Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Winchester schools report 24/7 monitoring and full MFA rollout after federal pilot work
Summary
IT staff told the board the district has moved to continuous monitoring and completed multifactor authentication deployment for employees; a phishing-awareness grant component was denied and the district has filed an appeal.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
District IT staff updated the board on cybersecurity improvements June 8, saying the division has shifted from a reactive posture to a continuously monitored, layered security model aligned with federal guidance.
Brandon Smith, the district’s network engineer, said the district now has 24/7 monitoring and threat detection across devices, network traffic and core systems, and has deployed multifactor authentication (MFA) for all employee Google Workspace accounts. “MFA is now fully adopted across all staff,” Brandon Smith said, adding that one-on-one training helped staff in roles that do not use computers daily.
The presentation cited alignment with federal guidance from the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST). Staff described additional technical measures now in place: endpoint protection, intrusion detection, application-level controls via next-generation firewalls, network segmentation, patch management, vulnerability scanning and periodic penetration testing.
Staff also discussed a federal grant (roughly $180,000 over three years) that included funding for a phishing-simulation and security-awareness platform. District staff said the awareness/training component was denied in the initial award; an appeal has been submitted and staff expect a reconsideration. Board members praised district IT efforts and stressed the importance of the awareness work, which they said targets the human risk vector behind many incidents.
District officials said the goal is to reduce detection-to-response time, protect student data and minimize operational disruption to instruction, testing and transportation.

