed the Town’s IT assets to an increased risk of unauthorized access, misuse or disruption. Also, the Comptroller did not utilize the IT Vendor to establish and implement a systematic account review process to help ensure that only necessary network and cloud account access remained enabled. The inadequate monitoring and oversight weakened accountability and could lead to difficulties attributing IT system activity to specific individuals.
Furthermore, the Comptroller did not develop a password policy for the Town Board (Board) to adopt.
Without effective safeguards, including adequate user account management and written guidance to communicate expectations and current cybersecurity industry standards for configuring and selecting passwords, the risk of a successful cyberattack is significantly increased, particularly given the Town’s use of cloud-based services for email communications. Cloud-based systems are directly exposed to the Internet, magnifying the risk of compromise when user account safeguards are inadequate. Cyberattack effects can include IT system downtime and disruption, the inability to provide services reliant on network and cloud-based resources, data theft (exfiltration) or corruption by malicious actors, and increased remediation and recovery costs.
Sensitive IT control weaknesses were communicated confidentially to officials.
The report includes five recommendations that, if implemented, will improve the Town’s network and cloud-based user account access safeguards from cybersecurity threats. Town officials agreed with our findings and indicated they plan to initiate corrective action.
We conducted this audit pursuant to Article V, Section 1 of the State Constitution and the State Comptroller’s authority as set forth in Article X, Section 5 of the State Constitution. Our methodology and standards are included in Appendix C.
The Board has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report should be prepared and provided to our office within 90 days, pursuant to Section 35 of the New York State General Municipal Law. For more information on preparing and filing your CAP, please refer to our brochure, Responding to an OSC Audit Report, which you received with the draft audit report. We encourage the Board to make the CAP available for public review in the Town Clerk’s office.
1 PPSI is any information to which unauthorized access, disclosure, modification, destruction or use – or disruption of access or use – could have or cause a severe impact on critical functions, employees, customers, third-parties or other individuals or entities.
2 Service accounts are created for the sole purpose of running a particular network or system service or application. For example, service accounts can be created and used for automatic backups.