Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

North Penn SD cybersecurity audit rates district "fair" as director details upgrades

North Penn School District Safe Schools Committee · March 25, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At the March 24 Safe Schools Committee meeting, Dr. Kristen Landis reported the district moved into the "fair" category with an FR Secure level-3 audit score of 614 and described infrastructure upgrades (next-generation firewall, dual 10-gig internet paths), immutable off-site backups, stronger identity controls, weekly external vulnerability scans and planned purple-team exercises.

Dr. Kristen Landis told the North Penn School District Safe Schools Committee on March 24 that the district's annual cybersecurity audit has shown measurable improvement and that the program will continue to expand its technical and procedural protections.

Landis said the district began formal cybersecurity work several years ago and has steadily improved under a multi-year partnership with FR Secure, which the district renewed for another five years. She reported the district moved from a starting "poor" rating into the "fair" category and cited a current audit score of 614 under a new level-3 assessment that added 291 controls across technology and administrative processes.

Why it matters: school-district networks host student records and operational systems that could disrupt instruction if compromised. Landis emphasized that upgrades are intended to reduce both the risk of intrusion and the time required to recover from incidents.

Landis outlined a series of recent and ongoing upgrades: the district installed a next-generation firewall with AI-assisted threat ingestion, upgraded core routing and edge switching (moving toward a single pane of management), and maintains two 10-gig internet connections for redundancy'one to Comcast at 401 North Broad in Philadelphia and a backup link to the Montgomery County Intermediate Unit that follows a divergent path.

She also described data protection steps, saying the district now stores off-site backups in two separate cloud locations with immutable backup capability to limit ransomware risk. Landis said the district will schedule a disaster-recovery tabletop exercise next year to test recovery procedures.

On account and identity protections, Landis said the district requires multifactor authentication for all staff and for high school students in grades 10'12, enforces password policies for younger students (this year second graders are required to set 12-character passwords and all students must change passwords annually), and requires vendors to connect only through the district VPN and Duo MFA.

Landis said vulnerability scanning is performed twice yearly internally and weekly externally, and the district takes advantage of free federal services where appropriate. She added the district's EDR vendor is rolling out statewide identity-management services that will help the district close old service accounts and better track required logins.

Looking ahead, Landis said the district will conduct four purple-team exercises (an outside red team attempts to exploit systems while an internal blue team defends) to identify gaps not caught in the audit.

Committee members praised the progress and asked about disaster recovery and how the cybersecurity audit overlaps with the business office's financial internal-controls testing. Miss Hauser (business office) described the two audits as separate but partially overlapping: the financial audit focuses on business-office internal controls while the cybersecurity audit focuses on system access and protection.

Miss Hauser told the committee the district's current cyber-insurance carrier is Chubb and that renewal applications are underway.

Procedural notes: the committee approved the Feb. 24 minutes earlier in the meeting and treated Landis's report as an informational item. Landis is scheduled to retire after spring break; Missus Lindsay Smith was introduced as the incoming director of technology who will work with Landis in the coming weeks.

The committee did not take formal action on policy changes during the meeting; Landis's update was informational and followed by committee questions. The Safe Schools Committee closed the meeting after a brief student-representative report.