Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

San Marino Unified reports cybersecurity work, reviews PowerSchool incident response for families

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

District technology and business staff described monthly vulnerability scanning, a CISA penetration test and 24/7 monitoring, and said they are notifying families following a PowerSchool vendor breach; PowerSchool is offering two years of credit monitoring to affected users.

At the June 9 strategy session, San Marino Unified staff outlined cybersecurity work completed during 2024–25 and the district’s response to a cybersecurity incident affecting the PowerSchool student information platform.

Technology staff told the board the district receives monthly vulnerability scans, engaged the federal Cybersecurity and Infrastructure Security Agency (CISA) to perform a penetration test, and maintains 24/7 monitoring through its security partner. The presenter said the district also uses endpoint protection and has a low daily threat count compared with previous years.

The district discussed a separate incident at PowerSchool, the vendor that hosts its student information system. Staff reported that PowerSchool acknowledged a breach that exposed some client data and that the company is offering affected students and families two years of credit monitoring. San Marino Unified said it has acted as a communication channel for PowerSchool, notifying families and providing resources offered by the vendor; staff noted that PowerSchool hosts the system and that the district’s control over vendor‑side credential protection is limited.

Technology staff also described security investments the district is pursuing, including phased firewall replacement (current firewall end of life in 2026), continued 24/7 monitoring, moving endpoint protection solutions, and piloting multifactor authentication for students. Staff recommended periodic tabletop drills with the security JPA and additional phishing‑awareness training for employees.

No policy vote occurred during the briefing; staff said they would return with implementation details for technology projects and vendor remediation actions related to the PowerSchool incident.