Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

District technology director briefs board on recent data breach risks, state breach-notification law

5681214 · August 25, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

District technology staff briefed the Mercer County board on cybersecurity requirements, a recent phishing incident and priorities to reduce exposure of student Social Security numbers; staff offered a closed-session briefing for technical details.

District technology staff told the board that August is Cybersecurity Awareness Month and summarized state breach-notification requirements and recent incidents affecting the district.

The presenter referenced the Personal Information Security and Breach Investigation Procedures and Practices Act (described in the meeting as the state’s breach-notification law) and said Kentucky requires specific notification steps and timing in the event of a data breach. The technology lead said the most common target in school systems is student Social Security numbers, and recommended reducing retention of SSNs where not required and deleting SSNs from old student records when possible.

The presenter said the district carries cyber coverage as part of an umbrella insurance policy and that other districts buy separate cyber riders with higher caps; legal counsel often advises on the proper coverage. The presenter described a recent phishing attempt that impersonated a district administrator and said staff deleted the messages before they caused harm. Because security-process specifics are sensitive, the presenter offered to provide a closed session briefing for board members to review technical monitoring and incident response procedures.

Board members asked whether the district’s insurance and procedures were adequate; staff said they carry cyber coverage under the district’s umbrella policy and that their approach is largely preventative: reducing data retention, training staff, and following the 11-page state guide on breach response. Staff emphasized time deadlines for notification and the list of entities the district must notify in a breach, which includes several state agencies.