Audit Objective
Did the Village of Cassadaga (Village) Village Board (Board) and officials provide adequate governance to safeguard information technology (IT) assets from cybersecurity threats?
Audit Period
June 1, 2024 – October 1, 2025
Understanding the Audit Area
Village officials should provide adequate cybersecurity governance to protect IT assets, ensure operational continuity, safeguard personal, private or sensitive information (PPSI),1 reduce the risk of cyber incidents and financial losses, comply with legal obligations and maintain public confidence.
Village officials engaged six external IT service providers during the audit period to perform various IT services, including printer support, hardware maintenance and repair, security services and other IT support services. The Village had eight full-time and 11 part-time employees and three computers as of October 2025.
Audit Summary
The Board and Village officials did not provide adequate governance to safeguard IT assets from cybersecurity threats. Because the Board and officials did not establish and maintain a comprehensive IT asset inventory, they could not effectively track these assets through their lifecycle. Additionally, policy, oversight and other internal control weaknesses increased the risk that IT assets and the data contained in IT systems could be lost, damaged or compromised. As a result, the Village’s financial data and other PPSI was at increased risk of unauthorized use, access, manipulation and loss, which could lead to financial loss and operational interruptions.
Without effective cybersecurity governance, including Board-adopted and enforced policies and IT contingency plan, and cybersecurity awareness training, the Village is at an increased risk of a successful cyberattack. Cyberattack effects can include IT system downtime and disruption, the inability to provide services reliant on IT assets, data theft (exfiltration) or corruption by malicious actors, and increased remediation and recovery costs. Cybersecurity governance weaknesses may also lead to ineffective cybersecurity risk management and inefficient incident response, which could potentially result in unauthorized access to Village IT assets and data.
Sensitive IT control weaknesses were communicated confidentially to officials.
The report includes eight recommendations that, if implemented, will improve the Village’s cybersecurity governance and IT asset safeguards. Village officials agreed with our findings and indicated they plan to initiate corrective action.
We conducted this audit pursuant to Article V, Section 1 of the State Constitution and the Office of the New York State Comptroller’s (OSC) authority as set forth in Article 3 of the New York State General Municipal Law. Our methodology and standards are included in Appendix C.
The Board has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report should be prepared and provided to our office within 90 days, pursuant to Section 35 of the New York State General Municipal Law. For more information on preparing and filing your CAP, please refer to our brochure, Responding to an OSC Audit Report, which you received with the draft audit report. We encourage the Board to make the CAP available for public review in the Clerk-Treasurer’s office.
1 PPSI is any information to which unauthorized access, disclosure, modification, destruction or use – or disruption of access or use – could have or cause a severe impact on critical functions, employees, customers, third-parties or other individuals or entities.