Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Wayzata highlights ransomware tabletop, S2SCORE and new Minnesota cyber-reporting requirement
Summary
District IT described an October 24, 2024 ransomware tabletop exercise and the S2SCORE risk metric, and reviewed Minnesota's requirement (Section 16E.36) that schools report cyber incidents within 72 hours beginning Dec. 1, 2024.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Wayzata Public Schools told the board it has exercised its incident response plan in a tabletop ransomware scenario and is using external risk measures to guide cybersecurity priorities.
Slides summarized an Incident Response tabletop exercise run on Oct. 24, 2024 that simulated a phishing attachment leading to a ransomware event; the post-mortem outlined communication, escalation procedures and a timeline of simulated actions. The district also cited use of S2SCORE as an information-security risk metric and said that a "Satisfactory" S2SCORE reflects investment in an information-security program.
The presentation referenced Minnesota statutory requirements for cyber-incident reporting: Section 16E.36 of the Public Safety and Judiciary Omnibus law, noting that school districts must report cybersecurity incidents within 72 hours and may use the Cyber Incident Reporting Form at mn.gov/mnit/cir. The slides named MNIT Cyber Navigators and MNIT SOC/BCA as state resources for schools.
District materials recommended continuing tabletop exercises, refining escalation paths and ensuring reporting compliance with state requirements as part of routine preparedness.
