Elgin is set to buy another layer of cybersecurity for its internet-connected computer systems as city officials said there had been evidence of a thwarted cyberattack recently.
The City Council on Wednesday night unanimously advanced for final approval a four-year agreement with Darktrace for its Enterprise Immune System for an annual amount of $72,000, based on the number of devices connected to the network, the amount of traffic and the network configuration.
“Darktrace has an innovative and unique approach to security monitoring with a smart machine system that can learn what normal network traffic looks like and then be more sensitive to alerting us when abnormal traffic appears,” Jeff Massey, Elgin chief technology officer, said of the purchase.
“Darktrace also combines the machine monitoring with human monitoring, which augments our city ITS (information technology support) staff with a high level of security expertise. It’s like having a highly skilled security expert on staff who never takes a day off or goes to sleep,” Massey said.
Elgin already runs a multilevel security environment with perimeter firewalls for any connection going in or out of the city network, Massey said.
“And we have endpoint security on all user devices as well as local firewalls and network segmentation, plus now adding the Darktrace Enterprise Immune system,” Massey said.
A memo prepared for the council meeting noted staff concerns about “the current cyber threat landscape is pushing the traditional security past its limits,” as a prime reason for buying more security.
City Manager Rick Kozal claimed there had been recent evidence of such a thwarted cyberattack, apparently coming from somewhere in Eastern Europe.
Massey said Elgin has been running a pilot test on Darktrace since the beginning of December, and there was an attempt from a Romanian IP address to access a city remote access terminal server.
Massey said: “The attempt was using a generic training account used for employee training. This account had extremely limited access with the city network. As a training account, it also had a very weak password, which was how it was exploited.”
Massey said Elgin had been running the Darktrace pilot for about three weeks when the attempt happened. The Darktrace system saw the incoming connection from a foreign IP address and flagged it, and a Darktrace analyst confirmed the traffic as real and sent Massey an email alert, which allowed staff to kill the connection and disable the training user account.
“So the Darktrace monitoring allowed us to see this intrusion as it happened, respond before any serious breach occurrence and shut it down cold,” Massey said. “It also prompted us to review all the passwords and increase some password complexity rules as well as add some additional firewall rules to strengthen the perimeter access.
“This was a very convincing display of just how well the Darktrace system works and what its value can be to the city.”
Massey said Darktrace has been a great vendor to work with in the pilot and “very helpful, treating Elgin staff as they would a full customer.”
“We tested several security systems before choosing Darktrace, evaluating the next-gen security environment. Darktrace really came out of the testing well ahead of the others,” Massey said.
In addition to augmenting the city’s ITS staff with a high level of security expertise, Massey said: “Darktrace also provided insight into network traffic that could indicate insider security risks as well as the traditional outside-the-firewall threats. Their system weeds out the normal while giving us actionable intelligence on what is happening within the city network.”
According to the Darktrace website, the company was founded in 2013 in Cambridge, England, “by mathematicians and machine learning specialists from the University of Cambridge, together with world-leading intelligence experts from MI5 and GCHQ, to bring transformative technology to the challenge of cyber security.” Its main headquarters are in England and San Francisco.
In December, TechCrunch reported that fast-growing Darktrace had 1,500 customers and 300 or so employees.
Carlos Munoz, a Darktrace cybersecurity executive, said the company offers “really exciting solutions for all sizes of organizations.”
He said threat actors might target smaller operations because those targets may lack security sophistication or don’t have staff dedicated to watching the operations. Munoz said cyber thieves usually are after personally identifiable information — records of individuals that can be used to commit fraud such as opening credit card accounts.
“Threats are coming from all over the world,” Munoz said.
Those from China tend to focus on intellectual property, Munoz said. Identity theft and ransomware attempts tend to come from Eastern Europe, and attempts to disrupt systems tend to originate from the Middle East and groups such as the Syrian Electronic Army, Munoz said.





