• Facebook
  • X
  • YouTube
Partly cloudy Dumfries 18.0 °C

Council bosses have secret stash of mobiles

Editor
Share:
  • Share On Facebook
  • Share On X
  • Share On Whatsapp
  • Share On Email

 

A SECRET stash of basic mobile phones are ready to be deployed by Dumfries and Galloway Council leaders in the event of a major cyber attack.

These extra measures have been taken in readiness for a potential cyber attack on the local authority’s systems, which could put critical services and finances at risk.

It comes after a ransomware attack in November 2023 crippled the Western Isles Council – and the recovery cost around £1 million.

At a meeting last week, councillors examined the lessons learned from that attack and pressed officials on what Dumfries and Galloway has done to protect itself.

Mid and Upper Nithsdale Councillor Tony Berretti questioned what would happen to the council’s telephone systems in the event of an attack.

And Kris Edgar, the council’s cyber security and ICT lead, confirmed preparations are in place — though he was cautious about revealing too much detail in a public forum.

He continued: “What I can say is we have a stock of handsets, basic mobiles. We have a stock of other devices that we could deploy and we have contracts in place with our suppliers where we could look to raise those in short order should they be needed.”

Councillor Berretti asked if there was a hierarchy for who would receive devices first in a crisis - and Mr Edgar confirmed that key staff, systems, and processes have been identified.

Council leader Stephen Thompson asked for a simple explanation of ‘air-gapped backups’ — which have been recommended by Audit Scotland as a technical safeguard against ransomware attacks.

Mr Edgar explained the council’s most critical data, described as “crown jewels,” is backed up with a third-party provider completely separate from any council infrastructure, local or cloud-based.

He added: “Should we then need those backups, if the worst would happen, we would contact the third party and bring the backups back.

“It doesn’t sit on the same servers, same infrastructure, same location.”

Councillors will get further detailed reports on cyber resilience arrangements, including offline briefings to discuss sensitive specifics.

 

Back