Justice Apologizes For Iowa Court System Authorizing Security Vulnerability Testing That Led To Break-Ins

Justice Apologizes For Iowa Court System Authorizing Security Vulnerability Testing That Led To Break-Ins

At a legislative hearing Friday, court administrators answered questions about their decision to hire “penetration testers” who were arrested for burglary last month.

The chief justice of the Iowa Supreme Court publicly apologized Friday for the court system’s authorization of security vulnerability tests that led to the arrests of two Coalfire employees for courthouse break-ins. 

The state senate’s Government Oversight Committee held a hearing to hear testimony about the break-ins at the Dallas and Polk County courthouses in September. According to reporting from The Des Moines Register, the Coalfire employees were following through on a contract signed by Iowa court system officials hiring them to test the “adequacy and effectiveness” of security at government buildings. 

"In our efforts to fulfill our duty to protect confidential information of Iowans from cyberattacks, mistakes were made," Chief Justice Mark Cady said during the hearing. "We are doing everything possible to correct those mistakes, be accountable for the mistakes and to make sure they never, ever occur again." 

Now, information technology officials with the state court system say that the employees, who were able to gain access to two courthouses over the course of two nights, acted outside of the scope of the contract. 

The Iowa court administration hired the company to test for cybersecurity vulnerabilities and "did not intend, or anticipate, those efforts to include the forced entry into a building," according to a statement given to the Register last month. 

In turn, local law enforcement were not warned about the break-ins and responded to an alarm at the Dallas County courthouse as if it were a real burglary. While the two employees arrested for third-degree burglary are free and there are no proceedings scheduled for their cases, legislators and local police say that the situation was dangerous for all involved. 

Legislators will continue their investigation until more facts are gathered, according to Sen. Amy Sinclair, the chair of the committee.  

"It is outside the scope of the judicial branch to authorize individuals to illegally break into facilities that they neither own nor provide security for," she told the Register. 

Todd Nuccio, the state court administrator, said that the contract had not been reviewed by a legal team and that oversight steps will be considered in the future, according to the Register. Sen. Claire Celsi told the Register that the court’s shrinking budget may have played a role, leading to them signing the contract and take the most “efficient” route. 

"It’s faintly disturbing that a contract of this magnitude was allowed to move forward without further review from someone higher up the food chain maybe," Celsi said. 

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Live From ISC West: Day 2 Recap

    If it’s even possible, Day 2 of ISC West in Las Vegas, Nevada, was even busier than the first. Remember to keep tabs on our Live From ISC West page for news and updates from the show floor at the Venetian, because there’s more news coming out than anyone could be expected to keep track of. Our Live From sponsors—NAPCO Security, Alibi Security, Vistacom, RGB Spectrum, and DoorKing—kept the momentum from Day 1 going with packed booths, happy hours, giveaways, product demonstrations, and more. Read Now

    • Industry Events
    • ISC West
  • Visiting Sin City

    I’m a recovering alcoholic, ten years sober this June. I almost wrote “recovered alcoholic,” because it’s a problem I’ve long since put to bed in every practical sense. But anyone who’s dealt with addiction knows that that part of your brain never goes away. You just learn to tell the difference between that insidious voice in your head and your actual internal monologue, and you get better at telling the other guy to shut up. Read Now

  • On My Way Out the Door

    To answer that one question I always get, at every booth visit, I have seen amazing product technology, solutions and above all else, the people that make it all work. Read Now

    • Industry Events
    • ISC West
  • Return to Form

    My first security trade show was in 2021. At the time, I was awed by the sheer magnitude of the event and the spectacle of products on display. But this was the first major trade show coming out of the pandemic, and the only commentary I heard was how low the attendance was. Two representatives from one booth even spent the last morning playing catch in the aisle with their giveaway stress balls. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

New Products

  • Dinkle DKU Barrier Terminal Blocks

    Dinkle DKU Barrier Terminal Blocks

    New DKU screw type terminal blocks use a spring-guided system where the screws are integrated and captive within the terminal enclosure. These screws can be backed out so that ring- or U-shaped cable lugs can be inserted, without the possibility of losing the screw. 3

  • Videoloft Cloud Video Surveillance VSaaS Solution

    Videoloft Cloud Video Surveillance VSaaS Solution

    Videoloft focuses on transforming traditional professional surveillance systems into cloud connected solutions via the Videoloft Cloud Adapter. 3

  • BIO-key MobileAuth

    BIO-key MobileAuth

    BIO-key International has introduced its new mobile app, BIO-key MobileAuth™ with PalmPositive™ the latest among over sixteen strong authentication factors available for BIO-key's PortalGuard® Identity-as-a-Service (IDaaS) platform. 3