Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Board hears details of past phishing incident; district outlines new cyber safeguards

Excelsior Springs School Board · May 14, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Administrators described a prior sophisticated phishing incident involving a compromised vendor account, legal actions and settlement, and a set of security measures now in place—including mandatory two‑step verification for admins, 14‑character minimum passwords, endpoint detection, web filtering and planned staff training.

The board received a briefing on a prior cyber fraud incident that targeted the district through a compromised vendor account. Administrators said the incident was executed via a vendor account used to request changes or payments and that it prompted legal action; the district and the vendor ultimately reached a settlement and the matter had been handled largely in closed sessions while litigation was pending.

Administrators outlined a suite of safeguards the district has implemented since the incident: stronger password rules (minimum 14 characters), mandatory two‑step verification for all administrative accounts, regular staff training and simulated examples, Securly web filtering for student and staff accounts, Sophos endpoint detection on district devices, daily network and system monitoring, controlled app installation for student devices, monthly patching of critical systems and subscription to external threat‑alert services. The district’s insurance provider (Musick) requires adherence to a seven‑step cyber security framework as a condition for coverage.

Board members asked why the public had not been informed earlier; administrators explained that the incident involved pending legal action and therefore parts of it were handled in closed session until settlement obligations allowed disclosure. Administrators acknowledged the incident remains a reminder of the ongoing risks and said a 30‑minute staff professional development module on email safety will be provided across buildings in 2025–26.

Direct quote from the briefing: “The incident that happened then was a sophisticated phishing attempt executed through a compromised account of one of our vendors,” an administrator said.

Next steps: technology staff will deliver the planned PD on email safety, continue system monitoring, and report any material developments back to the board.