MA Public Records Search
← Back to Search

Matthew Rocheleau v. Executive Office of Technology Services and Security (SPR 20200555)

Massachusetts Public Records Appeal · Petitioner won — agency ordered to provide records · Filed 03-19-2020

ClosedAppealPetitioner Won

SPR 20200555 is a Massachusetts Public Records Law appeal filed by Matthew Rocheleau concerning records held by Executive Office of Technology Services and Security, opened 03-19-2020. Type: Appeal. Status: Closed. Supervisor of Public Records determination: Petitioner won — agency ordered to provide records.

Case Details

Case Number
20200555
Case Type
Appeal
Case Subtype
Initial
Status
Closed
Requester
Matthew Rocheleau
Custodian
Executive Office of Technology Services and Security
Date Opened
03-19-2020
Date Closed
04-02-2020
Date Request Submitted
01-17-2020
Processing Fees Charged
0.00
Petitions Regarding Fees
No
Time to Comply
12 Business Days
Went to Court
No

PDF Document

Extracted Text (searchable & copyable)

The Commonwealth of Massachusetts William Francis Galvin, Secretary of the Commonwealth Public Records Division Rebecca S. Murray Supervisor of Records April 2, 2020 SPR20/0555 Shannon C. Sullivan, Esq. General Counsel Chief Privacy Officer Executive Office of Technology Services and Security One Ashburton Place, 8th Floor Boston, MA 02108 Dear Attorney Sullivan: I have received the petition of Matthew Rocheleau, of the Boston Globe, appealing the response of the Executive Office of Technology Services and Security (EOTSS). Specifically, Mr. Rocheleau requested “[t]he e-mail address(es) assigned to each employee of the Commonwealth of Massachusetts, showing their name and the department they work for.” Previous appeal This request was the subject of a previous appeal. See SPR20/0198 Determination of the Supervisor of Records (February 19, 2020). In my February 19th determination I ordered EOTSS to provide Mr. Rocheleau with a response to the request, provided in a manner consistent with the order, the Public Records Law, and its Regulations. EOTSS responded on March 5, 2020. Mr. Rocheleau responded and SPR20/0555 was opened as a result. The Public Records Law The Public Records Law strongly favors disclosure by creating a presumption that all governmental records are public records. G. L. c. 66, § 10A(d); 950 C.M.R. 32.03(4). “Public records” is broadly defined to include all documentary materials or data, regardless of physical form or characteristics, made or received by any officer or employee of any town of the Commonwealth, unless falling within a statutory exemption. G. L. c. 4, § 7(26). It is the burden of the records custodian to demonstrate the application of an exemption in order to withhold a requested record. G. L. c. 66, § 10(b)(iv); 950 C.M.R. 32.06(3); see also Dist. One Ashburton Place, Room 1719, Boston, Massachusetts 02108 • (617) 727-2832• Fax: (617) 727-5914 sec.state.ma.us/pre • pre@sec.state.ma.us

Shannon Sullivan, Esq. SPR20/0555 Page 2 April 2, 2020 Attorney for the Norfolk Dist. v. Flatley, 419 Mass. 507, 511 (1995) (custodian has the burden of establishing the applicability of an exemption). To meet the specificity requirement a custodian must not only cite an exemption, but must also state why the exemption applies to the withheld or redacted portion of the responsive record. Current appeal EOTSS initially responded on February 3, 2020 by denying access to records under Exemption (n) of the Public Records Law. G. L. c. 4, § 7(26)(n). In its February 3rd response EOTSS indicated “[t]he records you have requested below are not subject to public disclosure pursuant to M.G.L. c. 4, § 7, Twenty-sixth (n), as their disclosure would jeopardize the Commonwealth’s cybersecurity.” In my February 19th determination I found that EOTSS had not met its burden to withhold the responsive email addresses under Exemption (n). In particular, I found EOTSS did not meet its burden to show how the list of email addresses sufficiently “resemble[s] the records listed as examples in the statute” as contemplated in People for the Ethical Treatment of Animals (PETA) v. Dep’t of Agric. Res., 477 Mass. 280, 289-90 (2017). I also found that although EOTSS provided information regarding the risk of jeopardizing public safety or cyber security, it did not provide “sufficient factual heft” to conclude that a reasonable person would agree that disclosure of the email addresses is “likely to jeopardize. . .cyber security” as required by Exemption (n). Id. In its March 5th response EOTSS provides additional information regarding its Exemption (n) claim. Mr. Rocheleau objects to this response. Exemption (n) Exemption (n) applies to: records, including, but not limited to, blueprints, plans, policies, procedures and schematic drawings, which relate to internal layout and structural elements, security measures, emergency preparedness, threat or vulnerability assessments, or any other records relating to the security or safety of persons or buildings, structures, facilities, utilities, transportation, cyber security or other infrastructure located within the commonwealth, the disclosure of which, in the reasonable judgment of the record custodian, subject to review by the supervisor of public records under subsection (c) of section 10 of chapter 66, is likely to jeopardize public safety or cyber security. G. L. c. 4, § 7(26)(n). Exemption (n) allows for the withholding of certain records which if released would jeopardize public safety. The first prong of Exemption (n) examines “whether, and to what

Shannon Sullivan, Esq. SPR20/0555 Page 3 April 2, 2020 degree, the record sought resembles the records listed as examples in the statute;” specifically, the “inquiry is whether, and to what degree, the record is one a terrorist ‘would find useful to maximize damage.’” People for the Ethical Treatment of Animals (PETA) v. Dep’t of Agric. Res., 477 Mass. 280, 289-90 (2017). The second prong of Exemption (n) examines “the factual and contextual support for the proposition that disclosure of the record is ‘likely to jeopardize public safety.’” Id. at 289-90. The PETA decision further provides that “[b]ecause the records custodian must exercise ‘reasonable judgment’ in making that determination, the primary focus on review is whether the custodian has provided sufficient factual heft for the supervisor of public records or the reviewing court to conclude that a reasonable person would agree with the custodian’s determination given the context of the particular case.” Id. February 3rd response In EOTSS’s February 3rd response you indicated “[i]n reviewing your request, I consulted with our Chief Information Security Officer, our office's primary subject matter expert concerning the cybersecurity of our office and of the IT infrastructure our office maintains on behalf of the Commonwealth. It is his assessment that disclosing a complete list of email addresses for Commonwealth employees along with their names and corresponding departments would be a risk to the Commonwealth's cybersecurity and IT infrastructure.” You further assert that “[t]he primary risks – phishing, spear phishing, business email compromise, and social engineering attacks – though present when even a single email address is disclosed, are significantly amplified by wholesale disclosure. A disclosure of the requested nature would enhance the ability of adversaries to conduct highly targeted attacks against Commonwealth users.” EOTSS provided additional information regarding the risk of “spear fishing” and indicates “[s]pear phishing, in particular, is a major concern of the EOTSS Security Office.” You asserted the following: Email addresses are relatively easy to spoof, and it is possible that an adversary could fabricate an email so it appears to have originated from one of these users. Should we disclose a list of email addresses for every Commonwealth employee whose information we maintain, along with their name and the department where they are employed, cyber attackers would be able to tailor attacks specifically to each employee, making their attacks more convincing. Combined with other publicly available information (e.g., job titles, agency functions, social media accounts, etc.), the risk of a successful attack is further increased. The more email addresses an attacker can utilize, the greater the likelihood there will be a successful attack. EOTSS indicated that “[t]here are numerous examples of successful spear phishing attacks against government employees” and that “[w]hile the Commonwealth employs a variety

Shannon Sullivan, Esq. SPR20/0555 Page 4 April 2, 2020 of measures to guard against such attacks (e.g., requiring cybersecurity awareness training for all employees, implementing risk mitigation software solutions), human error and sophisticated phishing techniques continue to pose a real threat to Commonwealth cybersecurity.” With respect to the availability of responsive email addresses, you asserted “[w]hile we are aware that some employee email addresses are necessarily available to the public in order for such employees to effectively perform their job responsibilities, many of the employees whose email addresses are sought by this request generally have limited or no contact with the general public via their work email account, simply because there is no need based on their job function(s). This may make them less suspicious and more susceptible to an attack. There is limited or no public interest in the disclosure of such email addresses.” EOTSS provided information regarding the impact of a successful attack by indicating, in part, “[w]e are at risk of everything from financial damages through a successful business email compromise attack to interference with our ability to respond to real world emergencies should attackers gain access to our network via spear phishing and target our dispatch channels.” You further contend that “[s]uccessful infiltration of our network could have catastrophic consequences for the Commonwealth's operations. Wholesale disclosure of so many Commonwealth employee email addresses would substantially increase our vulnerability, while undermining the Commonwealth’s cybersecurity posture and the other protective and preventive measures we have taken, diminishing our ability to protect our IT infrastructure and the confidential personal and business data we are required to maintain.” March 5th response In its March 5th response EOTSS provides additional information regarding its Exemption (n) claim. In particular, you indicate “[t]he statutory language considered in [PETA] did not encompass the current language. Since that time, the General Court has since amended [E]xemption (n) explicitly to reference the cybersecurity of the Commonwealth. M.G.L. s. 4, c. 7, cl. 26(n).” You contend “[a] list of email addresses clearly creates a risk to the cybersecurity infrastructure of the Commonwealth for the reasons stated by EOTSS in its initial response and expanded upon here.” EOTSS references risks such as phishing attacks and you claim “[w]ell- curated, comprehensive lists of names, titles, and email addresses would make such cyberattacks easier to target in the same way that blueprints or schematic drawings would make physical intrusions easier to plan and execute.” You indicate “[a]ccordingly, EOTSS’s position with regard to the first prong of the statute should be accorded greater weight; the legislature has explicitly endorsed the security concerns implicated by the requested records.” With respect to the second prong of the PETA analysis, EOTSS addresses the issue of the purpose of the request. You indicate, in part, that “EOTSS takes the position that a reasonable custodian would not attempt to discern the intent of any given request and would instead apply a neutral standard when applying exemption (n), or indeed, any of the exemptions articulated in M.G.L. c. 4, s. 7. Applying such a standard here, EOTSS finds that your request is indistinguishable from a request that could lead to targeted spear phishing campaigns against

Shannon Sullivan, Esq. SPR20/0555 Page 5 April 2, 2020 large numbers of Commonwealth personnel.” You also note that “[f]urther, EOTSS consulted with the Massachusetts State Police (MSP), which is often involved in responding to cybercrime, and the subject matter experts in that area at the MSP agree with our assessment that disclosure of the responsive records would pose a substantial cyber security risk to the Commonwealth.” In his appeal petition Mr. Rocheleau asserts, in part, “[t]he [l]ist bears no resemblance to the records listed as examples in the statute.” He contends “[m]any of the emails on the [l]ist are already public, and presumably many more could be obtained through piecemeal requests for the emails of specific employees or groups of employees.” With respect to the potential risks associated with disclosure, Mr. Rocheleau contends “[n]either these vague risks, which the Department presumably takes steps to mitigate against (particularly given that the risks exist all the time, given the public nature of email addresses), nor the opinion of the MSP, is sufficient to meet the Department’s burden.” Despite its March 5th response, I find EOTSS has not met its burden to withhold the responsive email addresses under Exemption (n). In particular, EOTSS has not met its burden to show how the responsive record sufficiently “resemble[s] the records listed as examples in the statute” as contemplated in PETA. Id. Despite EOTSS’s contention that “[w]ell-curated, comprehensive lists of names, titles, and email addresses would make such cyberattacks easier to target in the same way that blueprints or schematic drawings would make physical intrusions easier to plan and execute,” it remains unclear how a list of otherwise public email addresses is similar to the examples listed in G. L. c. 4, § 7(26)(n). Although EOTSS provides information regarding the risk of jeopardizing cyber security, please note that as acknowledged by EOTSS in its response, the Supreme Judicial Court in PETA found that “[a]s the resemblance between the record sought and the listed examples in [E]xemption (n) decreases, the custodian’s burden for demonstrating ‘reasonable judgment’ increases. Thus, when the requested record bears little or no resemblance to the listed examples, the custodian’s burden for demonstrating that it exercised ‘reasonable judgment’ in determining that disclosure of the record is ‘likely to jeopardize public safety’ will be at its highest.” Id. at 290–91. In light of this heightened burden outlined in PETA, I find EOTSS has not provided “sufficient factual heft” to conclude that a reasonable person would agree that disclosure of a list of otherwise public email addresses is “likely to jeopardize. . .cyber security” as required by Exemption (n). Id. Conclusion Accordingly, EOTSS is ordered to provide Mr. Rocheleau with responsive records in a manner consistent with this order, the Public Records Law, and its Regulations as soon as practicable. A copy of any such response must be provided to this office. It is preferable to send an electronic copy of this response to this office at pre@sec.state.ma.us.

Shannon Sullivan, Esq. SPR20/0555 Page 6 April 2, 2020 Sincerely, Rebecca S. Murray Supervisor of Records cc: Matthew Rocheleau