Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Board rejects member-led data‑protection resolution after debate over cost and liability

New Hanover County Board of Education · August 4, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Board member David Perry proposed a resolution to limit use of cloud/multi‑tenant architectures for student data after recent statewide breaches; staff said vendors must meet SOC 2 standards and carry cyber insurance. The motion failed by roll call, 1–6.

David Perry, a board member, urged the New Hanover County Schools board to tighten how the district stores student data and to favor architectures that isolate district information from multi‑tenant vendor platforms.

"What we've seen over the last 18 months is two data breaches that happened within North Carolina," Perry said, citing PowerSchool and Canvas incidents and arguing that certifications alone do not guarantee safety. He moved to adopt a resolution that would direct the district toward data isolation and stricter vendor architecture requirements; another member seconded the motion to allow full discussion.

Staff answered detailed questions about what data vendors receive and what safeguards exist. "For some of our systems, yes," a district staff member said, describing directory information shared for authentication (first name, last name, email, grade) while noting that Infinite Campus contains more sensitive records and that the district requires SOC 2–type audits of vendors that access that data. The staff member added, "We have cyber security insurance for that very reason. The liability would fall into the insurance company," and said the district holds vendors to high standards when they access Infinite Campus data.

Board members split on trade‑offs between security and cost. One member pointed to an estimate in the packet of about $214,500 for equipment and said that hiring additional IT personnel could come at the expense of classroom positions. Perry countered that the district should not simply rely on third parties and that changes could be phased in. Another member highlighted that no system is absolutely hack‑proof: "A certification from an outlying person doesn't mean crap," Perry said, arguing for architecture change over certifications alone.

After discussion and a roll‑call vote, the motion to adopt the resolution failed, recorded in the meeting as defeated by 6 votes to 1. The board then moved on to other business.