Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

District technology report highlights device rollout, phishing training and NIST planning

Webster Central School District Board of Education · November 5, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The district reported deployment of 6,500 Chromebooks and 1,200 iPads, a low recorded phishing susceptibility (~1.7%), new password policy changes following a state audit, 24/7 monitoring with Arctic Wolf and planning to align with NIST 2 under state education law.

At the Nov. 4 Webster Central School District board meeting, district technology staff outlined recent device deployments, cybersecurity work and recommended policy changes following a state technology audit.

Mister Zimmer, the district's technology presenter, said the district has deployed about 6,500 Chromebooks and 1,200 iPads and uses student workers to enroll and prepare devices. He said the district maintains a three-year device-refresh cycle.

On cybersecurity, Zimmer said the district's phishing-prone rate sits at about 1.7 percent, below a cited industry average of about 4.3 percent, and that the district uses a training program called "Know Before." He described an ongoing partnership with security provider Arctic Wolf for 24/7 monitoring, penetration testing and monthly vulnerability scans.

Zimmer said a recent New York State education technology audit recommended a stronger password policy and limiting USB use because of malware risk. The district plans to update its password policy (discussing a 12-character standard) and to minimize USB usage while accounting for legitimate classroom needs such as photography and specialized labs.

He also said the district is preparing to transition to NIST 2 standards as part of compliance with state education law.

Board members asked operational questions about password notifications and how staff should report suspicious messages; Zimmer asked board members to contact him directly for follow-up and said the district triages suspected phishing attempts through central staff.

What happened next: the board thanked the presenters and there was no formal vote on cybersecurity policy changes during the meeting; any policy changes will appear in future board materials if proposed.