Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
District says it was not affected by PowerSchool breach; IT director details protections
Summary
District technology staff told the board Platte County School District #1 was not impacted by the late-December PowerSchool breach and described layered defenses—endpoint detection, a state-managed enterprise firewall with geo-fencing, ACLs, VPN plus multifactor authentication, and employee phishing tests—that they say prevented compromise.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Mister Gonzales told the board that although the PowerSchool incident in late December affected some organizations, "I am happy to report our school district was not involved." He said the likely attack vector in that incident was third-party access through a customer-service portal and that the district’s security posture — including advanced antivirus and endpoint detection, a state-managed enterprise firewall with geo-fencing and ACLs, and multifactor authentication for VPN remote access — prevented a breach of district systems.
Gonzales described operational practices: real-time monitoring of servers for vulnerabilities and suspicious activity, periodic phishing tests of staff, and a practice of monitoring any remote vendor access in real time. He told the board the state helped set up the enterprise firewall and that geo-fencing blocked the IP ranges used by the threat actor involved in the PowerSchool incident.
When asked whether staff email would require two-step authentication, Gonzales said stronger authentication is likely coming soon. He also described proactive password-hygiene measures, including testing the district password database against cracking tools and forcing resets when weak passwords are found.
The board did not vote on cybersecurity policy at this meeting; Gonzales’ presentation was an informational update and the board encouraged continued vigilance and potential rollout of two-factor authentication for staff.

