Cybersecurity Best Practices According to 3 Superintendents - GovTech

2024-01-22 13:44 (EST) - Lauraine Langreo

DEVELOP A PREVENTION AND RESPONSE PLAN

COMMUNICATE THE WHY BEHIND THE PLANS

(TNS) — Cybersecurity continues to be the No.1 technology concern for district technology leaders as schools have become much bigger targets for cyber attacks.There have been 1,619 publicly disclosed cyber attacks on schools between 2016 and 2022, according to K12 Security Information Exchange, a nonprofit focused on helping schools prevent cyber attacks.These incidents can cause major disruptions to teaching and learning and to administrative functions in a district. The attacks can also put sensitive data about students and employees at risk. In some cases, school districts have had to shut down schools for several days.Given those consequences, its imperative for district leaders to understand why they need to make cybersecurity a priority.In a Jan. 8 webinar hosted by the Consortium for School Networking and AASA, the School Superintendents Association, three superintendents shared their best practices for preventing and responding to cyber attacks. They are Peter Aiken of the Central York district in Pennsylvania, Gustavo Balderas of the Beaverton district in Oregon, and Mark Benigni of the Meriden district in Connecticut.Here are their tips:The three superintendents underscored the importance of having a plan that will help prevent or discourage cyber attacks, as well as a plan to respond to cyber attacks because they can happen to any district. (In fact, they all said their districts have been hit with some form of cyber attack).When it comes to preventing attacks, the panelists said providing "continuous" cybersecurity training for students and staff is "critical." Everyone who uses district technology should be trained on having good online habits so that they dont click on the wrong links, fall for phishing attacks, or accidentally give out sensitive information that hackers can use to attack a districts network.For staff, these trainings could be part of the annual training requirements that most districts have, Benigni said. They could also be part of the onboarding process for new staff members. For students, digital citizenship and online safety training could also be required.A response plan should include how leaders are to notify the school or district community, as well as law-enforcement agencies, Benigni said.It should also include mitigation and recovery strategies. For instance, when the Meriden school district had a few devices that were hit by a ransomware virus, Benigni said his district was prepared because they back up their devices regularly. They restored the devices from the latest cloud backup instead of paying the ransom.Districts should have backup plans to ensure learning isnt disrupted when technology is disabled because of a cyber attack, as well. Teachers should be "prepared to go old school" and make sure students are still learning, Balderas said.The three superintendents identified communication as being just as important as having a prevention and response plan. Part of the cybersecurity training for staff and students should include communicating why its important that a district secures its networks."I think the more available we can make ourselves and communicate the rhyme and reason, the why behind [the districts cybersecurity practices]," the more likely people will buy into them, Aiken said.How a district leader reacts and communicates with the community — students, staff, parents, local media — after a cyber attack is also critical because it could affect the districts credibility and reputation, Balderas said."Make sure you react quickly with all the information you can share and be very resolved in terms of what youre going to do to deter [attacks] in the future," he said.District leaders across the country should make it a priority to share best practices with one another, too, the panelists said."I think its important we learn from one another because most school systems are not going to have their own cybersecurity division to take action on these issues," Benigni said.

Source

Previous
Previous

Carnegie Mellon Cyber Attack Compromises Data of 7,300 People - GovTech

Next
Next

How small contractors can prepare for new cybersecurity rules - Federal News Network