Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Iowa City Community School District reviews cybersecurity program; board approves Jan. 14 minutes

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Superintendent Decker briefed the Iowa City Community School District board on a multi-pronged cybersecurity program — funded largely through SAVE and subject to confidentiality under Iowa law — and the board approved the Jan. 14 minutes by voice vote.

The Iowa City Community School District Board on Thursday received a detailed briefing from Superintendent Decker on the district’s cybersecurity program and approved the Jan. 14 meeting minutes by voice vote.

Decker told the board the district has “had no significant cybersecurity events” but faces constant probing and attempted attacks, and described a five-part security program that includes network protection, staff and student training, regular testing (phishing simulations and tabletop exercises), external penetration testing, and formalized incident-response and data-governance processes. “We are attacked all the time,” Decker said, adding the work is critical to protect operations, the district’s reputation and student and staff personally identifiable information.

The presentation traced the program’s development back to a June 2023 board briefing and described steps taken since: implementation of a vCISO (virtual chief information security officer) program, consolidation of multiple management platforms into a single unified management platform, expanded threat detection (including a managed MXDR service with 24/7 monitoring), quarterly phishing simulations, incident-response tabletop exercises, and both external and internal penetration testing.

Decker said the district’s phishing-simulation results compare favorably with industry averages: “industry average is about 10 or 11%,” he said, and the district’s highest recorded click rate was 2.3%. He described follow-up training for staff members who repeatedly click simulated phishing links and said staff training and user behavior are a central focus because people are often the largest vulnerability.

On testing and exercises, Decker said the district runs penetration tests and tabletop incident-response exercises at least twice a year; external penetration testing has “passed with flying colors” the last three years, while internal tests routinely identify vulnerabilities that the district then remediates. He also described updating a business-impact analysis, incident-response and disaster-recovery plans, and work to formalize a data-governance framework and role-based permissioning.

Decker noted funding and confidentiality constraints. He said the cybersecurity program has been “largely funded through SAVE,” with some other sources tapped and limited general-fund staff time used for implementation. He said certain contract, platform, and insurance details are kept confidential and that “by Iowa law, we’re allowed to keep those confidential,” adding that the board could request more detailed information in closed session.

The superintendent said the district has been advocating through UEN for greater flexibility in the state’s management fund to allow more cybersecurity activities to be funded there; currently, he said, the management fund may cover cybersecurity insurance and an asset inventory but the state has drawn the line on other cybersecurity activities.

Board members who spoke praised the work. Board member Bridal (first reference in discussion) said the work is “massively disruptive” to people’s lives when attacks occur and thanked staff for the effort. The board then moved to a housekeeping item: a board member moved to approve the Jan. 14 minutes, a second was given, and the board approved the minutes by voice vote.

The meeting adjourned after the cybersecurity briefing and the minutes approval; Decker said he was available to answer further questions or to provide additional confidential details in closed session if the board desired.