Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
RSU 25 outlines expanded cybersecurity monitoring after prior incidents
Summary
The district's technology lead described past ransomware and data‑exfiltration incidents and outlined new defenses—endpoint telemetry, a Security Operations Center (SOC), and Network Operations monitoring—intended to give 24/7 detection and isolation capability for devices and networks.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The RSU 25 technology lead briefed the board on the district’s cybersecurity posture, citing past incidents in 2017 and wider state activity in 2023. He said education is a frequent target for cyberattacks and described an operational shift toward continuous monitoring: endpoint telemetry, a Security Operations Center (SOC) to view device telemetry and isolate infected machines, and network‑level monitoring (Network Operations Center) to detect lateral movement.
The presenter said the district has moved from an open network to layered defenses, requiring software and devices to be approved through technology and curriculum review processes. He described periodic phishing/fish testing for staff, multi‑vendor comparisons of monitoring tools, and the planned use of third‑party vendors to provide affordable 24/7 monitoring. He emphasized the goals of protecting student and staff data, maintaining operations, and meeting insurer and vendor baseline requirements to secure cyber insurance coverage.
Board members asked about scope and staff burden; the technology lead said audits and monitoring take staff time but that vendor partnerships make continuous monitoring feasible. The briefing concluded with an ask for board support for budget and operational decisions needed to maintain the SOC and related services.

