Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Board hears update on past phishing incident, district outlines strengthened cyber controls

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Trustees received a staff report on a prior vendor-based phishing incident and were briefed on steps taken since, including multi-factor authentication, a 14-character password policy, endpoint protection and mandatory staff training.

The Excelsior Springs School District board discussed a past phishing incident involving a compromised vendor account and heard a summary of steps the district has taken to reduce future risk.

District staff described the incident as a sophisticated phishing attempt executed through a vendor account. Technology staff and administration said the district tightened controls after the event: password rules were updated to require at least 14 characters; administrators must use two-factor authentication; the district runs daily network and system monitoring; Sophos endpoint detection software protects district devices; Securly web filtering is applied to student and staff accounts; and the technology team manages student devices so only approved apps can be installed.

Dr. Bolamore (staff) said the district also changed its payment and invoice-review procedures to require multiple verifications when change requests or payment requests are received. Technology staff will deliver a 30-minute professional-development session at each building in 2025–26 focused on email safety and best practices. The district emphasized that employees will never receive a legitimate district email asking them to submit or change passwords via email or in a shared document.

Board members asked why the previous incident had been handled largely in closed session. Administration explained the matter involved pending legal action with the vendor and was kept in executive session while litigation and settlement discussions were underway; the district later reached a settlement and the matter returned to open discussion when it was concluded.

Technology director John Coleman was cited as the primary technical lead; the transcript records statements about his work and the steps taken to strengthen security controls. Trustees thanked technology staff and requested continued updates and training for staff on phishing recognition and other cyber risks.