Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
District technology report highlights device rollout, phishing training and NIST planning
Summary
The district reported deployment of 6,500 Chromebooks and 1,200 iPads, a low recorded phishing susceptibility (~1.7%), new password policy changes following a state audit, 24/7 monitoring with Arctic Wolf and planning to align with NIST 2 under state education law.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
At the Nov. 4 Webster Central School District board meeting, district technology staff outlined recent device deployments, cybersecurity work and recommended policy changes following a state technology audit.
Mister Zimmer, the district's technology presenter, said the district has deployed about 6,500 Chromebooks and 1,200 iPads and uses student workers to enroll and prepare devices. He said the district maintains a three-year device-refresh cycle.
On cybersecurity, Zimmer said the district's phishing-prone rate sits at about 1.7 percent, below a cited industry average of about 4.3 percent, and that the district uses a training program called "Know Before." He described an ongoing partnership with security provider Arctic Wolf for 24/7 monitoring, penetration testing and monthly vulnerability scans.
Zimmer said a recent New York State education technology audit recommended a stronger password policy and limiting USB use because of malware risk. The district plans to update its password policy (discussing a 12-character standard) and to minimize USB usage while accounting for legitimate classroom needs such as photography and specialized labs.
He also said the district is preparing to transition to NIST 2 standards as part of compliance with state education law.
Board members asked operational questions about password notifications and how staff should report suspicious messages; Zimmer asked board members to contact him directly for follow-up and said the district triages suspected phishing attempts through central staff.
What happened next: the board thanked the presenters and there was no formal vote on cybersecurity policy changes during the meeting; any policy changes will appear in future board materials if proposed.

