Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

District officials report tabletop cyber exercise, ongoing phishing tests

2154212 · January 28, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Administrators briefed the Safe Schools Committee on a regional cybersecurity tabletop exercise, ongoing vulnerability scanning and phishing tests, and annual updates to district cybersecurity posture.

District administrators told the Safe Schools Committee they attended a Multidisciplinary Cybersecurity tabletop hosted by the Montgomery County Intermediate Unit (MCIU) to test response plans and interagency coordination.

Marcus Roan described the exercise as an opportunity for administrators to practice notifications, continuity and response after a simulated hack. "We had the opportunity to go to the MCIU and participate in a cybersecurity tabletop exercise," Roan said, noting the scenario centered on data compromise and ransom. He added that the exercise helped administrators consider communications strategy and continuity of operations if key systems were unavailable.

Dr. Landis, the district’s director of technology, and others took part; administrators said federal agency representatives, including FBI and CIA panelists, contributed subject matter expertise. Dr. Bauer, who briefed the committee on district cybersecurity investments, said the district began annual independent cybersecurity assessments around 2018 and conducts daily vulnerability analysis and regular phishing tests. "Every year, we've made great strides," Bauer said.

Committee members described the emphasis on procedures — who communicates what and when — as a primary lesson from neighboring districts that have experienced breaches. Administrators said the district uses third‑party assessments, phishing campaigns and vendor services to track and reduce risk; they did not disclose exact vulnerability scores or detailed technical findings in the public meeting for security reasons.

Phishing tests: administrators said simulated phishing campaigns are ongoing. Dr. Bauer noted employees and board members are included in exercises; he gave an example in which a principal fell for a simulated Starbucks gift‑card phishing test and inadvertently instructed staff to click a link. The principal and staff received free coffee from the vendor as an anecdotal outcome; administrators framed the event as a training moment, not a real breach.

What the committee will do next: administrators said they will continue periodic updates to the committee and the board on cybersecurity posture. No formal action or vote was taken on cybersecurity items at the meeting.