Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Godley ISD cybersecurity review: district reports a recent incident, plans stronger passwords and multifactor access

2695844 · March 18, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Godley ISD’s technology staff told trustees that the district is investigating a recent cybersecurity incident, will tighten password rules and require multifactor authentication for accounts with district‑wide access, and plans to move sensitive servers off site where possible.

Godley ISD technology staff told the Board of Trustees on March 17 that the district is investigating a cybersecurity incident and is preparing multiple technical and policy changes to reduce future risk.

In a cybersecurity update delivered during the superintendent’s reports, the presenter said national K‑12 trends show an increase in sophisticated attacks, social engineering and command‑and‑control compromises. The presenter said “82 percent of all K‑12 organizations last year reported a cybersecurity incident,” and that the district is already working with external partners to review logs and run forensic analysis on a recent breach.

District IT staff outlined immediate and planned changes: shorter password rotation cycles (the presenter said a 60‑day cycle was under consideration), longer passwords, mandatory multifactor authentication for any account with access to district‑wide data, elimination of legacy network subnets and tighter access control lists (ACLs). The presenter also said staff are working to move high‑risk or sensitive data off district‑hosted servers where feasible to providers with larger security budgets and that external monitoring services (analyzed by partners such as MS‑ISAC) will continue to be used.

The update noted that a single week’s firewall logs showed nearly a terabyte of traffic in and out of the district network, most of it routine (device updates, HTTPS traffic and Google/Chromebook updates) but that the volume can mask targeted threats such as remote‑access tools that attackers use for command and control.

The board was told the district has no currently known externally exposed vulnerabilities (an outside vendor reported none since the district engaged the vendor) but that forensics on the recent incident remain ongoing.

As part of a planned remediation program, technology staff said they will: require multifactor authentication on administrative accounts, increase password complexity and frequency of required changes, eliminate legacy subnets and reduce lateral movement potential inside the network, and expand staff cybersecurity training. The presenter said those measures are partly constrained by budget and that many K‑12 districts nationwide face similar funding gaps for cybersecurity.

Trustees asked about the investigation timeline; staff said the forensic review was roughly 90 percent complete and that they would brief the board further, likely in closed session, with additional technical findings and any recommended contractual actions. The district did not disclose specific technical indicators of compromise in open session.

The cybersecurity update was part of the superintendent’s regular reports and followed a question‑and‑answer exchange with trustees about risk, costs and timing for next steps.