Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
State cybersecurity official warns boards to prepare: '''organizations will be breached, some won't know it
Summary
Iowa's state chief information security officer briefed the board on current cyber threats (ransomware, supply‑chain attacks, credential compromise), lessons from the Des Moines Public Schools incident and steps districts can take to reduce risk and speed recovery.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
State cybersecurity leadership briefed the board on threat trends, preparedness and response resources available to districts and other political subdivisions.
The official urged boards and administrators to treat cyber events like other crises and to build tested plans in advance. “I truly believe that there are two types of organizations: the first are ones that have been hacked when they know it, and the other is ones that have been hacked and they don't know it,” the state cybersecurity official said.
Key takeaways from the briefing: - Threat landscape: state‑sponsored actors, cybercriminal ransomware groups and credential compromise (phishing and business‑email compromise) are the most active threats. Supply‑chain breaches targeting vendors were also highlighted. - Incident response: the official described an incident in which early detection and state response teams blocked a ransomware intrusion targeting a political subdivision. The official said having an updated computer security incident response plan and a named incident response team shortens recovery time and reduces costs. - Practical steps: recommended practices include regular staff phishing training, documented recovery and continuity plans, mapping where sensitive student and employee data are stored, limiting data retention to what is needed, and testing plans periodically.
Resources and next steps: the state has a 24/7 cyber help line that districts can call and an Iowa cyber incident response team that can augment local teams and coordinate federal law enforcement and National Guard support when needed. The official encouraged districts to run phishing tests, exercise recovery procedures and use state incident‑response resources early in an event.
Board members asked how long an intrusive actor typically needs to move from initial access to data exfiltration; the official said that dwell times vary by sophistication and tools, and have shortened recently as adversaries automate parts of their work.
Why it matters: Cyber incidents can interrupt payroll, school bus routing, cafeteria services and real‑time access to student medical and special‑education records — operational functions that school leaders depend on.

