Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

RSU 25 outlines expanded cybersecurity monitoring after prior incidents

RSU 25 School Board · February 26, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The district's technology lead described past ransomware and data‑exfiltration incidents and outlined new defenses—endpoint telemetry, a Security Operations Center (SOC), and Network Operations monitoring—intended to give 24/7 detection and isolation capability for devices and networks.

The RSU 25 technology lead briefed the board on the district’s cybersecurity posture, citing past incidents in 2017 and wider state activity in 2023. He said education is a frequent target for cyberattacks and described an operational shift toward continuous monitoring: endpoint telemetry, a Security Operations Center (SOC) to view device telemetry and isolate infected machines, and network‑level monitoring (Network Operations Center) to detect lateral movement.

The presenter said the district has moved from an open network to layered defenses, requiring software and devices to be approved through technology and curriculum review processes. He described periodic phishing/fish testing for staff, multi‑vendor comparisons of monitoring tools, and the planned use of third‑party vendors to provide affordable 24/7 monitoring. He emphasized the goals of protecting student and staff data, maintaining operations, and meeting insurer and vendor baseline requirements to secure cyber insurance coverage.

Board members asked about scope and staff burden; the technology lead said audits and monitoring take staff time but that vendor partnerships make continuous monitoring feasible. The briefing concluded with an ask for board support for budget and operational decisions needed to maintain the SOC and related services.