Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity It topic
No spam. Unsubscribe anytime.
District hears cybersecurity report: backups, MFA rollout and phishing training under way
Summary
The board received a cybersecurity briefing from Sharp Business Systems and IT Director Maria Gintet. Presenters described current protections (backups, SOC monitoring, email protection), gaps (MFA deployment incomplete) and ongoing work including phishing tests, server consolidation and disaster recovery plans.
Get email alerts on the Cybersecurity It topic
No spam. Unsubscribe anytime.
Maria Gintet, director of IT and communications for Taos Municipal Schools, introduced a cybersecurity presentation from Sharp Business Systems at the Aug. 6 board meeting, saying legal counsel had advised the briefing be public but that sensitive details would be handled offline. Sharp account managers Richard Martinez and Jimmy Armijo and IT engineer Chris Tower described the district’s cybersecurity posture: endpoint protection and SentinelOne agents, backup schedules, security operations center (SOC) monitoring, simulated phishing and security awareness training, and movement of major applications (PowerSchool and Visions) to cloud hosting. Sharp reported that district data is backed up every four hours and that the vendor can restore servers, mailboxes and systems from those backups. Presenters said the district has implemented remote monitoring and management tools, endpoint agents and a security information and event management (SIEM) capability that detects anomalies. Sharp reported progress on multifactor authentication (MFA) deployment but acknowledged gaps: MFA rollout was about halfway complete at the time of the meeting. Sharp said it had performed server consolidation (reducing dozens of physical servers to fewer hosts running virtual machines) and had moved several applications to the cloud to reduce on-premises exposure. Sharp outlined a disaster-recovery plan that includes activation and notification, selecting recovery locations, retrieving backups and testing reconstitution. The firm said regular testing and maintenance are part of the program; the district had tested recoveries during recent summer power outages and restored services within the day in subsequent tests. Board members asked whether power outages provide an opening for attackers; presenters replied that loss of power reduces external access but increases recovery importance. Sharp also discussed the risks and opportunities from artificial intelligence (AI) and advised using AI defensively to detect and mitigate threats. IT staff confirmed they have begun internal phishing campaigns and said some staff clicked test links, triggering training. Director Gintet and Sharp asked board members to raise highly detailed security questions offline to avoid exposing sensitive system details in public session.

