Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

District technology staff briefs board on data-breach rules, common risks and insurance coverage

6423769 · October 14, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A district technology staff member briefed the board on the Personal Information Security and Breach Investigation Procedures and Practices Act (House Bill 5), recommended preventive steps for student Social Security numbers and said the district carries cyber coverage under its umbrella policy.

District technology staff briefed the Mercer County Board of Education on state reporting requirements and best practices in the event of a data breach and described common attack targets and the district's insurance posture.

The presenter told the board that since enactment of the Personal Information Security and Breach Investigation Procedures and Practices Act (commonly referred to in the meeting as House Bill 5) the district follows a published, multi-step notification and response process in the event of a compromise. Some notification tasks must happen immediately, others within 72 hours; the presenter said the Kentucky Department for Libraries and Archives is among the state offices that must be notified for certain breaches.

The staff member emphasized prevention and noted that the most common target in school systems is student Social Security numbers. The speaker said districts should remove or avoid storing Social Security numbers when not required and to delete them from old records where possible. The presenter said the district is covered for cyber incidents under its umbrella insurance policy but that the district has not purchased a separate cyber rider and that other districts sometimes do.

At least one board member asked about multi-factor authentication, technical specifics and the district's ability to discuss sensitive monitoring practices in closed session. Staff said they are willing to provide additional detail in a closed session for security reasons and will follow reporting timelines should a breach occur.

No formal board action was taken; the presentation was informational.