Board of Supervisors - Special Meeting

Thursday, July 9, 2026

The Board of Supervisors held a special meeting to discuss a potential cybersecurity event involving unauthorized access to the county's security camera server. The board voted to refer the matter to the Iowa Attorney General and DCI for independent review and to formally cancel the contract with the unauthorized vendor.

About this meeting

Government Body
Board of Supervisors
Meeting Type
Board Of Supervisors
Location
Madison County, IA
Meeting Date
July 9, 2026

Transcript

60 sections

0:00 – 1:19Speaker 4

Let's go ahead and call this special hospital closed session to order, please. May I have a roll call? Supervisor Fitch. Supervisor Stanton. Here. Supervisor Hobbs. Here. Okay. Do I have a motion to approve the Agenda to, and it's for a possible closed session pursuant to Iowa Code 21.5 to discuss information containing records in the custody of a governmental body that are confidential records pursuant to section 22.7 subsection 50. So moved. Do I have a second? I will second that. All in favor please vote aye. Aye. All opposed? Motion carries. Okay, so as you guys know, this is the next thing is to motion in closed session. I've received additional information and I no longer think that this meeting should be closed because of this information. We risk violating open meeting law. So I'd like to proceed in open session. rather than going to closed session. However, if someone wants to make a motion to go into closed session, we can certainly consider that.

1:20Speaker 5

Well, then we need to have this on Teams. It should have been.

1:24 – 7:12Speaker 4

No, we're not required to have it on Teams. So is that true? We don't have to have electronic, correct, Michael? But if we always do. As long as we've posted it. We always do. i mean i think if it's properly noticed you can go ahead and proceed another session i don't know what the practice is then but um it's fine that it was the closest okay all right so let's go ahead and um unless someone unless you two want to go well you voted against closed session so you probably want to stay open okay okay so there is a reason why um it was that there was no motion we need a motion we are we've already motioned to approve the jet oh Do you, are you saying we should move a motion to not go into closed session? I'll entertain a motion to not go into closed session. Any discussion? All in favor please vote aye. Aye. All opposed? Motion carries. We are in open session. So the original reason why I requested this closed session was because of a potential cybersecurity event that I already let you both know about. And basically on June 19th, I was advised that there were 10 failed login attempts into the vendor admin login access to our security system here. Of course, that concerned me, and I contacted our county attorney and our sheriff on that. I contacted them last week. I've never received a response from the sheriff, and the county attorney is less than... You did eventually receive a response yesterday, yeah. And that he would not be at this meeting, and that he had some feedback and referred to the county attorney. The county attorney's response was a less than professional, which is unfortunate. So the additional information I received regarding this, because I was concerned, I asked the vendor to provide me footage of what was going on here because the attempted access was on site. Unfortunately, what I saw was we had the county attorney the sheriff, and the unauthorized vendor that we removed in March accessing the server in here. So apparently there was an attempt to log in by someone who's not authorized that was clearly removed from the server in March. And it was assisted in that by our county attorney and our sheriff. So I don't know what's going on. Needless to say, I'm a little disturbed at that, and there's absolutely no reason for someone to need a vendor admin rights. Our county attorney and our county sheriff have full access to our video server because they are in law enforcement. They can download video, they can access video, they can watch things live, they can export video. The only thing they can't do, which a vendor admin can do, is change users, add users, remove users, change pass codes, delete footage, and turn on the microphone in this room. And provide audit trails. And provide audit trails, yes. So given the concern that happened in our last closed session and subsequently disclosed by members of the public, The concern about turning on an audio while we are in closed session with counsel by legal opposition, because we have outstanding legal issues, is deeply concerning to me. However, at this point, I don't know what we can do about it as a board. So I think this is something that probably needs to be referred to somebody higher up. DCI, AG, I leave it at the board's discretion. We also should probably update our policy regarding our access to the servers to make it very clear that the Board of Supervisors are the only ones that can authorize any kind of changes at all. I think that I would have thought that would have been clear, but apparently it's not clear enough. Also too, I think even though the vendor, the unauthorized vendor was already notified that the contract that was signed with them for maintenance and disability was not authorized, It was not approved by the board. It was signed by a staff member who changed their title on that contract, a title that doesn't exist. So I think what we need to do is formally notify the vendor that we want to officially cancel the contract. And I would like to ask for a refund of all fees paid because it was one of their staff members that attempted to log in to our server. and what they were clearly not authorized. So that's kind of why I wanted to, I didn't think it was appropriate to do a closed session because it's not something I want to give the appearance that we are covering up. And I'm concerned. So now you guys have all the information I do. Do you have any questions or how do you want to do it? I kind of leave it to you both now.

7:12 – 7:56Speaker 3

One point of clarification. because I dove into this after being formally notified about the situation last Thursday. This information was happened upon. It wasn't sought. There was no indication or no knowledge that someone had tried to do this, but there was a separate audit log requested from our current certified authorized vendor for this camera system. And while reviewing that information, that is when it was discovered that these additional administration attempts to log in as administrator occurred. Correct.

7:57 – 8:23Speaker 4

So I just wanted to clarify that point. All inquiry, it was an inquiry to the vendor on something else. And that's when the vendor discovered this and immediately notified me. Apparently he notified you too. Yeah. So... And I requested for more information. Did he notify the sheriff, whoever discovered this? I don't know if he did. He notified us as the board. He notified two of you as the board.

8:23Speaker 2

I think what you're asking is, did that person, the happenstance situation, would that involve the attorney or the sheriff?

8:33Speaker 3

Based on the video data that I saw, I can understand why he didn't, or if he didn't. I think we're getting off track here.

8:42 – 9:19Speaker 2

Well, actually, I just, for clarification for my notes, the situation that you're asking, that you're kind of clarifying about, because it's not clear, the vendor was doing something for one of you, and I think your question was... I don't know if he was doing anything for you. He was doing something for me. Okay, and... So then I think Diane, your question is, cause I want to make sure I get this right. You did not involve the county attorney nor the sheriff with your request.

9:20Speaker 2

Prior, prior to that, prior to it happening. Okay. So not involved.

9:24 – 10:40Speaker 4

I mean, I could surely explain why I did not do that. And I'm happy to do that. And the reason why my inquiry was because of what happened in our closed meeting, um, and subsequently disclosed by a member of the public, I wanted to make sure that those that were conflicted out of our closed meeting with legal counsel were not watching our meeting on the video and sharing that information with their clients. So I made that inquiry to make sure that no one was logged in watching our meeting on June 4th or subsequently downloading video of our meeting and sharing it with their clients. What was the result? That is none of your concern. That is not the subject of this meeting. So the subject of this meeting was the unlawful, potentially unlawful, failed logging attempts and the enabling of that by our county attorney and our county chair. Again, I don't know enough, which is why I don't think it should be on our plate. I think we need to refer it to law. But that is the reason why the original inquiry was So needless to say, I was very surprised at the 10 failed logins. One or two, I forgot the password.

10:40Speaker 5

Did you have actual existing records and reports of this? Because you're opening yourself up to some, you're making some crazy accusations.

10:49 – 11:19Speaker 4

I'm not the one opening anyone up to anything. We have someone, we have an unauthorized vendor that was given access to a suit that that was given access to a county server and they were unauthorized. That contract was not authorized. It was signed without our knowledge and committed to and not budgeted for by a staff member last year. We found out about it this year by accident when we were going out to bid for the upgraded server in the courthouse.

11:19Speaker 3

And has the resolution on March 10th where we had to be very specific.

11:25 – 13:18Speaker 4

that summit was the only authorized administrator for this camera system and people were present we've been through this before so so the only the only person that's opening themselves up is potentially that vendor why that's why and you know i want to give people the benefit of the doubt and this is why i asked the county attorney and the sheriff for more information on this so And they declined to provide that and our county attorney was a little smart about it. So, well, that's not the point here. So, at this point, we have folks that are unauthorized that are being brought into our security system, Diana, and I'm surprised you don't have an issue with that. Were you aware of this? You did not know any of this was going on? No, how would I know? I didn't know anyone was hacking into anything. No, after the fact, you know what the reason was why they were going in there, because they didn't tell us. They didn't tell me, I don't know. Okay, all right. So I'm concerned about this, but again, I don't think, because it involves two elected officials and a vendor, at the very minimum, I'd like to work on updating our policy. and making sure that everything is 100% clear because apparently somebody thinks this is okay. Refer the matter to the AG and the AG's office and the DCI and formally notify, because apparently an email isn't enough, formally notify this unauthorized vendor to cancel the contract and refund the summer. Michael, we may need to involve you on that. I don't know what your advice on that is.

13:21Speaker 1

Yeah, that's fine. I mean, I didn't make a thousand notes. I'm happy to help if it's just, you know, drafting a formal notification, drafting a formal referral, like I guess it's kind of whatever, whatever you all decide or whatever you all need.

13:32Speaker 4

Okay. So did you have anything else? Any other questions?

13:38 – 14:01Speaker 3

No, I think there are ample opportunities for, to reply and explain what happened here. There were 40 emails, 40 emails went around about this matter. So I make a motion that the Madison County Board of Supervisors refers this matter to the Iowa Attorney General and DCI for an independent review.

14:04Speaker 4

Do you want to do that as a separate motion? Do it separate. Okay.

14:07Speaker 5

You don't really have a policy. We don't really have a policy to do this. That's going to be a separate motion. That's going to be a separate motion. You're going to do this after. You're going to make policy after the fact, after you're forwarding this.

14:17Speaker 3

We're going to tighten everything down. We're going to tighten everything down.

14:20 – 14:57Speaker 4

To try to prevent this from happening again. Diane, apparently we have an outline. When we say authorized, we mean authorized. So I didn't think we had to make it any clearer. We made it very clear in March that that vendor was not authorized in this building because the contract, unauthorized contract, was signed without our knowledge. And frankly, I think they pretended that, oh, we didn't know. Well, I've been in the private sector for a long time. I negotiated hundreds of contracts. You know who the right people are. So she's worked with us for years.

14:58Speaker 3

Especially what happened, it was addressed in March, too.

15:00 – 15:13Speaker 4

It was addressed in March. So, and, you know, we directed the auditor to make sure that that happened, and I don't know what happened. For some reason, he thought it was okay to come in here.

15:13Speaker 5

What's the cost of us doing this DCI and AG? I'm just going to refer it.

15:20Speaker 3

So there's a motion on the table to refer this matter to the AG and DCI. Do I have a second?

15:29Speaker 4

Second. Any further discussion? All in favor, please vote aye.

15:35 – 15:48Speaker 5

Aye. All opposed? I'm going to say nay because, and I want the record to show, that I would like to deal with this in-house and get to it. I tried. We tried. We have 40 emails, Diane. Let's try with other people.

15:49Speaker 5

Undone. All in favor, please vote aye.

15:53 – 16:34Speaker 4

Aye. All opposed? I already said it. Okay. Okay, I'll entertain a motion now to update our security camera server policy. Currently, all it addresses is who can log in, which currently is the county attorney, the county sheriff, and the authorized vendor. Because they're law enforcement, they do need to still have access. But I think we need to make sure that it's clarified 100% that you don't have the right to get vendor access. I didn't think that was, anyway.

16:35 – 16:48Speaker 3

So question, then would we roll in cybersecurity policy to that or have a separate cybersecurity policy? We might need to treat them separately as far as the camera system versus just overall cybersecurity.

16:48 – 18:05Speaker 4

Well, the one we have right now is mostly because of open records requests. We were getting members of public asking for open records for the security camera footage. And last year, I think what the intent was is to kind of tighten that. So it's clear that who has access to log in and view it and who could authorize sharing that information as an open records request. And right now, for the open records request, the ones that can approve that are the auditor, the sheriff, the county attorney, and I think that's it. I think the Board of Supervisors can be on there. And I think we need to tighten that up regarding the actual server access. But to your point regarding cybersecurity, I know we have, do we, Refresh my memory, did we have cybersecurity language in our handbook? So I think doing a cybersecurity policy is going to be a lot more complex. What we can do is we can put that as a to-do, because the current policy I'm talking about is the one we have right now, which deals with login access and

18:07 – 18:30Speaker 3

Just to clarify, and that was updated last year, and I got involved in that because I discovered that our courthouse camera system did not require a username and password. Anybody who had access to that space could access the camera system. Oh. And so at that time, I was very alarmed by that, and that's the only reason I got on board with, okay, let's make sure that the only people who can access this camera system are the sheriff and county attorney.

18:31Speaker 3

So just to remind people what drove that last year.

18:36 – 18:52Speaker 4

okay okay all right so um so did you want to make i'll retain a motion to update our current policy for open records and access as well you don't have you only have this

18:54Speaker 5

cybersecurity. No, we don't have cybersecurity. You have a motion to proceed.

18:57Speaker 4

Did you want to make a motion for cybersecurity or did you want to make a motion for update policy or did you want to make a motion for both? I want to make a motion for both.

19:07Speaker 3

Okay, do you want to please state that? I'll make a motion that we update our camera system policy. Okay, and just leave it at that?

19:16 – 19:37Speaker 2

Yeah, we'll have to sort through what those details are. Okay. We want to also make sure that There is a requirement for a work order to be done that clearly shows when an access is made. Well, the problem with that is one of the... That's another company's procedure. They won't just go in on their own.

19:37Speaker 4

Well, unfortunately, Michelle, that's only for actual technicians. When they're salespeople, they don't require work orders. So there will be no work order for what happened on an accident.

19:47Speaker 2

I'm saying there should be.

19:48Speaker 4

She said, add it.

19:49Speaker 2

We should add that because there you go. Then you've got a really good paper trail. I feel about that. Yeah.

19:57 – 20:10Speaker 3

Well, if we, I think we need to, we need to sort through those details. I don't think this is the time and the place to sort those details today. We're making a decision. If we're going to update that policy, that's going to have to be a totally separate discussion regarding all those details. Am I right?

20:10Speaker 5

So if I agree, the motion is update the camera system. Yeah, we can go and we need to sort through those details.

20:18Speaker 3

Yes, camera policy access. That's the motion. We'll get advice on that as well. So that's going to be a further discussion. Probably a work session.

20:26 – 20:41Speaker 4

Yeah. All right. Do I have a second for that? I need further discussion. All in favor, please vote aye. Aye. All opposed? Motion carries. And then the last... As a hub switch? Yes.

20:42Speaker 3

And then the last one... Well, we need to do cyber security policy, or do you want to tackle that separately another time?

20:51Speaker 4

I thought we were going to roll it all in one. Okay.

20:54Speaker 5

Do the camera system as a whole.

20:57Speaker 3

But the cyber attack on our internet and our IT and all that is a completely different scenario. That's right.

21:05Speaker 4

There's overlap. Where is this?

21:07Speaker 5

It's not the problem.

21:08Speaker 4

The cyber security is not. Well, so the cyber security attack is technically on. It didn't happen. But it didn't happen.

21:16Speaker 3

So why don't I make a note and maybe we add it for the next Tuesday.

21:21Speaker 4

Oh, that's a good idea. Discussion of new business, cyber security policy.

21:24 – 21:52Speaker 3

Can you ladies add that, please? Okay. Thank you. So we can skip that one for now. Okay, then I will make a motion that we proceed with, that we ask Michael Bull to generate documentation to cancel the current service agreement with Johnson Controls and ask for a refund. Okay, do I have a second?

21:55 – 22:25Speaker 4

I will second that. Any further discussion? All in favor, please vote aye. Aye. All opposed? Motion carries. Okay. Anything else to discuss? Otherwise, there's nothing else on the agenda. All right. I'll entertain a motion to adjourn. Second? Second. All in favor, please vote aye. Aye. All opposed? Motion carries. Thank you, everyone.

This transcript was automatically generated from the official public meeting video and is presented unedited. It reflects remarks made on the public record by elected officials, staff, and public commenters. Transcript accuracy may vary; view the original recording for reference.