Audit Objective
Did the Village of Lacona (Village) Board and Village officials (officials) provide adequate governance to safeguard information technology (IT) assets from cybersecurity threats?
Audit Period
June 1, 2024 – October 3, 2025
Understanding the Audit Area
Village officials should provide adequate cybersecurity governance to protect IT assets; ensure operational continuity; safeguard personal, private or sensitive information (PPSI);1 reduce the risk of cyber incidents and financial losses; comply with legal obligations; and maintain public confidence.
Village officials engaged two external IT service providers during the audit period to perform various IT services, including hardware maintenance and repair, security services and other IT support services. The Village had six employees and three computers (two desktops and a laptop) as of October 2025.
Audit Summary
The Board and officials did not provide adequate governance to safeguard IT systems from cybersecurity threats. The Board and officials did not develop or adopt written IT policies, provide employees with cybersecurity awareness training or develop an IT contingency plan to help minimize the risk of data loss or suffering a serious operational interruption. As a result, the Board and officials cannot be assured that Village IT systems and PPSI contained therein are secured and protected from unauthorized use, access, manipulation and loss. The Board and officials also have minimal assurance that, in the event of a disruption or disaster (e.g., a ransomware attack), employees and other parties would be able to react quickly and effectively to help resume, restore and report critical IT systems failures or data breaches in a timely manner.
Without effective cybersecurity governance, including Board-adopted and enforced policies, clearly documented roles and responsibilities and cybersecurity awareness training, the Village is at an increased risk of a successful cyberattack. Cyberattack effects can include IT system downtime and disruption, the inability to provide services reliant on IT assets, data theft (exfiltration) or corruption by malicious actors, and increased remediation and recovery costs. Cybersecurity governance weaknesses may also lead to ineffective cybersecurity risk management and inefficient incident response, which could potentially result in unauthorized access to Village IT assets and data.
Sensitive IT control weaknesses were communicated confidentially to officials.
The report includes four recommendations that, if implemented, will improve the Village’s cybersecurity governance and IT system safeguards. Village officials agreed with our findings and recommendations and indicated they plan to initiate corrective action.
We conducted this audit pursuant to Article V, Section 1 of the State Constitution and the Office of the New York State Comptroller’s (OSC) authority as set forth in Article 3 of the New York State General Municipal Law. Our methodology and standards are included in Appendix C.
The Board has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report should be prepared and provided to our office within 90 days, pursuant to Section 35 of the New York State General Municipal Law. For more information on preparing and filing your CAP, please refer to our brochure, Responding to an OSC Audit Report, which you received with the draft audit report. We encourage the Board to make the CAP available for public review in the Village Clerk-Treasurer’s (Clerk-Treasurer) office.
1 PPSI is any information to which unauthorized access, disclosure, modification, destruction or use – or disruption of access or use – could have or cause a severe impact on critical functions, employees, customers, third-parties or other individuals or entities.