databreaches.net 6 Sept 2026, 11:54 UTC

New York Audits Expose Cybersecurity Gaps in Three Towns

CyberSIXT Evidence Panel Source marked as original reporting

NEW York State Comptroller DiNapoli has published further municipal cybersecurity audits, covering the Town of Wilton and the villages of Cassadaga and Lacona. The audits, covering periods from 2024 into 2025, found governance and access-control weaknesses that left IT assets and data vulnerable to misuse or disruption. Wilton, which relies on a third-party IT vendor, had 77 enabled user accounts, 132 computer accounts and 110 cloud email accounts.

The audit concluded that network and cloud account access were not adequately monitored, with 18 employee accounts and four service/shared accounts deemed unnecessary and should have been disabled. There was also no established password policy for the Town Board, and no systematic account-review process to ensure only necessary access remained enabled.

In Cassadaga, eight full‑time and 11 part‑time staff used three computers as of October 2025, with six external IT service providers engaged for various tasks. The audit found an absent IT asset inventory and weak governance, increasing the risk of loss, misuse or exposure of financial data and other PPSI. Lacona reported six employees and three computers, with two external IT service providers.

Its audit highlighted no written IT policies, no cybersecurity awareness training for staff, and no IT contingency plan to mitigate data loss or operational disruption. In each case, the findings point to governance gaps and inadequate controls; the full reports are available via the Comptroller’s and NY OSC sites for detailed recommendations and evidence.

View full article

Article by CyberSIXT