Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Board urged to adopt written cybersecurity breach protocol, backups and quarterly risk assessments

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Board members at the April 7 work session said the district lacks a written breach protocol and should add cyber-risk actions to its strategic plan and budget, including backup recovery, updated cyber liability insurance and quarterly risk assessments.

Board members raised cybersecurity as a district priority at the April 7 work session after attending training that highlighted recent breaches in other districts.

A board member asked whether the district had a written breach protocol; staff responses indicated the district "may not" have a written protocol, though the district maintains full backups. The meeting record shows board members asking administration to include cybersecurity planning in the district’s strategic plan and budget.

Specific items raised Speakers listed several actions they viewed as necessary: a written incident response protocol, a clearly documented backup and recovery plan that can be executed by staff other than the person who handles IT day-to-day, upgraded or confirmed cyber liability insurance, regular (quarterly) risk-management assessments, and staff training so multiple people can execute the protocol during a crisis.

Concerns and examples Board members cited examples from other states where breaches shut down central office operations, stopping payroll, attendance reporting and grading functions. One speaker noted that some attackers demand ransom payments to restore systems and that district officials should plan for that possibility.

Next steps Board members asked administration to provide sample policies and to present recommendations at a future meeting. Administration said it would coordinate with IT staff (Miss Jarvis and Mr. Woodhaugh were referenced in the discussion) and produce a written protocol and training plan for board review.

Ending The board directed administration to draft written procedures, identify recovery roles, assess insurance coverage and present a risk-management schedule and budget implications at a future meeting.