Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the K12 Cybersecurity topic
No spam. Unsubscribe anytime.
Task force hears cybersecurity warnings for K–12 systems; UETN and vendors urge basic protections and statewide coordination
Summary
Vendor and network officials warned the task force that students' data and K–12 systems in Utah face active threats; presenters recommended multifactor authentication, endpoint detection, zero‑trust frameworks, vendor accountability and a coordinated state approach.
Get email alerts on the K12 Cybersecurity topic
No spam. Unsubscribe anytime.
Officials from cybersecurity vendors and the Utah Education and Telehealth Network (UETN) briefed the Utah School Security Task Force on active digital threats to school systems and recommended baseline protections and state-level coordination.
Kevin Lopez, representing Fortinet, described a string of recent breaches affecting companies that provide services to schools. Lopez said many breaches could have been blocked or mitigated with relatively basic protections such as multifactor authentication (MFA), endpoint detection and a zero‑trust approach that limits access to only the applications a given user needs. He told the task force that MFA can reduce the risk of account compromise by up to 99% (industry estimates), and he outlined vendor‑management steps such as contractual security requirements (SOC 2, NIST standards, FedRAMP for cloud services) and requiring risk‑assessment reports from vendors.
Spencer Jenkins, with the Utah Education and Telehealth Network, explained UETN’s role as the statewide education network and described incidents where UETN detected anomalous traffic — for example, a distributed denial‑of‑service attack against a school hosting an esports event — and was able to work with the local district to mitigate the attack. Jenkins said UETN is commissioning a statewide security posture assessment across K–12 and higher education to identify gaps and inform potential managed services; UETN said a report and recommendations are forthcoming.
Representative Ryan D. Wilcox, chair, told members he has tracked recent compromises and said that, “last week, 170,000 records that I’m aware of” of student data were compromised. The task force also learned that the legislative auditor has commenced an audit into school cybersecurity; Jenkins confirmed the audit began the same morning and said that the results should help guide state planning.
Task force members and presenters highlighted several near‑term best practices: - Implement multifactor authentication on education systems that hold student or staff data. - Deploy endpoint detection and response (EDR) tools on devices that access school data. - Build a zero‑trust network access model and use role‑based privileged access management to limit who can change critical systems. - Hold vendors to security standards in contracts (SOC 2, NIST guidance, FedRAMP where applicable) and request vendor risk assessments. - Consider statewide managed services or shared detection platforms so districts that lack IT staff can benefit from centralized monitoring and incident response.
Jenkins said UETN and other partners will pursue funding and federal opportunities to support statewide services, and he recommended the task force treat cybersecurity as part of overall school safety planning.
Members asked for basic cybersecurity standards to be included in the task force’s work and for continued coordination between UETN, the Division of Technology Services and local districts.
