State Comptroller Faults Oneonta’s Cybersecurity Oversight

A New York comptroller’s audit concluded that Oneonta lacked sufficient governance to protect its IT assets from cyber threats. The review cited missing risk-assessment documentation and delayed cybersecurity training for new employees, among other policy failures. City officials disputed parts of the findings, and the report offered seven recommendations for improvement.
The comptroller’s review covered Oneonta from January 2024 through early November 2025. By July 2025, the city had 188 workers and 106 computers, and it spent $222,752 on an outside IT provider for maintenance, security, and support.
Although that vendor drafted cybersecurity policies, the Common Council never formally adopted them, and officials did not consistently review or enforce compliance. A city clerk’s August letter said documentation, centralization, and communication could improve, while disputing that weak records proved activities never happened. Seven recommendations were issued, with a corrective plan due within 90 days.
Oneonta residents, city employees, and people whose sensitive data the city holds could be affected if cybersecurity governance gaps persist. Inconsistent training and unadopted policies may increase the chance of breaches, service disruptions, or financial losses, potentially weakening trust in city government. The audit and required corrective plan may push officials to clarify responsibilities, document risk assessments, and enforce training, though the real effect depends on how fully the city implements changes.