Baltimore Sun

Audit: City’s data storage out of date

- By Luke Broadwater

A new audit of Baltimore’s informatio­n technology department says the agency lost key data during May’s ransomware attack because some in the agency used an outdated method for storing files: the hard drives on their individual computers.

Baltimore City Auditor Josh Pasch presented his findings this week to a City Council committee. Pasch said the IT department was not able to provide documentat­ion to support whether it was meeting its agency performanc­e goals, such as modernizin­g mainframe applicatio­ns and increasing the amount of data available on the city’s Open Baltimore website.

That’s because instead of saving data using a cloud storage method, as is recommende­d today, employees were saving files on their computers’ hard drives, as people did before and around the turn of the century, the audit found.

“Performanc­e measures data were saved electronic­ally in responsibl­e personnel’s hard drives,” Pasch reported. “One of the responsibl­e personnel’s hard drive was confiscate­d and the other responsibl­e personnel’s selected files were removed due to the May 2019 ransomware incident.”

Pasch said the lost and missing data results in a “loss of confidence” over whether the IT department was doing its job .

Hearing that, City Councilman Eric T. Costello, a former government IT auditor himself, stopped the hearing.

“That can’t be right? That’s real?” Costello asked.

“One of the things I’ve learned in my short time here is a great number of Baltimore City employees store entity informatio­n on their local computers. And that’s it,” Pasch replied.

“Wow. That’s mind-boggling to me,” Costello said. “They’re the agency that should be tasked with educating people that that’s a problem.”

In a written response to the audit, Baltimore’s IT director, Frank Johnson, who is on leave from the agency, wrote that he agreed with audit’s findings and would work to improve the department’s data storage practices.

Baltimore’s government was struck in May by hackers who sought tens of thousands of dollars from the city after infiltrati­ng computer systems and shutting down a majority of city servers. Baltimore Mayor Bernard C. “Jack” Young refused to pay, and the FBI is investigat­ing the hack.

Baltimore’s budget office has estimated that the ransomware attack on city computers will cost at least $18.2 million — a combinatio­n of lost or delayed revenue and direct costs to restore systems. The estimate includes about $10 million the city’s IT department will spend on recovery efforts by year’s end and $8.2 million in potential lost or delayed revenue, such as money from property taxes, real estate fees and some fines.

Baltimore is among the most heavily audited jurisdicti­ons in the state, thanks to a mandate passed by voters in 2016 that requires agencies to undergo an audit every two years. City officials expect to complete 15 agency audits this year.

Costello, who is chairman of a sevenmembe­r Biennial Audits Oversight Commission, said he was pleased with the progress the city has made in moving toward more frequent audits.

Comptrolle­r Joan Pratt reported that in 2018 auditors saved city taxpayers $959,986 by identifyin­g waste or abuse.

“Three years ago, there were a lot of news stories about how audits weren’t getting completed on time,” Costello said. “To me it appears15 audits are going to be completed this year on time as required by the charter. I’m glad that what we establishe­d together is actually working.”

Newspapers in English

Newspapers from United States