Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
District outlines response to PowerSchool breach; technology audit identifies low-/higher-impact steps
Summary
District technology and finance staff told the board a late-December PowerSchool breach affected student and staff records nationally; the district said PowerSchool paid a ransom, is investigating, and the district is conducting audits and staged remediation work while monitoring potential exposure.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The director of technology told the board the late-December PowerSchool breach was a large, nation-wide incident that included student and staff personally identifying information (dates of birth, names, home addresses and parental contacts). He said PowerSchool "paid the ransom" and is conducting an investigation; district staff have posted guidance, sent emails to staff, and opened claims with insurers and working groups (PACE) while monitoring the risk of disclosure.
The technology director also described recent security audits. An independent consultant performed a CIS-controls-based audit identifying immediate 'low-hanging fruit' steps (policy changes, backups) and a 60-day plan for items with some user impact; higher-impact work will be scheduled for summer. An ESD security scan is in progress. Staff emphasized that end users remain the primary vulnerability and described plans for simulation-based training to reduce phishing and credential risks.

