Proactive Security Starts With Leadership
Of course, getting school leadership on board with the evolving needs of a cybersecurity strategy is a big factor in influencing what can actually be carried out by the IT team. Boggs says that having the backing of executive leadership has “reduced a lot of panic and frustration for me. Cybersecurity is not an IT problem. It’s an organizational issue that we all work together on. We may not be able to do everything, but there is a plan in place. It really does start at the top; without executive buy-in, you’re toast.”
Live Training as Long-Term Strategy
As artificial intelligence is infused into an increasing number of tools used to improve the classroom experience, it’s also aiding threat actors, who are exploiting the data being put into those very tools. Boggs believes this data governance challenge could be the biggest general risk schools face in the near future.
“Where is the AI tool being used? Is it an approved tool? Is there an agreement for your organization? Because how are you going to cover something you don’t know about?” says Boggs.
Because every school employee deals with some level of personally identifiable information, as well as data that belongs to the school district, Boggs says that awareness training is critical: talking with staff and making them aware of what can and cannot be put into AI tools. Recently, Cityscape began conducting dedicated, live AI awareness training sessions for its staff, deciding not to rely solely on sending out informational videos that may or may not be viewed.
“Do we have to do the video because of certain laws and requirements? Yes, but we’re also getting in front of our staff and actually talking, trying to make it engaging, so people don’t just tune out. There’s jokes and pictures of my cat on the screen to keep their attention. I’ll stand on my head if I have to,” Boggs explains. “I know that live training is not always feasible for larger districts,” he adds. “Smaller ones, you can normally get in front of your staff at least once a year. I find the most engagement is when you’re in person.”
Cyber Insurance Compliance
Although cyber insurance can also be important in case of an incident, the same rules apply as when shopping for any kind of insurance: Read the fine print.
“If the insurance company says you need to do these 10 things, and you've only done nine of those things, your coverage may lapse. They may not cover you because of that one item. Just because you have a policy doesn’t mean you don’t need to not review it," says Boggs.
Reaching Out for Resources and Community
Schools should always be on the lookout for free cybersecurity resources from national agencies and can also check to see what their state government offers. Boggs sees CIS as an excellent untapped resource for K–12 cybersecurity.
“The thing I’ve learned most is that we are better together. The worst time I ever had in this journey was the first six months, when I was by myself. I was embarrassed by what I didn’t know — and I didn’t know what I didn’t know. It got better once I started connecting with people,” says Boggs. He adds that “I know it can make you nervous, wondering, ‘What will people think? They’re probably so far beyond me, they might not even want to talk with me.’ I found that none of that’s true. They’re all willing to help you.”
