Artwork for podcast Talking Technology with ATLIS
Strengthening K-12 Cybersecurity and Vendor Risk Management with April Mardock
Episode 1244th August 2026 • Talking Technology with ATLIS • Association of Technology Leaders in Independent Schools (ATLIS)
00:00:00 00:58:41

Share Episode

Shownotes

April Mardock, Chief Information Security Officer at WASIPC, joins the podcast to analyze the primary entry points targeted in K-12 ransomware incidents. The discussion offers actionable guidance on multi-factor authentication, vendor risk management, data retention policies, and using gamified tabletop exercises to prepare school leadership for cyber incidents.

Transcripts

Peter Frank:

Welcome to Talk Technology with Atlas, the show

Peter Frank:

that plugs you into the important topics and trends for

Peter Frank:

technology leaders, all through a unique independent school

Peter Frank:

lens. We'll hear stories from technology directors and other

Peter Frank:

special guests from the independent school community,

Peter Frank:

and provide you with focused learning and deep dive topics.

Peter Frank:

Kevin Warenda, TLIS: Hello, everyone, and welcome to Talking

Peter Frank:

Technology with Atlas. I'm Kevin Warendo, Director of Information

Peter Frank:

Technology Services at the Hofstra School in Lakeville,

Peter Frank:

Connecticut,

Bill Stites:

and I'm Bill Stites, the Director of

Bill Stites:

Technology at Montclair Kimberly Academy in Montclair, New

Bill Stites:

Jersey,

Hiram Cuevas:

and I'm Hiram Cuevas, the Director of

Hiram Cuevas:

Information Systems and Academic Technology at St. Christopher

Hiram Cuevas:

School in Richmond, Virginia.

Hiram Cuevas:

Kevin Warenda, TLIS: All right, gentlemen, I made it. The

Hiram Cuevas:

training wheels are off. Peter finally let me open the show by

Hiram Cuevas:

myself. Well, it's good to be rid of Peter. I think that's

Hiram Cuevas:

what we can say about that. Anything that pushes Peter to

Hiram Cuevas:

the side, I am all for.

Hiram Cuevas:

I'm speechless. I'm actually a big fan of Peter,

Hiram Cuevas:

so you know.

Bill Stites:

Oh, I'm Peter's biggest fan, and he knows it. I

Bill Stites:

just like giving him grief. Hiram and I, you and I, just

Bill Stites:

spent so much time with Peter. I don't even know where to begin.

Bill Stites:

Kevin Warenda, TLIS: Indeed, we did. Well, I'm preparing for a

Bill Stites:

totally new experience myself next week. At the end of the

Bill Stites:

week, my family, including our dog, will be piling into an RV

Bill Stites:

or rented to travel to the Midwest. My older daughter is

Bill Stites:

going to be competing in gymnastics at the Junior

Bill Stites:

Olympics.

Bill Stites:

Oh, awesome! Good for you. We've got campgrounds

Bill Stites:

mapped out. We've got a chartered fishing trip, and then

Bill Stites:

everything else is going to be quite the adventure. So, I'm

Bill Stites:

actually curious, Bill and Hiram, you have any epic road

Bill Stites:

trip memories worth sharing? So many people may know I've seen

Bill Stites:

all 30 baseball stadiums in the United States. We've generally

Bill Stites:

flown into different areas and mapped them around, and I will

Bill Stites:

tell you as far as a road trip goes. One, I'm extremely jealous

Bill Stites:

of what you're doing. I always wanted to get a camper and do

Bill Stites:

that because my retirement goal is to live the van life. I want

Bill Stites:

to get something kind of just be able to travel around like that.

Hiram Cuevas:

Teach a chum van-that's what you want,

Bill Stites:

exactly. But but based on the travels that I had,

Bill Stites:

the one thing I would highly recommend people to do: we flew

Bill Stites:

into Seattle, we drove over to Cannon Beach, Oregon, home of

Bill Stites:

the Goonies, where that was filmed, and then we drove down

Bill Stites:

the Pacific Coast to San Francisco, and that is a road

Bill Stites:

trip that I would take time and time again, some of the most

Bill Stites:

beautiful landscape, beautiful scenery, and one of the best

Bill Stites:

drives that I had. We were amazed because when we were

Bill Stites:

inland on one side, it was like 100 degrees, and as we made our

Bill Stites:

way back to the coast and over the mountains and came back

Bill Stites:

down, we literally saw a 50 degree switch in temperature

Bill Stites:

when we went from one side to the other, so prepare for all

Bill Stites:

and enjoy yourself. But it was a great road trip.

Hiram Cuevas:

I'm very jealous as well. Grace and I we drove

Hiram Cuevas:

across the country many years ago, did Bryce Canyon, Kings

Hiram Cuevas:

Canyon, and Sequoia, and then for our honeymoon we camped for

Hiram Cuevas:

two weeks out in the Pacific Northwest in Montana. So we knew

Hiram Cuevas:

we were going to get along after two weeks camping together. I

Hiram Cuevas:

think what you'll probably love the most is when you pass

Hiram Cuevas:

Kentucky. That's when the humidity starts to drop. It

Hiram Cuevas:

really is fascinating, and the dry air of the Midwest and the

Hiram Cuevas:

further west you go is just fabulous compared to the East

Hiram Cuevas:

Coast.

Hiram Cuevas:

Kevin Warenda, TLIS: All right. Well, speaking of going places,

Hiram Cuevas:

I'm excited to see where the podcast takes us today. Our

Hiram Cuevas:

guest is a veteran K 12 cybersecurity leader with more

Hiram Cuevas:

than 20 years of experience. She's nationally recognized in K

Hiram Cuevas:

12 cybersecurity risk management and governance. Currently

Hiram Cuevas:

serving as the Chief Information Security Officer for WASIPSE,

Hiram Cuevas:

which is a Washington School District cooperative. It's my

Hiram Cuevas:

pleasure to welcome April Mardach to the show. Please tell

Hiram Cuevas:

us more about yourself and your journey that brought us here

Hiram Cuevas:

today.

April Mardock:

Sure. So I've been in K 12 a long time. I

April Mardock:

originally actually started as a var doing support for back in

April Mardock:

the day Solaris, Novell, Netware, a lot of old tools, and

April Mardock:

slowly migrated to supporting Macs, which ended up with a lot

April Mardock:

of K 12 customers. That time, I supported over 100 different

April Mardock:

companies, small, medium, and large. So I got a lot of field

April Mardock:

engineer experience, hands on, you know, setting up the whole

April Mardock:

set stuff and troubleshooting and training users and all of

April Mardock:

the things. And eventually, I ended up taking a position with

April Mardock:

a local ESD, which is like a regional area that supports

April Mardock:

school districts. So, like Washington has nine ESDs, and

April Mardock:

the ESDs are partially state funded in a tiny way, like 5% of

April Mardock:

their budget, and then the rest of their income comes from their

April Mardock:

local school districts as they provide services. And so, I

April Mardock:

provided regional services to K 12 s in my region, and since

April Mardock:

basically '99, and in fact was involved in a bunch of Y2K

April Mardock:

stuff. So I've been doing cyber for a long time. Did firewall

April Mardock:

audits and configurations. I was on the techy side of things,

April Mardock:

right? Doing an awful lot of support for soup to nuts, a

April Mardock:

district that has no techs or one IT person. Who might also be

April Mardock:

the science teacher? So you've got the small districts, the

April Mardock:

medium districts, and the large districts. And eventually, I

April Mardock:

ended up getting hired by the largest district in the state

April Mardock:

here in Washington, Seattle. Worked for Seattle 15 years ish,

April Mardock:

and then now I'm back at the state level, K 12, working for

April Mardock:

WASI as their chief information security officer. And what's

April Mardock:

cool about my job here is I am 50% internal facing, doing

April Mardock:

cybersecurity and CISO work, helping with incident planning

April Mardock:

and response, all of the normal kind of create a cybersecurity

April Mardock:

program from scratch. But I'm also doing 50% external facing,

April Mardock:

which allows me to do some of the national work with K 12 six,

April Mardock:

and to work with districts across my state in helping bring

April Mardock:

everybody to a higher degree of cybersecurity stability and

April Mardock:

include postures. So, for instance, one of the things that

April Mardock:

I think I'm about to get kicked off, I'm actually participating

April Mardock:

as a lead in the state's cyber incident response team, so I'll

April Mardock:

probably be heavily involved in K 12 support in that space, and

April Mardock:

I'm also working with the state on putting together a

April Mardock:

vulnerability management process where we will get an email and a

April Mardock:

flag when a district has essentially-I don't know-you've

April Mardock:

seen how many districts have gotten taken over by way of

April Mardock:

exposing an Exchange server or a SharePoint server or something

April Mardock:

like that that didn't get patched in a timely way, or just

April Mardock:

didn't get removed because it was end of life. Right? Those

April Mardock:

are kind of threats, and the state's going to work with me.

April Mardock:

Maybe it's looking really, really likely on allowing WIC to

April Mardock:

sort of coordinate that notification and helping

April Mardock:

districts figure out what to do to mitigate their

April Mardock:

vulnerabilities for those sort of extraordinary all hands

April Mardock:

remote takeover risk kind of things. So super excited! It's

April Mardock:

been a long journey, and I'm in a place where I can really move

April Mardock:

the needle, both at the state and the national level. With the

April Mardock:

K 12 six side, the technical working group there is a group

April Mardock:

of K 12 geeks, security geeks from across the U.S. as well as

April Mardock:

some folks that are not geeks, that help us with making sure

April Mardock:

the messaging is understandable for any district. And that group

April Mardock:

has come up with some amazing resources that are free to

April Mardock:

anybody who wants to use them. Things like the "What to Do If

April Mardock:

You're Compromised" checklist, where you can basically go

April Mardock:

through and if you get a compromised account, it reminds

April Mardock:

you of all the things to do-not just reset the password or flush

April Mardock:

the sessions, but look and see if somebody connected an

April Mardock:

application. Right? Look and see what rules might have been

April Mardock:

configured. Look to see what else may have been done, because

April Mardock:

as we all know, the attackers are getting more sophisticated.

April Mardock:

So, that's a group that also came up with a 14 question

April Mardock:

cybersecurity assessment that's really easy for small districts,

April Mardock:

independent schools to do. That gives you like your top marching

April Mardock:

orders for the top one or two things you should really focus

April Mardock:

on for the year. Doesn't take a rocket scientist. Really

April Mardock:

approachable. So that's been kind of one of my big goals: is

April Mardock:

to try to make cybersecurity approachable for everybody, all

April Mardock:

the districts, tiny or huge. Oh,

April Mardock:

Kevin Warenda, TLIS: that's such important work. I saw recently

April Mardock:

you posted an article on your LinkedIn feed. I think it was

April Mardock:

you've interviewed 24 school districts who've been victims of

April Mardock:

ransomware, and you kind of boiled that down into a really

April Mardock:

approachable lens to think about this through like the three

April Mardock:

doors that attackers come through. Maybe you could talk a

April Mardock:

little bit about your findings there and how easy it is

April Mardock:

actually to maybe think about securing those doors.

April Mardock:

Yeah, when I was with my very large district, I

April Mardock:

did not want to be next in the ransomware parade, and to do

April Mardock:

that, I started asking folks at conferences and other places.

April Mardock:

You know, after they presented about their event, you know how

April Mardock:

did bad guys get in? You know, in the very beginning, the camel

April Mardock:

got their nose under the tent. Where'd they poke their nose,

April Mardock:

right? And it turned out that it was really only three answers,

April Mardock:

and three answers that aren't rocket science. The first one

April Mardock:

tends to be when, like I mentioned earlier, there's a

April Mardock:

device or a system that's exposed to the internet and is

April Mardock:

not patched in a timely way, whether that's a server like an

April Mardock:

Exchange or SharePoint server, or it's a VPN appliance, it's a

April Mardock:

firewall management port. Please tell me you've removed all the

April Mardock:

management ports from internet. They should not be facing the

April Mardock:

internet, but that's a different discussion. But anything that's

April Mardock:

basically exposed to the internet that wasn't patched in

April Mardock:

a timely way, or is end of life and doesn't have patches

April Mardock:

anymore, right? So that's number one. It's keep those things

April Mardock:

patched really quickly. And it used to be we said 30 days. Now

April Mardock:

it's 14 days. I'd say if you can patch it within 48 hours, you're

April Mardock:

in a better place. If there's a big announcement that says

April Mardock:

people can take over your whole system through that device is

April Mardock:

probably a good idea to patch it, especially those CISA known

April Mardock:

exposed vulnerabilities are also known as CEVs. So that's door

April Mardock:

number one. Door number two is where basically remote access is

April Mardock:

possible, and it's either VPN or. Some kind of remote desktop

April Mardock:

service, but there's no MFA required, meaning you don't have

April Mardock:

to put in an authentication token. You don't get an SMS.

April Mardock:

There's nothing other than a username and a password that

April Mardock:

gives you full remote access to that district or that

April Mardock:

organization, and that includes vendors. We're really bad about

April Mardock:

letting vendors use the same account for all their texts, and

April Mardock:

we don't make them use MFA because well, there's phone

April Mardock:

issues, right? And we're terrible about enforcing our own

April Mardock:

rules when we get pushback. And what that means is that vendors

April Mardock:

have some bad habits too. They like to, for instance, reuse

April Mardock:

password across clients. And so, if a password gets compromised,

April Mardock:

whether it's a staff person's password or a vendor's password,

April Mardock:

and that username and password can be used to log into that

April Mardock:

district and have full remote access, that's a pretty big

April Mardock:

hole, right? And so that's number two. The other one that

April Mardock:

happens is phishing, which we all see phishing every day. We

April Mardock:

run into that, but phishing grows legs and takes over your

April Mardock:

organization if the user who gets the fish and responds to

April Mardock:

the fish also has local administrator rights, because

April Mardock:

what happens then is the fish lands, and the user's machine is

April Mardock:

then taken over and used to crawl across and take over the

April Mardock:

rest of the network, and sometimes the hygiene of that

April Mardock:

organization is bad enough, where they've also used the same

April Mardock:

administrator configuration password on all the devices. All

April Mardock:

the staff devices get a password. All the student

April Mardock:

machines might get a different password. But the problem is

April Mardock:

when that password then gets compromised, it can be used to

April Mardock:

take over every machine very quickly.

Bill Stites:

You mentioned working with Solaris and with

Bill Stites:

Novell, and I think at least Hiram and I-I'll leave Kevin out

Bill Stites:

of this-but Hiram and I are the old gray beards in the room.

Bill Stites:

We've been at this for a while. When you said that Hiram and I

Bill Stites:

are both heard Novell, it was like ding ding, remembering from

Bill Stites:

years past. And I just remember walking into our network room,

Bill Stites:

our network closets and just the number of tools that we had that

Bill Stites:

were on prem to deal with all of this patching that you're

Bill Stites:

talking about, you know, and everything that was going on

Bill Stites:

with that, the number of servers you were maintaining, so on and

Bill Stites:

so forth. I want to get your thoughts on how that model, how

Bill Stites:

that mode has changed with so much moving to the cloud now,

Bill Stites:

and so much of what's out there going into the cloud, and what

Bill Stites:

your thoughts are there, and what that means for, I'll say

Bill Stites:

the due diligence that we need to do on our parts to make sure

Bill Stites:

that our cloud services are configured properly, or our

Bill Stites:

cloud providers are doing their due diligence, and I want to

Bill Stites:

thank both K 12 six and CISA because I saw this on a K 12 six

Bill Stites:

email just like I think yesterday or the day before that

Bill Stites:

there's a new set of tools that were put out called Scuba. That

Bill Stites:

is for those that don't know the acronyms because it's like

Bill Stites:

acronym soup when we talk about this stuff. That is a secure

Bill Stites:

cloud-based application. It's a set of tools and recommendations

Bill Stites:

that they put out to help you evaluate these cloud services.

Bill Stites:

So, with that said, what are your thoughts in everything that

Bill Stites:

I mentioned there?

April Mardock:

Okay, so I'll start with, although you've

April Mardock:

probably pushed 75 or even 80% of your stuff to the cloud,

April Mardock:

don't forget you still have on-prem entry points like the

April Mardock:

firewall and like the firewall management ports. Make sure you

April Mardock:

stay on top of keeping those patched. We don't think of them

April Mardock:

as servers, right? We don't think of them as something that

April Mardock:

needs to be patched, but they do. So that's stage one. Stage

April Mardock:

two, vendors make mistakes too, and sometimes the vendor

April Mardock:

defaults are terrible. And a case in point on this would be

April Mardock:

if you guys saw what happened with Clark County Schools, one

April Mardock:

of the attacks that they dealt with was somebody taking over

April Mardock:

the student passwords. And at the time, the student passwords

April Mardock:

were based on birth dates. And I will say a lot of school

April Mardock:

districts use birth dates or something like it to configure

April Mardock:

those initial passwords, and they don't always force password

April Mardock:

changes when they do it. Here's the problem that makes a student

April Mardock:

account easy to log into, easy to guess because you get the

April Mardock:

user account, you get the password, which is their

April Mardock:

birthdate, and you log in. Now here's where it gets ugly.

April Mardock:

Everybody should be doing this who's a school district IT

April Mardock:

manager, which is you need to log in as a student account and

April Mardock:

look around and search for things like SPED or IEP or

April Mardock:

discipline or all of the sensitive words right from a

April Mardock:

student account and see what's been overshared, because what

April Mardock:

happens with Clark County, as I understand it, is there were

April Mardock:

Google work groups that a student could add themselves, or

April Mardock:

a criminal using a student's account could add themselves to,

April Mardock:

but either way, it's a problem. If a student can do this, it's

April Mardock:

also problematic, and get access to all the content in that work

April Mardock:

group. What that means is, if you can break in with a student

April Mardock:

account and can search for all of that sensitive. Content you

April Mardock:

can steal that sensitive content, and the default

April Mardock:

configuration was problematic. I'll use a Microsoft example.

April Mardock:

Microsoft made it so that when you shared a file in the earlier

April Mardock:

days, it would share with everyone, whether they were

April Mardock:

on-prem or in the cloud. And so you created this link. If that

April Mardock:

link got out, it was visible. But here's where it gets ugly.

April Mardock:

The AI search engines can now expose files that were shared

April Mardock:

with everyone, internet access that you didn't intend to ever

April Mardock:

share. Now, just because the person has privilege, because

April Mardock:

you said allow it to either everyone or allow it to everyone

April Mardock:

in the organization. Okay, think of this from a teacher point of

April Mardock:

view. I want to share a file with the kids in my class, and

April Mardock:

I'm going to share this file. And I'm not going to name all 30

April Mardock:

kids that I want to send this file to. I'm going to share it

April Mardock:

with everyone in the org. Right? That makes sense for a teacher.

April Mardock:

Same thing happens for say somebody in IT. They want to

April Mardock:

share something out to all the staff. They'll share it with

April Mardock:

everyone in the org. Well, here's something that often

April Mardock:

happens in K-12: the students and the staff are in the same

April Mardock:

organization. When you share a file with everyone in the org,

April Mardock:

it gets shared to everyone, staff and students. Sometimes

April Mardock:

those files are sensitive. You don't intend it to get in the

April Mardock:

wrong hands, but if you've shared it with wide open

April Mardock:

privileges, now anyone with an account, and that means

April Mardock:

criminals with accounts, can get to that file. So those are

April Mardock:

mistakes kind of made in the early configuration where the

April Mardock:

default sharing was too open, or the default for that group

April Mardock:

membership is too open. It allows people to inject

April Mardock:

themselves. All of those kinds of defaults in your tenant, your

April Mardock:

Microsoft or your Google tenant can bite you because a it's

April Mardock:

easier to steal accounts because the passwords are sometimes

April Mardock:

either already know or easy to guess, and b those accounts if

April Mardock:

you start searching for sensitive content will reveal

April Mardock:

things you'd really rather they not reveal. So that's part one.

April Mardock:

Part two is our vendors and the vendor stuff? Couple things

April Mardock:

there. So make sure that when you're contracting with vendors,

April Mardock:

if you give PII to vendors, this is one of the things I worked on

April Mardock:

with K 12 six in the technical working group.

April Mardock:

We actually created a document that you guys should have access

April Mardock:

to. That is what I call lightweight vendor management,

April Mardock:

and there's low risk vendors, medium risk vendors, and high

April Mardock:

risk vendors, and we consider the high risk vendors vendors

April Mardock:

that either have really sensitive student data, or are

April Mardock:

operationally critical. If this thing goes down, we have trouble

April Mardock:

teaching, or we have trouble keeping the buildings open, or

April Mardock:

we have trouble bussing kids-it's something that will

April Mardock:

really create a showstopper kind of situation. So those are the

April Mardock:

high-risk vendors, and for the operationally high-risk vendors,

April Mardock:

I ask questions like, "What kind of redundancy do you have if

April Mardock:

there's a Microsoft outage in this region? Can you fail over

April Mardock:

somewhere else? Or Amazon outage in this region? Can you fail

April Mardock:

over somewhere else? Here's the sneaky part: Amazon and

April Mardock:

Microsoft will charge you for that extra resiliency. So some

April Mardock:

companies don't pay it. If they're an operationally

April Mardock:

critical vendor, you want to start asking those questions.

Hiram Cuevas:

We actually felt some of that when the incident

Hiram Cuevas:

in the Strait of Hormuz occurred. About 22% of all data

Hiram Cuevas:

traffic apparently goes through that area, and a lot of folks

Hiram Cuevas:

were complaining at my school and a bunch of other schools.

Hiram Cuevas:

You know what's going on with our SaaS applications, and I've

Hiram Cuevas:

reminded them, hey, there's a lot going on, a lot of rerouting

Hiram Cuevas:

of traffic, and sometimes that kind of stuff is out of our

Hiram Cuevas:

hands, and we can't even control that because it's such a main

Hiram Cuevas:

trunk of data.

April Mardock:

Yeah, for sure. And outages, if it's

April Mardock:

operationally critical to your org, you want to make sure that

April Mardock:

that software that you are subscribing to has some

April Mardock:

resilience built in, so that you have less outages as a result. I

April Mardock:

have seen cases where, for instance, the West Side Amazon

April Mardock:

West drops, or maybe some of their DNS functionality drops,

April Mardock:

and all kinds of things break. Right. So, what you want is to

April Mardock:

make sure that the vendor that you're putting your money in for

April Mardock:

operationally critical stuff has resiliencies built in. Whether

April Mardock:

it's incident response stuff, they have disaster recovery and

April Mardock:

can come back. They have resiliency in their services.

April Mardock:

You just want to make sure that's covered. And then on the

April Mardock:

flip side of that, where it's sensitive data, those are

April Mardock:

different questions, right? Number one, I want to make sure

April Mardock:

that they can delete my data when I'm done, and that they

April Mardock:

don't force me to send them a certified letter to say you must

April Mardock:

delete my data because vendors see data as a long-term money

April Mardock:

source, and they really don't like deleting it. They don't

April Mardock:

like getting rid of it. They don't like purging it. They like

April Mardock:

to feed it to their AI models and learn from it. And I really

April Mardock:

want my data back when I'm done. The other thing that I'm

April Mardock:

thinking about with vendors is: Do you really have to give them

April Mardock:

all the data they're asking for? As an example. I stopped giving

April Mardock:

vendors birth date data. Why? Most of the time, they can get

April Mardock:

by with the graduation year. They don't need a birth date.

April Mardock:

They just need basically a rough idea of what range the kid is

April Mardock:

in. It's not always the case, right? I can't do that with

April Mardock:

every vendor. There are a few cases where that's an exception.

April Mardock:

But in general, why are we giving, for instance, vendors

April Mardock:

parent home address information just because they ask for it? If

April Mardock:

they don't have a legitimate reason to mail the parents, I

April Mardock:

don't think they should have home address information. Maybe

April Mardock:

email if the parents legitimately interacting with

April Mardock:

them or registering with them or whatever for a portal, but do

April Mardock:

they really need a home address? And I start asking that question

of vendors:

Is why are you asking for this content? Maybe

of vendors:

we used to give this to you, but maybe we shouldn't anymore.

of vendors:

There isn't a reason to give vendors content that they really

of vendors:

don't need for the purpose that we're hiring them for.

of vendors:

Kevin Warenda, TLIS: Yeah, and it strikes me as you're asking

of vendors:

your vendors about how resilient they are. I know we go the extra

of vendors:

step too to ask for a software bill of materials. Like that

of vendors:

understanding of their service is probably not just one thing;

of vendors:

it's probably also reliant on their own third-party vendors.

of vendors:

And so, if they're hosting their application in AWS West, it's

of vendors:

good to understand. All right, then if you're tied to that

of vendors:

region, that if that goes down, this service may also go down. I

of vendors:

actually spend a lot of time having to educate my community

of vendors:

when things stop working, as to why that's down. It's like,

of vendors:

well, why is Canvas down? It's like, well, because Canvas is

of vendors:

hosted on a third-party cloud that was down today on DNS

of vendors:

issues. Like, so yeah, Canvas's issue is actually the

of vendors:

infrastructure they're reliant on. So I think that's an

of vendors:

important call out that you made there. It's like ask your

of vendors:

vendors to describe their solution, what it's built on,

of vendors:

and how it's configured. Not just from a resiliency and a

of vendors:

data security or data residency perspective, but also just in

of vendors:

terms of what makes up your service. What are you also

of vendors:

contracting with, and what are your agreements with those

of vendors:

vendors too? Because this is where we get into data residency

of vendors:

or controllers and processors too, right? Depending on who

of vendors:

that goes to, like if you're signing a contract with vendor

of vendors:

A, well, if there's a sub processor involved there, like

of vendors:

that data may actually go into that other third party, and that

of vendors:

agreement survives that. So I think that's great that you're

of vendors:

asking about that, and I would say expand that even to all

of vendors:

aspects of that service offering to them. The

Bill Stites:

one thing I will add to what you just said is

Bill Stites:

that Hiram and I have been spending a lot of time working

Bill Stites:

with one of the groups that partner with ATLIS a lot is

Bill Stites:

nine, and what you're talking about is that vendor vetting,

Bill Stites:

those sub processors. It's amazing when you get into that,

Bill Stites:

you start looking at that not only from the resilience

Bill Stites:

standpoint, but where's all that data going? And April, you said

Bill Stites:

something that really resonated with me. When you start working

Bill Stites:

with a lot of these vendors, you know how much information are

Bill Stites:

you giving them? I think one of the things that often happens,

Bill Stites:

and I can remember distinctly saying no to one of our vendors,

Bill Stites:

was when they were asking for API level access to our

Bill Stites:

information systems because they were connecting things that was

Bill Stites:

providing direct service. It was like if we wanted to use this,

Bill Stites:

this how it went in, and they were like, "Well, just give us

Bill Stites:

API, you know, read write to all these scopes. And I'm like, "No,

Bill Stites:

I'll give you read access, and I'll give you read access to

Bill Stites:

these because you need to tell me why. And a lot of times, what

Bill Stites:

I found is not for nothing. It's laziness on the part of the

Bill Stites:

vendor to really work to only ask for what they need. They're

Bill Stites:

like, you know what? Just give me as much as you can, and I'll

Bill Stites:

figure out what I'm going to do with it later. With no thought,

Bill Stites:

or maybe there is thought, and I'm just being naive to what

Bill Stites:

they're actually requesting and what that actually opens up from

Bill Stites:

that risk standpoint.

April Mardock:

Well, there's another layer to that too: is

April Mardock:

how long are they allowed to keep the data? And I know for

April Mardock:

districts, we have a tendency to keep stuff as long as we

April Mardock:

possibly can because at some point that turned out to be a

April Mardock:

valuable thing. I'm going to argue the calculus has changed,

April Mardock:

and keeping data, especially sensitive data like discipline

April Mardock:

data longer than you need to is a liability, and so when you're

April Mardock:

working with a vendor and you're giving them sensitive content,

April Mardock:

you really ought to have a retention and archive and

April Mardock:

removal process in place so that all the data doesn't stay there

April Mardock:

forever. Case in point, a lot of us use payroll systems, right?

April Mardock:

Payroll systems have like bank account information. How many

April Mardock:

years of bank account information is in that system?

April Mardock:

If it gets compromised, they might be going back 2030, years.

April Mardock:

That becomes a problem if you don't have the ability to purge

April Mardock:

the content safely and get rid of the content you aren't

April Mardock:

legally required to keep, and you don't have a process for

April Mardock:

managing that, whether it's in house or with a vendor. That

April Mardock:

creates a big liability because when you are compromised, you're

April Mardock:

going to have to go back and notify decades of employees and

April Mardock:

or students if you haven't archived that content and pulled

April Mardock:

it, especially out of the live systems. They do tend to

April Mardock:

compromise the live systems first. They may eventually get

April Mardock:

around to archives if you have to keep it for some legal

April Mardock:

reason. It doesn't necessarily have to be in the live load,

April Mardock:

right? You could put it in another database that you zip up

April Mardock:

and tuck away for when you need it for something else, and maybe

April Mardock:

that's password protected or some other way less accessible

April Mardock:

to the attackers. But if it's all in your live system and it

April Mardock:

goes back decades, you're going to be notifying decades of

April Mardock:

people, and that's expensive. And it's not fair that it's not

April Mardock:

their fault that you decided to keep data longer than you needed

April Mardock:

to.

Hiram Cuevas:

What's interesting about that is I don't know many

Hiram Cuevas:

folks that actually ask vendors to delete their data. Schools,

Hiram Cuevas:

in particular. I mean, when you have the transition of employees

Hiram Cuevas:

coming in and out and in and out and in and out, how many of us

Hiram Cuevas:

actually have done that due diligence of saying, "Hey, I

Hiram Cuevas:

need to contact all my vendors within my tech stack to

Hiram Cuevas:

eliminate these people or this group of students or whatever.

Hiram Cuevas:

It's a massive undertaking, but it certainly is one that we need

Hiram Cuevas:

to keep a top of mind,

April Mardock:

and I would think of like a phase one, phase two

April Mardock:

approach. Maybe you don't do it on a micro level for everyone

April Mardock:

who leaves. There's often, at least in the state of

April Mardock:

Washington, there's stuff we have to keep seven years after

April Mardock:

they leave, or

Hiram Cuevas:

correct,

April Mardock:

however long it is. But you set up something

April Mardock:

where all the records that are discipline records that get to a

April Mardock:

certain age that have aged out can get pulled together, right?

April Mardock:

You don't manage it as an individual, but you start

April Mardock:

tagging and classifying data, and asking the vendors to do the

April Mardock:

same so that they can appropriately dispose of data

April Mardock:

without you micromanaging and saying, "Well, this person left

April Mardock:

seven years ago. Let's go purge their stuff. I can't imagine a

April Mardock:

small district taking that on, it's a big lift, but there are

April Mardock:

ways we can still push the vendors to delete content in a

April Mardock:

timely way. And the other thing is, when you change vendors and

April Mardock:

you move data from System A to System B, don't move all of it

April Mardock:

if you can avoid it. Use those opportunities when you're

April Mardock:

changing vendors or doing upgrades to purge content you

April Mardock:

don't legally have to keep. Whether that's the vendor doing

April Mardock:

the work or you doing the work, I think it's something we need

April Mardock:

to be more intentional about.

Hiram Cuevas:

So, April, we've been looking at this at a very,

Hiram Cuevas:

very high level, at 50,000 foot level, and I'd be curious if you

Hiram Cuevas:

wouldn't mind opining on a situation that I think many

Hiram Cuevas:

schools are dealing with this summer. I had a faculty member

Hiram Cuevas:

come back to me after attending a conference, all sorts of great

Hiram Cuevas:

ideas come out of conferences, and one of them had to do with

Hiram Cuevas:

his interest in using App Scripts to develop an extension

Hiram Cuevas:

for him to use with his students. And when I took a step

Hiram Cuevas:

back, I was like, "Okay, App Scripts is open by default, and

Hiram Cuevas:

I didn't realize it was open by default on the Google domain. So

Hiram Cuevas:

that the first thing we did was we shut that down,

April Mardock:

turn that off.

Hiram Cuevas:

Yeah, and I'm curious what your opinion is in

Hiram Cuevas:

general about the whole access to app scripts by anybody to

Hiram Cuevas:

your Google domain, for better or for worse. I mean, this

Hiram Cuevas:

teacher wants to do the right thing. He wants to try and reach

Hiram Cuevas:

kids a certain way, and I think it's a great idea. I'm trying to

Hiram Cuevas:

develop a sandbox, but we don't have the resources in order to

Hiram Cuevas:

try and figure all that out when it just appears in the middle of

Hiram Cuevas:

the summer. Be curious what your thoughts are.

April Mardock:

So generally, it's one of those where I turn

April Mardock:

off the ability for folks to enable it by default, and they

April Mardock:

have to go through a vetting process, and most of the

April Mardock:

districts I'm dealing with now have to legally review software

April Mardock:

for accessibility anyway, and that includes stuff that you

April Mardock:

would expose in a classroom, like your extension that you're

April Mardock:

talking about, because the district I worked for was the

April Mardock:

first district in the U.S. to get sued for not having a math

April Mardock:

tutoring program that was intended for the student use was

April Mardock:

not accessible by a blind parent at home, and it turned out some

April Mardock:

of the district web pages also weren't accessible to blind

April Mardock:

parents, and what it meant was that the district had to do a

April Mardock:

formal intake process to avoid further lawsuits to make sure

April Mardock:

that software met a certain minimum standard, and all

April Mardock:

software had to go through that process. And the rule was

April Mardock:

anything that the district purchased or anything that the

April Mardock:

district deployed or allowed to be deployed, right? Like this

April Mardock:

application that you're talking about, had to go through a

April Mardock:

formal review process, and that has a checklist of things to

April Mardock:

look at, whether it's accessibility, whether it's the

April Mardock:

cybersecurity configuration, whether it's the privacy

April Mardock:

concerns that might come with it, like any other extension

April Mardock:

that you would deploy, you run it through the same process. If

April Mardock:

that teacher wants to submit their custom written application

April Mardock:

and go through the same vetting process, I would expect the

April Mardock:

process to allow fair treatment of that in the same way they

April Mardock:

would if they wanted to bring in a third-party tool. The problem

April Mardock:

I run into is a little more esoteric. Is yes, I want to turn

April Mardock:

it off and vet everything that I turn back on, and I want to have

April Mardock:

an intake process to cover legal. But you're going to run

April Mardock:

into CTE classes and other places where they want to do

April Mardock:

that kind of programming and learn. Those skills and become

April Mardock:

capable of doing this kind of work, and so what you'll end up

April Mardock:

doing is creating special sandboxes for that, where you're

April Mardock:

going to have to find a way around just saying no. And so I

April Mardock:

understand it's a complicated ask.

April Mardock:

Kevin Warenda, TLIS: I think it's ironic. I spent almost a

April Mardock:

decade in public school supporting technology as well,

April Mardock:

so there's definitely that angle of if there's a regulation or a

April Mardock:

law or legal reason to do something, you can leverage that

April Mardock:

as the excuse of why you're doing it to try to maybe deflect

April Mardock:

the responsibility of that choice from the IT director. And

April Mardock:

I find myself doing that now, even with our cyber liability

April Mardock:

provider, right? So as independent schools, maybe we

April Mardock:

don't have so much of that regulation or public school

April Mardock:

requirements based on statutes and such, but I'm not above

April Mardock:

using the cyber liability policy requirements to say no. Like the

April Mardock:

reason we have MFA for everyone is not because I want to make

April Mardock:

your lives harder; it's because it's required by our insurance

April Mardock:

provider, or we have a vetting process for software and

April Mardock:

applications because it's required by our cyber liability

April Mardock:

provider, so it's ironic we have to use that as the tool to try

April Mardock:

to deflect from why we're doing that. But it's for the right

April Mardock:

reasons, and I think it's tough sometimes to try to educate

April Mardock:

users as to why that's so important. I want to come back

April Mardock:

to something you said earlier about the oversharing of

April Mardock:

information. I think this is especially relevant now. I've

April Mardock:

heard lots of talk. You were also talking about classifying

April Mardock:

or categorizing data sets. This all speaks to this question now.

April Mardock:

With these AI tools, especially generative AI tools that now can

April Mardock:

work at machine speed, they are uncovering all this stuff that

April Mardock:

is shared. And what I'm hearing is the recommendation is you

April Mardock:

really have to get your data house in order before adopting

April Mardock:

these types of tools for any kind of use, because otherwise

April Mardock:

it's just going to find all those corners where you're

April Mardock:

hiding stuff. And if it's not labeled, if it's not

April Mardock:

categorized, I know Microsoft has a tool for this called

April Mardock:

Purview. Right, you can actually classify and categorize what's

April Mardock:

public, what's internal, what's confidential, and these tools

April Mardock:

then can actually utilize those tags and classifications to

April Mardock:

properly put things or expose where there might be issues.

April Mardock:

They can

April Mardock:

Kevin Warenda, TLIS: maybe you could talk a little bit of any

April Mardock:

experience you have in that area or why this is so important in

April Mardock:

the age of AI.

April Mardock:

Two things I do recommend turning off those AI

April Mardock:

search tools until you've done at least some searches and clean

April Mardock:

up on your own. But the second layer to that, one of the

April Mardock:

districts I work with did tag documents using the Microsoft

April Mardock:

tools that were sensitive, and then use the DLP controls to

April Mardock:

block the sharing and the emailing of those sensitive

April Mardock:

documents out, and so that can prevent theft and overexposure

April Mardock:

of content that probably shouldn't be shared. I will say

April Mardock:

sometimes staff have I would call it semi legitimate reasons.

April Mardock:

They might be in working on their doctorate in education and

April Mardock:

they want data. They should be asking for that data formally

April Mardock:

instead of just taking it. It's interesting to see who flags

April Mardock:

that data loss prevention tool, but tagging that content is

April Mardock:

getting easier and easier. You can give it examples of the kind

April Mardock:

of content, especially if it's a form type content like a

April Mardock:

transcript, a discipline form, all of those kinds of things.

April Mardock:

You can teach the system, and it will actually automatically go

April Mardock:

out and flag them, find them, and tag them for you, and then

April Mardock:

you can treat them as appropriate. So yes, those tools

April Mardock:

are getting better. I will say, two years ago, it was a real

April Mardock:

pain to try to do this, and it's getting cleaner and cleaner as

April Mardock:

you move along. I don't have enough experience in the Google

April Mardock:

environment to know how easy that is to do in that space. I

April Mardock:

suspect the tools are coming if they aren't already there to be

April Mardock:

able to automatically flag content and prevent it from

April Mardock:

being overshared, prevent it from being misused in that way.

Bill Stites:

I'll go back to that piece with the Scuba Tools.

Bill Stites:

I just literally got off a call yesterday because we went

Bill Stites:

through a full audit of our Google domain

April Mardock:

with Scuba.

Bill Stites:

Well, Scuba Tools is what I'm going to use

Bill Stites:

actually to validate what we did in our audit, we used another

Bill Stites:

vendor that we've used, and this is now our third audit with them

Bill Stites:

to go through all of that. And it really highlighted a bunch of

Bill Stites:

the things that you mentioned with regard to the oversharing,

Bill Stites:

the DLP controls. You know what you need to turn on and off, how

Bill Stites:

you need to go through that type of audit, and I found that

Bill Stites:

that's incredibly helpful for me and for my team because, as you

Bill Stites:

mentioned, you're not as familiar with the Google

Bill Stites:

environment, so you couldn't comment. Well, we don't live and

Bill Stites:

breathe in these areas every day, and your role as a CISO is

Bill Stites:

one that we hear coming up in schools whenever they talk about

Bill Stites:

this vetting, they say, "Well, talk to your risk committee,

Bill Stites:

talk to your CISO and your risk person. And I'm like, "That's

Bill Stites:

just another hat that we put on over the course of our day, and

Bill Stites:

we're trying to make the best guess in terms of." How we can

Bill Stites:

go about doing that, and one of the things I'll credit Hiram for

Bill Stites:

getting me started on is using AI to actually help with some of

Bill Stites:

that work, whether that be in the evaluation or vetting of

Bill Stites:

services, whether that be in some of the search work that

Bill Stites:

you're talking about there. What would you recommend to people

Bill Stites:

listening to have as their common tool belt of either

Bill Stites:

partners or tools or things to consider as they put on that

Bill Stites:

CISO hat that they are interchanging with their

Bill Stites:

database administrator hat, their mobile device management

Bill Stites:

hat? You know all those things. What can we put in our tool belt

Bill Stites:

to help us with this work that we're doing to level it up a

Bill Stites:

little bit for us?

April Mardock:

So I'd go at a couple different angles. One

April Mardock:

would be working with their local regional support agency if

April Mardock:

they have one, like an ESD educational service district or

April Mardock:

equivalent. If they have a state department of education that has

April Mardock:

a cybersecurity focus. Sometimes some states have cybersecurity

April Mardock:

resources at the state level. For the independents and the

April Mardock:

smaller districts that don't have that support structure, you

April Mardock:

can look to something like K 12 six that's providing guidance

April Mardock:

around vendor management. I'm the chair of the technical

April Mardock:

working group, and one of our next tasks after the Essentials

April Mardock:

reboot will be that scuba report is amazing, but it's like 20

April Mardock:

pages long and there's hundreds of entries in it that are red,

April Mardock:

green, and yellow. And I find that a lot of the smaller

April Mardock:

district folks are just overwhelmed by that report and

April Mardock:

they don't know where to go next. And so K 12 six is going

April Mardock:

to work on sort of a top 10 Microsoft tenant and top 10

April Mardock:

Google tenant things to look for that are kind of urgent that we

April Mardock:

need to make sure all districts are taken care of. So there's

April Mardock:

sort of a crawl, walk, run approach to that, where you can

April Mardock:

basically start with the simple stuff and work your way up.

April Mardock:

Obviously, there are also vendors available that can help

April Mardock:

even the smaller organizations that can do the number crunching

April Mardock:

and give you something actionable. I don't have

April Mardock:

specific vendor recommendations available, but I can say that

April Mardock:

there are a number of them out there that are targeted to

April Mardock:

helping small K 12 s do what they need to do. They realize

April Mardock:

that K 12 s not just don't have a CSO. It might be the science

April Mardock:

teacher who's doubling as the IT admin. It's a pretty constrained

April Mardock:

environment, and they don't have the time or the resources to do

April Mardock:

all the things a big district can do, even though they're

April Mardock:

asked to. And so, how do they offload that? There are some

April Mardock:

virtual CISO stuff out there as well. I will say, Security

April Mardock:

Studio has a virtual CISO class for folks who want to bump up

April Mardock:

their skill sets, and there's also folks who specialize in

April Mardock:

like nonprofit support CISOs. So they're not looking to make a

April Mardock:

dime on you; they're looking to help because they're in it for

April Mardock:

the social benefit and the social good reasons, rather than

April Mardock:

just you're another customer that can pad the dollars. That's

April Mardock:

something I like to see as folks that are in it to try to make a

April Mardock:

difference and provide resources at cost or just over cost that

April Mardock:

help with both the assessment and the training and the support

April Mardock:

to help folks get where they need to go.

April Mardock:

Kevin Warenda, TLIS: Jeff, what I find so impressive is that the

April Mardock:

scope of what you are responsible for supporting now.

April Mardock:

It is very large, 750,000 people. All these districts, but

April Mardock:

you really do maintain a focus on what makes that up is a lot

April Mardock:

of small schools in some cases too, and that those don't always

April Mardock:

have the resources. So I really appreciate that approach and

April Mardock:

that focus that you have. I think you've even developed some

April Mardock:

of your own tools to contribute too, right? Like I think you

April Mardock:

have a AI chat bot that helps with tabletop exercises. Can you

April Mardock:

talk maybe a little bit about what you're building yourself as

April Mardock:

you're seeing the needs and the need for things that are free?

April Mardock:

So I'm a gamer, and I came from a DND Dungeons

April Mardock:

and Dragons kind of background, and I also am an emergency

April Mardock:

operations center volunteer. I'm actually OxCom certified in ham.

April Mardock:

I'm a ham extra, so I spent a fair amount of time in emergency

April Mardock:

response work and getting like FEMA certified for all the ICS

April Mardock:

stuff. And so what it means is I have a really strong background

April Mardock:

in both gaming and in emergency response, and I combined that

April Mardock:

with cybersecurity, and I created essentially a

April Mardock:

facilitated game. It's more of an interactive cyber attack

April Mardock:

story that you can interact with as a school district, or really

April Mardock:

as anyone. It's a Gemini gem that will actually ask you some

April Mardock:

questions. So it'll start out by saying, "What kind of org are

April Mardock:

you? How big are you? Do you have an incident response plan?

April Mardock:

Was it tested? When was the last time you tried restoring your

April Mardock:

backups? All of those kinds of questions, right? There's like

April Mardock:

six questions that ask for setup, and then it drops you

April Mardock:

into a scenario where you've been attacked, and as you

April Mardock:

respond, it will then respond in kind and provide. Options. It

April Mardock:

rolls dice on success or failure. It'll give you bonuses

April Mardock:

if you have a good approach, and it will give you a summary of

April Mardock:

your performance at the end. And so, it's something that I can do

April Mardock:

in person, and I've done it in person. I did it at the K 12 six

April Mardock:

conference for somebody from I think I had about 30 states

April Mardock:

represented at that session, and I did an interactive session

April Mardock:

with the whole room pretending to be supporting one district,

April Mardock:

and they would make decisions. and It goes through six injects,

April Mardock:

and then at the end, it will give you a summary report. And

April Mardock:

what's neat about that is it's adaptive; it never plays the

April Mardock:

same way twice. It is intended to be a bit more strategic, so

April Mardock:

it's going to ask questions about your communications and

April Mardock:

how you would make a legal decision, and how transparent

April Mardock:

you want to be as a district about the attack, and maybe some

April Mardock:

of the extortion methods that the attackers may be using. Like

April Mardock:

sometimes they'll call parents, right, and tell the parents

April Mardock:

about what they've stolen. And it's fairly realistic. I will

warn you:

you'll have a little bit of PTSD if you've been

warn you:

through an attack, but I think it's a great learning

warn you:

opportunity and it's free. It's on my LinkedIn. I'll reshare it,

warn you:

and I think you have it in the links that you can provide for

warn you:

the podcast. It's useful for any size organization, but I built

warn you:

it for the little ones that really don't have anyone to do

warn you:

this for them, and they can't afford a consultant to come in

warn you:

and do it for them. You can also, if you want to stack the

warn you:

deck a little, because IT directors, as a whole, myself

warn you:

included, like to know what we're getting into before we

warn you:

walk into an executive session. You can run through the scenario

warn you:

once, figure out what all the injects are, get it to where you

warn you:

like it, and then tell it to replay the same game. And so the

warn you:

variability is less at that point, and you kind of know what

warn you:

you're going to get into. So if you want to run that session

warn you:

with your executive cabinet, you can. You can also ask it to be

warn you:

more technical. You can adapt it on the fly and use it with your

warn you:

IT teams. The other tool that I set up with permissions from our

warn you:

friends at Black Hills Security is they have a backdoors and

warn you:

breaches game that is great for IT teams to practice their

warn you:

here's what I'm being presented with and here are the tools I

warn you:

can do cybersecurity response with.

warn you:

I turned it into a game where I set up a storyline where I walk

warn you:

through what the attackers are doing over a period of time, and

warn you:

then I line that up with the backdoors and breaches game,

warn you:

where you have basically how does the attacker get in, how

warn you:

does the attacker pivot and move to other machines, how do they

warn you:

establish persistence, and how do they do exfiltration, how do

warn you:

they steal stuff? There's an online version that is free that

warn you:

you can play with your teams, and it's a great way to get the

warn you:

IT teams practicing without having to deal with a real

warn you:

event. So I kind of have both approaches. The Gemini Gem is a

warn you:

little bit more strategic in its approach, and then if you do the

warn you:

back doors and breaches thing, it's more tactical.

Hiram Cuevas:

So April, in this entire conversation, you're kind

Hiram Cuevas:

of preaching to the choir in terms of what we need to do,

Hiram Cuevas:

let's say your audience is for CFOs and heads of school in

Hiram Cuevas:

independent schools. Explain to them the challenges of the

Hiram Cuevas:

staffing model that you currently see in independent

Hiram Cuevas:

schools when it comes to cyber.

April Mardock:

So most schools are what under 2500 kids. It's

April Mardock:

like 75% or more. Those school districts and independent

April Mardock:

schools really don't have the ability to tag somebody to be

April Mardock:

cybersecurity full time. In fact, many of them don't even

April Mardock:

have like a network tech that's formally trained in

April Mardock:

cybersecurity, and so the risk is rarely elevated to the

April Mardock:

boardroom. It doesn't make it into executive session, except

April Mardock:

when maybe they go to renew an insurance policy if they have

April Mardock:

one. And unfortunately, it doesn't get raised to the level

April Mardock:

of risk that I think it represents to small districts

April Mardock:

and independent schools. You are potentially at risk of not just

April Mardock:

going offline, but potentially going under. There's a

April Mardock:

significant percentage of districts and small businesses,

April Mardock:

especially that literally stop operating after this happens. I

April Mardock:

can give a case in point. I know of a you know the 403 Bs. It's a

April Mardock:

retirement savings for educators. So one of the 400 3b

April Mardock:

operators that was used in my region got ransomed. All the

April Mardock:

systems were shut down. They didn't have adequate backups,

April Mardock:

and they went under and didn't come back. It happens when a

April Mardock:

ransom event happens. The business may cease to function.

April Mardock:

You lose trust. You lose reputation with your community,

April Mardock:

and potentially you lose your ability to function. You can't

April Mardock:

do assessments. You lose your bus routing. I mean, think of

April Mardock:

all the things that could go sideways if your systems were

April Mardock:

all offline. And it's worth having that business continuity

April Mardock:

conversation with. Anyway, because there's other reasons

April Mardock:

stuff could go offline. It could be an extended power outage, but

April Mardock:

you need to help them understand the consequences of systems

April Mardock:

going offline in terms of availability, and then the

April Mardock:

consequences in terms of lost trust and lack of enrollment as

April Mardock:

a result, and the other pieces of that where maybe they can't

April Mardock:

get it back. What if they can't get their bus routes back? What

April Mardock:

if they can't get the payroll working? Payroll goes offline.

April Mardock:

They can't pay folks. There's just so many high risk things

April Mardock:

that come about as a result of not having eyes on this ball

April Mardock:

that they either need to contract for that support and

April Mardock:

make it a regular part of their process, or they need to train

April Mardock:

somebody up, but they really do need to spend some amount of

April Mardock:

resources on risk managing this. Otherwise, if they choose to

April Mardock:

ignore it, unfortunately, you guys I think introd with it, or

April Mardock:

I saw it recently. Maybe it was actually a K 12 six thing. It's

April Mardock:

like one out of five has seen a cyber incident, so we're next.

April Mardock:

It's another one of those. It's not if it's when, and so if they

April Mardock:

don't pay attention to this, the risk just gets amplified. One

Bill Stites:

of the things that I want to take this out of the

Bill Stites:

boardroom and out of like the sea level, and I want to bring

Bill Stites:

it down to how do you have these conversations with your staff,

Bill Stites:

because we'll talk a lot about the COVID hangover, which was

Bill Stites:

the wild west of apps and tools and things that everyone were

Bill Stites:

signing up for. How do you have this conversation with maybe

Bill Stites:

just below sea level, or when you get into the operational

Bill Stites:

aspects of school, and then when you get into the classroom? How

Bill Stites:

do you make it clear to them that I think, Kevin, you said

Bill Stites:

this earlier. We're not saying no to simply say no. We're

Bill Stites:

saying no for X, Y, and Z reasons. How do you suggest

Bill Stites:

having those dialogs, those conversations with those groups?

April Mardock:

That's sometimes a harder conversation because

April Mardock:

they're trying to teach and they're under resourced and

April Mardock:

scrambling to make do with the resources they have as well, but

April Mardock:

part of this is they now know. For instance, MFA. MFA was a big

April Mardock:

problem for a lot of schools, and MFA. There was a lot of

April Mardock:

pushback of I don't want to get interrupted in the classroom. I

April Mardock:

have little enough time to train my kids as it is. I don't want

April Mardock:

to do it, but they realize everything that's important,

April Mardock:

like their bank stuff, requires MFA, and then you pull it down

April Mardock:

to brass tacks. Well, if you don't MFA, then anyone can log

April Mardock:

in with your account and change where your paycheck gets

April Mardock:

deposited. Right, employee self-service, and so all of a

April Mardock:

sudden you make it relevant. It's a what's in it for me

April Mardock:

approach. So then they realize, oh, if I don't have MFA, then my

April Mardock:

paycheck could get redirected, and it has happened. I know of

April Mardock:

districts where paychecks get redirected because they didn't

April Mardock:

do MFA, and people have a tendency to reuse the same

April Mardock:

password in multiple places, so it can get stolen from lots of

April Mardock:

places. The example I used was it doesn't even require a

April Mardock:

mistake on your part. Evite got broken into, and when Evite got

April Mardock:

broken into, the bad guys stole the passwords in clear text. Do

April Mardock:

you know how many district folks use their same username and

April Mardock:

password from the district on the Evite site? Now the bad guy

April Mardock:

knows your username and your password. If there's no MFA,

April Mardock:

then they can use that username and password on every system

April Mardock:

you've used that same password for, and so that means they can

April Mardock:

redirect your paycheck. They can log in and steal your student's

April Mardock:

data. They can log in and do everything you can do, and so

April Mardock:

then they start to realize, oh yeah, maybe I should be thinking

April Mardock:

about that differently. Applications are similar risks.

April Mardock:

You can show them that the consequence of that loss is

April Mardock:

significant enough to impede their ability to teach. It's a

April Mardock:

cause and effect thing. It's a what's in it for me thing.

April Mardock:

Kevin Warenda, TLIS: It seems like the theme of this podcast

April Mardock:

today has been it's not rocket science, right? You're talking

April Mardock:

about basic hygiene. You're talking about common sense

April Mardock:

approaches. You're talking about things that don't require a lot

April Mardock:

of technical expertise to pull off, and yet we all still need

April Mardock:

to hear it again and again to internalize that and to put

April Mardock:

these things into practice and to check these doors. April, one

April Mardock:

of the things that you were talking about was the MFA piece.

April Mardock:

One of the questions that I had that often comes up. I mentioned

April Mardock:

the audit that we had done, and it came up in terms of part

Bill Stites:

of that audit. I've read a lot that says frequent

Bill Stites:

password changing is often more harmful than having a strong

Bill Stites:

password that meets a certain character length has certain

Bill Stites:

things in it, and then on top of that, having MFA is MFA and a

Bill Stites:

strong password enough, or is there more needed? That

Bill Stites:

frequency of password change. Is really what I'm curious about

Bill Stites:

because I think you need to change your password every 30

Bill Stites:

days, or you need to change your password every X number of days

Bill Stites:

has diminished, and I want to know if that's true or if that's

Bill Stites:

a falsehood that's just getting perpetuated out there, and that

Bill Stites:

you should be changing password and have that MFA piece done.

April Mardock:

So as much as I'd like to wave a magic wand and

April Mardock:

make all the software that districts use single sign-on,

April Mardock:

where there's a password that's managed in that way, that's not

April Mardock:

happening. So if you think about it, 90% of the applications you

April Mardock:

use are single sign-on, and that password rotation-let's say it's

April Mardock:

once a year-that password rotation is fine. And in fact,

April Mardock:

I'd even downgrade the MFA protected passwords and make

April Mardock:

them simpler, make them fairly straightforward. And length

April Mardock:

matters more than complexity, in my opinion. By the way, you

April Mardock:

know, if it's a 14 character password, but you don't do the

April Mardock:

crazy symbols, because all they're going to do is put $1

April Mardock:

sign or a one at the end anyway. You know it. But here's the

April Mardock:

problem I'm finding, and this happened with School Dude, so

April Mardock:

School Dude got compromised, and again, clear text passwords were

April Mardock:

stolen. And it was not at the time single sign-on. District

April Mardock:

employees have a tendency to use, and school employees the

April Mardock:

same username and password for all work things, and they'll

April Mardock:

change it, and they change it everywhere that they use the

April Mardock:

password. So I use J Smith, and I use Totem 223, and that gets

April Mardock:

used everywhere. And the single sign-on systems, when I change

April Mardock:

my password, let's say there's a compromise, you force folks to

April Mardock:

change their password. It gets changed, but it doesn't get

April Mardock:

changed in those things that are not managed by the single

April Mardock:

sign-on. And as IT directors, we know some of the systems we have

April Mardock:

aren't quite the single sign-on yet, whatever it is, HVAC, the

April Mardock:

Access Badging system. I don't know what it is, but often there

April Mardock:

are systems that are not single sign-on yet, and so I believe

April Mardock:

you need to rotate passwords at least once a year, regardless of

April Mardock:

MFA or not, because those passwords are reused elsewhere.

April Mardock:

That's my argument. So I would suggest once a year, not every

April Mardock:

30 days, but annually I think is important because single sign-on

April Mardock:

and MFA is not in all the places.

April Mardock:

Kevin Warenda, TLIS: Bill, it's worth noticing that NIST did

April Mardock:

finally update their guidance on this topic. For a while, they

April Mardock:

were stuck on the constant rotation, but finally realized

April Mardock:

that you can rotate less often when there are additional

April Mardock:

securing factors in place, and only change when there's

April Mardock:

indicators of compromise or on a longer schedule. And that was

April Mardock:

based on field work they did to say, yeah, what we're finding is

April Mardock:

that kind of as April said, humans just put one extra

April Mardock:

character at the end if there's no complexity requirement.

April Mardock:

They're not making better passwords. They're more likely

April Mardock:

to then write it down on a sticky note. So even NIST did

April Mardock:

finally adjust their recommendations. But I think

April Mardock:

April has a good balance there of still do it, especially if

April Mardock:

there's an indicator of compromise. But I think what

April Mardock:

April's pointing out is it's not that system that's actually the

April Mardock:

issue. It's the reuse of that in other systems. If you're not

April Mardock:

encouraging the use of a password manager, where you're

April Mardock:

getting a unique password for every single different service,

April Mardock:

which would obviously be the ideal, but not everyone's going

April Mardock:

to do that. So I think that's good advice.

April Mardock:

And I disagree with this. I think that you do

April Mardock:

need to rotate at least once a year, and not just when it's

April Mardock:

been compromised because of that fact that MFA really isn't in

April Mardock:

all the places.

April Mardock:

Kevin Warenda, TLIS: That's solid recommendation from the

April Mardock:

field, from someone who's seen and talked to many districts

April Mardock:

being compromised. That we'll take your word for that one for

April Mardock:

sure. Are there any topics, programs, things that you wanted

April Mardock:

the opportunity to talk about that we didn't ask about?

April Mardock:

I would just say also look for cooperatives like

April Mardock:

Waspsy in your region that can get you software and services,

April Mardock:

whether it's cybersecurity services or some of the amazing

April Mardock:

software tools out there for incident response or EDRs or

April Mardock:

even managed service providers. I worry about the 24 by seven

April Mardock:

problem. Most small orgs can't cover night, weekend, and

April Mardock:

holidays when attacks happen, and the bad guys are even timing

April Mardock:

nights, weekends, and holidays. So figure out how you can do

April Mardock:

after hours response. And I strongly suggest folks think

April Mardock:

about allowing their tools to automatically isolate either a

April Mardock:

user or a machine. If it flags as compromised, shoot first, ask

April Mardock:

questions later, check it in the morning. But you really need to

April Mardock:

be thinking about isolating proactively, especially off

April Mardock:

hours. But let the system isolate the user or the system

April Mardock:

and follow up, rather than follow up, verify, and then

April Mardock:

isolate. Because the bad guys are moving faster; they are AI

April Mardock:

assisted, and if you leave that thing sitting for a whole spring

April Mardock:

break, you may be in real trouble. So that's one of the

April Mardock:

other things I want folks to think about: is being proactive

April Mardock:

in those and look to your regional service agency, your

April Mardock:

WISIPs of the world, for the tooling for that because they

April Mardock:

often get amazing prices for that kind of stuff.

April Mardock:

Kevin Warenda, TLIS: And it's a lot of great partners and

April Mardock:

vendors. Work with the Atlas community, or the Atlas

April Mardock:

community itself too, has a lot of that. So certainly, we are a

April Mardock:

resource for independent schools to connect with those types of

April Mardock:

vendors as well.

Bill Stites:

I want to thank April. As I mentioned before, we

Bill Stites:

came on every day. I've got emails, whether it's from K 12

Bill Stites:

six or CISO or our New Jersey cybersecurity cell, and it can

Bill Stites:

be drinking like a fire hose, and having her on to be able to

Bill Stites:

talk about some of these really practical pieces that we focus

Bill Stites:

in on really helps.

Hiram Cuevas:

I'm really glad I made it to this episode because

Hiram Cuevas:

the beach is calling my name, but this was definitely a

Hiram Cuevas:

conversation that needed to be had, and I was grateful for the

Hiram Cuevas:

opportunity to speak to you, April.

Hiram Cuevas:

Kevin Warenda, TLIS: And I'll echo what Bill and Hiram said,

Hiram Cuevas:

"Thank you, April, for joining us today. I think we'll maybe

Hiram Cuevas:

wrap with a softball question: Is there a book or a podcast or

Hiram Cuevas:

a white paper that you've read this summer or listened to that

Hiram Cuevas:

you think is worth a share for our community?

April Mardock:

I will have to say on the entertainment side of

April Mardock:

things, because of the gaming influence, I'm enjoying the

April Mardock:

Dungeon Crawler Carl series. It's giving me a perspective on

April Mardock:

how to troubleshoot things in novel ways and thinking outside

April Mardock:

the box. So, if you haven't already seen it, there's an

April Mardock:

audio book and a regular book series that's becoming almost

April Mardock:

viral, but it's worth a chance to step outside of yourself and

April Mardock:

think outside the box, because some of the solutions that we're

April Mardock:

asked to come up with, especially in small orgs, we

April Mardock:

have to be really creative. And sometimes I need a little bit of

April Mardock:

encouragement in that space.

April Mardock:

Kevin Warenda, TLIS: I appreciate that, and thanks for

April Mardock:

encouraging all of us, Bill Hiram. What's on your summer

April Mardock:

reading list? Anything worth sharing? To be honest with you,

April Mardock:

I'm just

Bill Stites:

getting back off of a two week break where I

Bill Stites:

did

Bill Stites:

absolutely nothing. I didn't even

Bill Stites:

read.

Bill Stites:

I just kind of like laid in the sun. Hiram, hopefully you're

Bill Stites:

going to get a bunch of that. My reading list consists of about

Bill Stites:

200 emails that have piled up over the course of the last two

Bill Stites:

weeks of being out.

Hiram Cuevas:

I'm similar boat there, except I'm reading terms

Hiram Cuevas:

of service agreements with different vendors.

Hiram Cuevas:

Kevin Warenda, TLIS: All right, quite a lively bunch here.

Hiram Cuevas:

April, thanks so much for joining us today and sharing

Hiram Cuevas:

your expertise. If anyone wants to connect with you, what's the

Hiram Cuevas:

best way to find you online or find what you're writing?

April Mardock:

Catch me in LinkedIn and connect me there.

April Mardock:

And then also anybody in the Washington areas, welcome to

April Mardock:

ping me at cybersecurity at wasipsy. It's w sipc.org if they

April Mardock:

want assistance in my state.

April Mardock:

Kevin Warenda, TLIS: All right, thanks everyone for joining

April Mardock:

another episode of Talking Technology with Atlas. See you

April Mardock:

next time.

Peter Frank:

This has been Talk Technology with Atlas, produced

Peter Frank:

by the Association of Technology Leaders in independent schools.

Peter Frank:

For more information about Atlas and Atlas membership, please

Peter Frank:

visit theatlas.org. If you enjoyed this discussion, please

Peter Frank:

subscribe, leave a review, and share this podcast with your

Peter Frank:

colleagues in the independent school community. Thank you for

Peter Frank:

listening.

Video

More from YouTube