Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Policy topic

No spam. Unsubscribe anytime.

Anderson 3 board advances cybersecurity policy and administrative rule on first reading; members press for clearer fraud and notification rules

Anderson 3 School Board of Trustees · March 9, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

On first reading the board approved a cybersecurity policy and companion administrative rule, and trustees asked staff to define "financial fraud," list business-email-compromise and wire-transfer fraud in the response plan, and add clearer reporting and high-risk-exception triggers for board notification.

The Anderson 3 School Board moved two cybersecurity items — a policy on cybersecurity and an administrative rule on information-security awareness — forward on first reading at its March 9 meeting, and several trustees urged the policy committee to add more specific definitions and notification requirements before the second reading.

"School districts are number one for cyber attacks. Number one. number one target and the number one victim," a committee member told the board after reporting on a presentation by a state cyber advisor; the committee member said that reality underscores the need for clear incident definitions and post-incident reporting to the board.

Board members pressed for three changes: a clear definition of "financial fraud" and inclusion of financial-fraud scenarios (fraudulent vendor payments, business-email-compromise, wire-transfer fraud) in the administrative-rule response plan; explicit thresholds that trigger mandatory board notification (rather than routine password resets); and post-incident briefings covering scope, systems affected, mitigation steps, potential risk and recovery status.

Miss Gray, the district technologist referenced by trustees, was singled out for her team's work: a board member praised the technology staff and pointed to a recent "security scorecard" the district runs as evidence the department has procedures in place, while also saying the policy should codify those protections for future boards.

What’s next: both the policy and the administrative rule passed first reading by voice vote and were sent back to the policy committee for revisions. Trustees said they expect the committee to return a revised draft addressing the fraud definitions, incident scope, and reporting cadence before the second reading.