The Superintendent’s Worst Fear
ESC Region 1 Finance Advisory Council November 10
The Superintendents Worst Fear ESC Region 1 Finance Advisory - - PowerPoint PPT Presentation
The Superintendents Worst Fear ESC Region 1 Finance Advisory Council November 10 Superintendents Imagine having to notify parents or employees that their personal privacy has been violated!!!!!! Martin Yarborough BS, MEd, PhD (Tarleton
ESC Region 1 Finance Advisory Council November 10
Superintendents
Imagine having to notify parents or
employees that their personal
privacy has been violated!!!!!!
Objective of this Discussion
I want to provide you a recipe for, maybe not preventing but certainly mitigating, cyber attacks
…a malicious breach of a school’s security to expose sensitive and confidential data.
Cybercrime has …
…touched organizations of every size and shape in every industry – including K-12 school districts.
Cybercrime looks like …
…students hacking into databases to change grades. …hackers instigating a DDOS (denial of service) attack which stops electronic testing. …thieves stealing personal identification information (PII) and posting it on the internet. …staff losing a laptop or tablet with access to highly sensitive information. …ransomware being used to hold a district hostage and costing thousands of $$$.
Equifax
So What …
An attack on a school’s IT system can compromise the ability to teach. If personal information is exposed, districts may be subject to penalties under FERPA including the loss of potential federal funding. Civil Lawsuits could cost millions. Districts may find they aren’t covered for damages under traditional business interruption insurance policies. District business offices may not be able to function for a period of time and fulfil timely requirements such as payroll.
One thing is clear…
place.
Is this for real?
2016 Netwrix survey
2016 Netwrix survey
2016 Netwrix survey
49% of educational institutions have faced security incidents caused by human errors, and 37% have had security incidents due to malware.
2016 Netwrix survey
2016 Netwrix survey
Educational institutions named lack of budget (74%), lack of time (54%) and insufficient participation of senior management (44%) as the main obstacles to taking a more efficient approach towards cyber risk management.
2016 Netwrix survey
2016 Netwrix survey
Oh My! This is for real
May 22, 2017 Texas Association of School Boards Inadvertently posted the names and social security numbers of Texas school employees publically
Corpus Christi ISD Laredo ISD Edcouch-Elisa ISD La Hoya ISD Laredo ISD Los Fresnos CISD Mission CISD Monte Alto ISD Progreso ISD Rio Grande City CISD Lyford CISD McAllen ISD San Perlita ISD South Texas ISD United ISD Weslaco ISD Victoria ISD Calhoun County ISD Goliad ISD Halletsville ISD Shriner ISD Killeen ISD Ector County ISD Leander ISD Round Rock ISD Alief ISD San Benito CISD Fort Worth ISD Beaumount ISD Bridge City ISD Port Arthur ISD Kountze ISD West Orange-Cover CISD Midway ISD Temple ISD Robinson ISD Glen Rose ISD Pflugerville ISD
2017 Argyle ISD Victim of an email phishing scheme. Employees were victimized by a W-2 scam affecting most employees as reported by EdTech Strategies.
2016 Region XI Service Center A cyber attack that paralyzed the websites of at least 2 area school districts for several days and sidelined the websites of many more in the region. Affected commerce, testing and student records.
May 12, 2017 Mesquite ISD Food & Nutrition Services was hit by a cyber attack that crippled the POS systems and affected student nutrition accounts.
May 14, 2017 DeWitt-Lavaca SPED Cop Encountered a ransomware attack which compromised all student SPED records. The files were encrypted rendering them inaccessible and non-functioning. Data was lost and had to be re-created.
2017 Calallen ISD Encountered a ransomware attack which compromised all computers in the district. The attack infected most servers in the district.
2016 Santa Rosa ISD Encountered a malware attack causing the district to go without computers and telephones while repairs were made.
Why?
Since 2005,
educational data records have been compromised.
and HiEd) cyber security breaches have been reported and made public.
Cyber crime may not be prevented… 70% of the issues are human-caused 30% are caused by technology.
But …
Cyber security Awareness program.
ability to develop awareness programs.
breach occurs!
How…
The ideas, customs and social behavior of a particular society that allows them to be free from danger
Establishing a model for security involving risk management, security design, security implementation and verification. Defining how an
addresses constraints
protect the physical and information technology assets.
Texas Schools need a common approach
The madness has to stop!!!
Lets see how it can work implementing in 7 phases ….
Prioritize and Scope
calculates risk.
Prioritize and Scope Orient
now”.
how they work.
Increasing Maturity
Prioritize and Scope Orient Create a Current Profile
the framework enablers and assign each a Framework Tier level.
Prioritize and Scope Orient Create a Current Profile Conduct a Risk Assessment
Assessment.
and compare to perception of Current Profile.
(internal/external)
Prioritize and Scope Orient Create a Current Profile Conduct a Risk Assessment Generate a Target Profile
generate a Target Profile.
Assessment
Prioritize and Scope Orient Create a Current Profile Conduct a Risk Assessment Generate a Target Profile Analyze, Prioritize and Determine Gaps
the Target (TO-BE) and identify the gaps.
Prioritize and Scope Orient Create a Current Profile Conduct a Risk Assessment Generate a Target Profile Analyze, Prioritize and Determine Gaps Develop and Implement Action Plans
series of project proposals.
competent project manager.
communication plans and quality plans for each identified gap.
You may need some help to do this ….