Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

District tech director presents cybersecurity plan after PowerSchool breach; vendor contract and NIST framework highlighted

3442369 · March 6, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Tech director Dirk Van Curren outlined a 22-page district cybersecurity and incident response plan that uses the NIST framework, plans to contract a 24/7 endpoint-detection vendor, and cited the recent PowerSchool data incident as a catalyst for strengthening protections.

RSU 51/MSAD 51’s technology leadership presented a district cybersecurity plan at the March 6 board meeting and answered detailed questions about vendor monitoring, student privacy protections, and the August–February PowerSchool incident that affected many schools.

Dirk Van Curren, who identified himself as the district’s technology director, said the district prepared a 22‑page incident-response plan built around the NIST (National Institute of Standards and Technology) Cybersecurity Framework and templates supplied or recommended by MSMA (used in the meeting as the district’s insurance/cyber-insurance liaison). He told the board the plan is not a public document in full because it includes operational details the district does not want released.

Van Curren said the district runs a one-to-one device program and has “about 360” network endpoints; protecting student and staff data, financial systems, and vendor supply chains is a top priority. The district intends to contract a third-party vendor that will provide endpoint detection and 24/7 monitoring and can take immediate actions — for example isolating a compromised device or segment of the network.

Board members and community members asked whether the vendor will provide attempted-attack reporting and notification to district staff; Van Curren said the tech department will be notified of both successful and attempted incidents and that the vendor can disable specific ports or devices if needed.

The discussion turned to the PowerSchool breach. A district speaker said PowerSchool retained external forensic help (reported as Experian in the meeting) and is contacting people whose records were in the downloaded files. The district said it is still awaiting a complete inventory of what was in the stolen file; portions of the file were encrypted and could not be opened by the actor. The district reported that only one staff member’s Social Security number was in the dataset it provided and that some PII (for example student birthdates and directory information) may have been exposed. The district previously advised affected people and offered credit monitoring where appropriate.

Staff said the district already forces two-factor authentication for staff accounts and is working toward student two-factor options, noting technical challenges such as students without personal phones. Van Curren said phishing is the district’s most common threat, and the district conducts staff training and some student digital-citizenship work through Common Sense Media.

Next steps include presenting the plan to the district safety committee and conducting regular reviews; the district will also finalize a contract with the selected vendor and begin phased implementation of additional endpoint detection and network protections.

The board’s questions focused on notification thresholds, the district’s experience with DDoS-style disruptions, license renewals for recently upgraded hardware, and the timeline for vendor rollout.