{"id":207,"date":"2024-06-10T16:14:00","date_gmt":"2024-06-10T16:14:00","guid":{"rendered":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/?p=207"},"modified":"2024-07-23T16:16:55","modified_gmt":"2024-07-23T16:16:55","slug":"committee-on-technology-holds-oversight-hearing-on-cybersecurity-of-nyc-agencies","status":"publish","type":"post","link":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/2024\/06\/10\/committee-on-technology-holds-oversight-hearing-on-cybersecurity-of-nyc-agencies\/","title":{"rendered":"COMMITTEE ON TECHNOLOGY HOLDS OVERSIGHT HEARING ON CYBERSECURITY OF NYC AGENCIES"},"content":{"rendered":"<p class=\"has-text-align-center\"><strong>The hearing comes on the heels of both public and private concerns including <\/strong><a href=\"https:\/\/www.chalkbeat.org\/newyork\/2023\/6\/23\/23772027\/nyc-student-data-breach-security-moveit-department-education-hack\/\"><strong>recent data breaches<\/strong><\/a><strong> to <\/strong><a href=\"https:\/\/www.nytimes.com\/2023\/12\/21\/business\/rite-aid-ai-facial-recognition.html\"><strong>FCC barring Rite Aid from utilizing facial recognition technologies&nbsp;<\/strong><\/a><\/p>\n<p><strong>New York, New York, June 10, 2024 <\/strong>\u2013 The New York City Council\u2019s Committee on Technology held a crucial hearing on the cybersecurity of New York City agencies, focusing on safeguarding critical infrastructure and New Yorkers\u2019 personal data following cyberattacks in recent years on City agencies and their vendors, including the <a href=\"https:\/\/nypost.com\/2024\/05\/05\/us-news\/over-380k-more-nyc-students-had-info-leaked-bringing-total-to-over-1m\/\">Department<\/a> of <a href=\"https:\/\/www.chalkbeat.org\/newyork\/2023\/6\/23\/23772027\/nyc-student-data-breach-security-moveit-department-education-hack\/\">Education<\/a>, <a href=\"https:\/\/www.beckershospitalreview.com\/healthcare-information-technology\/nyc-health-hospitals-switching-from-change-healthcare.html\">Health + Hospitals,<\/a> and <a href=\"https:\/\/www.politico.com\/news\/2024\/04\/02\/new-york-city-payroll-system-has-been-down-for-a-week-following-phishing-attack-00150198\">NYCAPS<\/a>.&nbsp;<\/p>\n<p>The Committee sought updates from the Adams Administration on cybersecurity measures mandated by Executive Orders 28 and <a href=\"https:\/\/www.nyc.gov\/office-of-the-mayor\/news\/003-002\/executive-order-3\">3<\/a>, and Local Law 89 of 2020. However, despite this technology and cybersecurity reorganization, centralization, and publicly announced prioritization of these systems, there have been multiple breaches of City systems that have affected thousands of New Yorkers.&nbsp;<\/p>\n<p>Representatives from the Office of Technology and Innovation (OTI) Chief Information Security Officer for Cyber Command Kelly Moan and Office for Legal Matters Deputy Commissioner Chantal Senatus testified, emphasizing the omnipresence of zero-day vulnerabilities and the processes in place to address them. OTI mentioned that they &#8220;work collaboratively with agencies to determine what data is impacted&#8221; in the event of a breach, but would not provide specific details. Social engineering was noted as a key threat, and OTI highlighted their \u201croutine\u201d engagement in identifying issues and promoting cyber maturity. However, OTI was unable to specify how often audits occur, only mentioning they are conducted &#8220;periodically.&#8221;<\/p>\n<p>While acknowledging efforts such as the <a href=\"https:\/\/manhattanda.org\/ccsi\/\">NYC Cyber Critical Services and Infrastructure Project (CCSI)<\/a> established in 2019, the Committee expressed disappointment with OTI&#8217;s inability to provide concrete information about specific actions they take to protect City systems, citing the public nature of the hearing. Committee members across the ideological spectrum acknowledged the need for confidentiality regarding certain security details, but concurred in expressing concern regarding OTI\u2019s lack of substantive responses.<\/p>\n<p>The Committee also heard several bills related to facial recognition, biometric technology, and data privacy. OTI declined to provide feedback on the bills, noting that they did not have jurisdiction, without sharing which agency would be responsible for implementation and providing feedback. OTI&#8217;s representatives also could not provide clarity on which agency is responsible for oversight of this technology, leaving members of the Committee and the public without a resource to report issues of civil rights and other concerns. As the committee has previously observed, despite the Administration\u2019s elevation of OTI as a priority, there are many instances in which the omnipresence of technology appears to preclude any particular agency from taking responsibility.&nbsp;<\/p>\n<p>The Committee appreciates OTI&#8217;s commitment to enhancing cybersecurity and the dedicated cybersecurity workforce across the City, but today\u2019s hearing showed significant gaps in communication and accountability that must be addressed to ensure the security and privacy of New Yorkers.<\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>The hearing comes on the heels of both public and private concerns including <\/strong><a href=\"https:\/\/www.chalkbeat.org\/newyork\/2023\/6\/23\/23772027\/nyc-student-data-breach-security-moveit-department-education-hack\/\"><strong>recent data breaches<\/strong><\/a><strong> to <\/strong><a href=\"https:\/\/www.nytimes.com\/2023\/12\/21\/business\/rite-aid-ai-facial-recognition.html\"><strong>FCC barring Rite Aid from utilizing facial recognition technologies&nbsp;<\/strong><\/a><\/p>\n<p><strong>New York, New York, June 10, 2024 <\/strong>\u2013 The New York City Council\u2019s Committee on Technology held a crucial hearing on the cybersecurity of New York City agencies, focusing on safeguarding critical infrastructure and New Yorkers\u2019 personal data following cyberattacks in recent years on City agencies and their vendors, including the <a href=\"https:\/\/nypost.com\/2024\/05\/05\/us-news\/over-380k-more-nyc-students-had-info-leaked-bringing-total-to-over-1m\/\">Department<\/a> of <a href=\"https:\/\/www.chalkbeat.org\/newyork\/2023\/6\/23\/23772027\/nyc-student-data-breach-security-moveit-department-education-hack\/\">Education<\/a>, <a href=\"https:\/\/www.beckershospitalreview.com\/healthcare-information-technology\/nyc-health-hospitals-switching-from-change-healthcare.html\">Health + Hospitals,<\/a> and <a href=\"https:\/\/www.politico.com\/news\/2024\/04\/02\/new-york-city-payroll-system-has-been-down-for-a-week-following-phishing-attack-00150198\">NYCAPS<\/a>.&nbsp;<\/p>\n<p>&#8230;<\/p>\n<p><strong><small><a href=\"https:\/\/council.nyc.gov\/jennifer-gutierrez\/2024\/06\/10\/committee-on-technology-holds-oversight-hearing-on-cybersecurity-of-nyc-agencies\/\">READ MORE<\/a><\/small><\/strong><\/p>\n","protected":false},"author":232,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[71],"tags":[25,116,115,117,15],"class_list":["post-207","post","type-post","status-publish","format-standard","hentry","category-tech","tag-committee-on-technology","tag-cybersecurity","tag-facial-recognition-technologies","tag-nyc-cyber-critical-services-and-infrastructure-project-ccsi","tag-oti"],"_links":{"self":[{"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/posts\/207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/users\/232"}],"replies":[{"embeddable":true,"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/comments?post=207"}],"version-history":[{"count":0,"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/posts\/207\/revisions"}],"wp:attachment":[{"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/media?parent=207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/categories?post=207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/council.nyc.gov\/jennifer-gutierrez\/wp-json\/wp\/v2\/tags?post=207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}