Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Audit topic

No spam. Unsubscribe anytime.

Auditors: Utah K–12 cybersecurity practices lag; higher education stronger but inconsistent — committee refers audit

Utah Legislature Audit Subcommittee · September 25, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Legislative auditors told the audit subcommittee that many K–12 school districts in Utah lack baseline cybersecurity protections — including multifactor authentication, incident response plans, and patch management — and that higher education institutions show stronger but inconsistent controls.

State auditors presented a cybersecurity performance audit showing significant gaps in cybersecurity practices across Utah’s local education agencies and inconsistent implementation of controls in higher education.

Auditors said that, based on surveys and limited active testing, many K–12 LEAs had not implemented baseline controls identified by the Cybersecurity and Infrastructure Security Agency (CISA), especially incident response planning, staff training, multifactor authentication (MFA), and timely patch management. Chris McClelland, one of the audit presenters, cited two school-district breaches in the past year that exposed 450,000 student records and 30,000 employee records and said stronger MFA and patching might have prevented those incidents.

On higher education, auditors noted stronger baseline cybersecurity controls but inconsistent policies and accountability across institutions; they recommended that the Utah Board of Higher Education clarify policy and accountability and that the Legislature study minimum standards and barriers facing LEAs.

Commissioner Jeff Landward and system CIO Steve Hess responded that the Board of Higher Education has adopted CIS-based standards and uses a shared CIO model (University of Utah support) to help less-resourced institutions; they said the system will revise policy to improve accountability. The auditors and higher-education officials discussed the cost-effectiveness of baseline measures such as MFA and training.

President Adams moved to refer the public and higher education cybersecurity performance audit to the Education Interim Committee (lead) and relevant appropriations subcommittees; the referral passed by voice vote. Committees will consider whether statutory standards, board policy, or other measures are the appropriate path to raise baseline cybersecurity across schools.

Provenance: topic introduction at SEG 1310; findings and examples through SEG 1469; response SEG 1600–1760; referral motion SEG 1825–1845.