Pennington county responds to cyber incident

By: 
Leslie Hladysz
On July 5, it was announced that Pennington County was responding to a cybersecurity incident affecting portions of its network. Offices were closed for the Independence Day holiday and remained closed July 6 for most face to face public interactions.
While some services have been restored, there are still a few transactions that can be handled in person at the county offices.  The most recent update given July 9 and confirmed with Katy Urban, public information officer for the Pennington County State’s Attorney’s Office July 11, details that the treasurer’s office still cannot process any registrations in person currently. 
Staff is available at each kiosk location so that people who have questions about how to use the kiosks have immediate assistance. People can also use my605drive.sd.gov to register their vehicles.
The auditor’s office cannot process any lien payments. Early voting is still available between 7 a.m. and 4 p.m.
The register of deeds can now process vital records requests and can accept real estate recordings. However, they cannot be fully processed at this time.
The county commissioner meetings are still being held in person, but they are not being livestreamed.
Planning and Zoning (P & Z) can process building permits but is doing so manually. And the next full agenda P & Z Commission meeting is now moved to July 27.
Critical life safety services, including 911 Dispatch, the Pennington County Jail, Juvenile Services Center, the Care Campus and other public safety operations as well as court operations remain operational. Urban said, “the full restoration process can take some time.” She does not know when full restoration will take place. 
Because this is an ongoing investigation, the county is not able to say much about the incident specifically. Urban does note that this type of attack has not occurred in Pennington County before, and that the county does have cyber security insurance. 
Shawn Palmer, IT consultant with Rapid Tech Works in Rapid City, has no firsthand knowledge of the extent of the county cyberattack but said in general the response to an attack of this nature is essentially the same—lock down the system, investigate what happened and clean up before rechecking and allowing people back in to use the system. 
“The easiest thing to do if somebody bad is in the system is to pull the plug,” Palmer said. 
This means denying access to others, in this case the general public, while investigators resolve issues on all fronts. How long this takes depends on the level of penetration. Certain systems like information tied to Social Security numbers,  bank accounts or HIPAA might take longer to resolve and take a third party “deep dive.” 
Palmer said making sure nothing is left on the account, resetting passwords, changing multifactor authentication and checking logs of where the system was compromised all need to be handled prior to opening the system back up. The password also needs to be reset. 
“You don’t want to turn any services on until the original point of entry is patched and remediated,” Palmer said. 
Currently, Pennington County is working alongside the South Dakota National Guard Cyber Incident Response Team,  the South Dakota Fusion Center, Cybersecurity & Infrastructure Security Agency (CISA) and the South Dakota Department of Homeland Security to resolve the incident. 
For more information visit pennco.org.

User login