Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Governance topic

No spam. Unsubscribe anytime.

Committee reviews data-governance updates and ParentSquare account breach

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Communication and Policy Committee reviewed the district's updated data governance manual and heard from technology staff about a ParentSquare account compromise that sent messages to high school staff; administrators described backup, inventory and authentication improvements.

The Communication and Policy Committee of the Concord School Board reviewed updates to the district’s data governance manual and received an update about a ParentSquare account compromise during its April 9, 2025 meeting.

The review covered changes to the district’s data governance and disaster recovery arrangements, and administration described a limited intrusion into the ParentSquare messaging platform that resulted in unauthorized posts to high school staff accounts. Committee Chair Cara Meeker opened the review and Superintendent Kathleen Murphy introduced the presenters; Dan Albert, the district’s director for technology, led the presentation.

Albert said the district first created a data governance manual in February 2009 and that state law (referred to in the packet) requires the district to present the manual annually. He noted the formal data-governance policy itself had not been updated since 2018 and recommended minor title and responsibility updates.

“We really put a lot of work into a lot of the stuff in this manual as far as getting things done rather than just writing them down,” Dan Albert said. He described recent infrastructure changes: an on-site data center at Concord Heights School that now replicates to a secondary site at Millbrook School District, an archival server that preserves six months of backups, and cloud failover capability so core systems such as Munis can be spun up remotely for payroll or other critical functions. Albert also said the district backs its Office 365 and Google environments to a secondary cloud archive.

Albert described an ongoing effort to inventory district software, data privacy agreements and configured access applications. He said that compiling and maintaining a comprehensive inventory is labor-intensive for the district’s seven-person IT team but is useful for identifying unused or duplicate services and for faster incident response.

On the ParentSquare incident, Albert said the district identified a compromised ParentSquare account that was used to send posts to high school staff. “It does look like this account was compromised,” he said, adding that attackers attempted to access Google and Microsoft accounts but were blocked by multi-factor authentication and regional blocking. Albert said the intruders used a VPN to mask their IP address and that the district shut the service down while investigating. Superintendent Kathleen Murphy added that the compromise did not appear to reach district systems beyond the ParentSquare posts and that staff acted quickly to limit impact.

Committee members pressed for follow-up details, including whether students’ Social Security numbers were ever collected or stored and whether user training reduces phishing risk. Albert said student Social Security numbers are not collected or stored “for our systems” but noted he could not speak to every department. He also said the district has used phishing-test tools for years, has added reporting tied to Microsoft Defender, and can identify users who click malicious links to trigger password resets or remediation.

The district flagged several next steps during the discussion: update the data governance manual to reflect recent backup and disaster‑recovery changes, continue the software-inventory effort, tighten ParentSquare configurations or account protections where feasible, and provide a follow-up incident summary to the committee when more information is available.

Committee Chair Cara Meeker said the discussion was informational and that no formal action on the manual was expected at the meeting.

Ending: The committee did not take a vote on the manual at the meeting; staff were asked to bring updated material and any recommended policy edits to a future meeting for further review.