Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Oregon City Schools adopts cybersecurity framework after district IT presentation
Summary
After a presentation on phishing training and an AI email-security tool, the Oregon City Board of Education voted to adopt an official cybersecurity program framework aligned with Ohio House Bill 96.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The Oregon City Board of Education voted May 19 to adopt an official cybersecurity program framework and authorize its implementation under Ohio House Bill 96 following a technical presentation on district cyber defenses.
Wes, the district's technology presenter, told the board the work is "moving from just an IT thing. It's really a process thing, a whole organizational effort," and described a three-part approach: adopt a recognized framework (the CIS controls), run annual staff cybersecurity training and phishing simulations, and deploy an AI-powered email-security tool to block malicious messages before they reach staff inboxes. He said phishing click-through rates dropped from about 17% to 6.75% over four months as staff completed training and simulations.
The presenter said the AI tool will classify roughly 8,500 incidents over a 90-day test period (about 93 per day in the district's review) and can remove or remediate flagged messages automatically. "It learns as it watches our environment to help make those decisions," he said, describing how the system reduces false positives by recognizing normal communication patterns.
Board members moved and seconded the resolution to adopt the cybersecurity framework and implement it in accordance with Ohio House Bill 96; the motion carried on a roll-call vote.
The district will complete an initial CIS control self-assessment this summer, finish the email-security rollout and tune the system for local operations, and continue annual staff training focused on common K-12 attack vectors such as business email compromise and phishing. The board did not set a public timeline for school-by-school implementation beyond the described summer work plan.
What happens next: district staff will finish the technical rollout this summer, report assessment results to the board and return with any recommended changes to training or tools.

