April Mardock, Chief Information Security Officer at WASIPC, joins the podcast to analyze the primary entry points targeted in K-12 ransomware incidents. The discussion offers actionable guidance on multi-factor authentication, vendor risk management, data retention policies, and using gamified tabletop exercises to prepare school leadership for cyber incidents.
Welcome to Talk Technology with Atlas, the show
Peter Frank:that plugs you into the important topics and trends for
Peter Frank:technology leaders, all through a unique independent school
Peter Frank:lens. We'll hear stories from technology directors and other
Peter Frank:special guests from the independent school community,
Peter Frank:and provide you with focused learning and deep dive topics.
Peter Frank:Kevin Warenda, TLIS: Hello, everyone, and welcome to Talking
Peter Frank:Technology with Atlas. I'm Kevin Warendo, Director of Information
Peter Frank:Technology Services at the Hofstra School in Lakeville,
Peter Frank:Connecticut,
Bill Stites:and I'm Bill Stites, the Director of
Bill Stites:Technology at Montclair Kimberly Academy in Montclair, New
Bill Stites:Jersey,
Hiram Cuevas:and I'm Hiram Cuevas, the Director of
Hiram Cuevas:Information Systems and Academic Technology at St. Christopher
Hiram Cuevas:School in Richmond, Virginia.
Hiram Cuevas:Kevin Warenda, TLIS: All right, gentlemen, I made it. The
Hiram Cuevas:training wheels are off. Peter finally let me open the show by
Hiram Cuevas:myself. Well, it's good to be rid of Peter. I think that's
Hiram Cuevas:what we can say about that. Anything that pushes Peter to
Hiram Cuevas:the side, I am all for.
Hiram Cuevas:I'm speechless. I'm actually a big fan of Peter,
Hiram Cuevas:so you know.
Bill Stites:Oh, I'm Peter's biggest fan, and he knows it. I
Bill Stites:just like giving him grief. Hiram and I, you and I, just
Bill Stites:spent so much time with Peter. I don't even know where to begin.
Bill Stites:Kevin Warenda, TLIS: Indeed, we did. Well, I'm preparing for a
Bill Stites:totally new experience myself next week. At the end of the
Bill Stites:week, my family, including our dog, will be piling into an RV
Bill Stites:or rented to travel to the Midwest. My older daughter is
Bill Stites:going to be competing in gymnastics at the Junior
Bill Stites:Olympics.
Bill Stites:Oh, awesome! Good for you. We've got campgrounds
Bill Stites:mapped out. We've got a chartered fishing trip, and then
Bill Stites:everything else is going to be quite the adventure. So, I'm
Bill Stites:actually curious, Bill and Hiram, you have any epic road
Bill Stites:trip memories worth sharing? So many people may know I've seen
Bill Stites:all 30 baseball stadiums in the United States. We've generally
Bill Stites:flown into different areas and mapped them around, and I will
Bill Stites:tell you as far as a road trip goes. One, I'm extremely jealous
Bill Stites:of what you're doing. I always wanted to get a camper and do
Bill Stites:that because my retirement goal is to live the van life. I want
Bill Stites:to get something kind of just be able to travel around like that.
Hiram Cuevas:Teach a chum van-that's what you want,
Bill Stites:exactly. But but based on the travels that I had,
Bill Stites:the one thing I would highly recommend people to do: we flew
Bill Stites:into Seattle, we drove over to Cannon Beach, Oregon, home of
Bill Stites:the Goonies, where that was filmed, and then we drove down
Bill Stites:the Pacific Coast to San Francisco, and that is a road
Bill Stites:trip that I would take time and time again, some of the most
Bill Stites:beautiful landscape, beautiful scenery, and one of the best
Bill Stites:drives that I had. We were amazed because when we were
Bill Stites:inland on one side, it was like 100 degrees, and as we made our
Bill Stites:way back to the coast and over the mountains and came back
Bill Stites:down, we literally saw a 50 degree switch in temperature
Bill Stites:when we went from one side to the other, so prepare for all
Bill Stites:and enjoy yourself. But it was a great road trip.
Hiram Cuevas:I'm very jealous as well. Grace and I we drove
Hiram Cuevas:across the country many years ago, did Bryce Canyon, Kings
Hiram Cuevas:Canyon, and Sequoia, and then for our honeymoon we camped for
Hiram Cuevas:two weeks out in the Pacific Northwest in Montana. So we knew
Hiram Cuevas:we were going to get along after two weeks camping together. I
Hiram Cuevas:think what you'll probably love the most is when you pass
Hiram Cuevas:Kentucky. That's when the humidity starts to drop. It
Hiram Cuevas:really is fascinating, and the dry air of the Midwest and the
Hiram Cuevas:further west you go is just fabulous compared to the East
Hiram Cuevas:Coast.
Hiram Cuevas:Kevin Warenda, TLIS: All right. Well, speaking of going places,
Hiram Cuevas:I'm excited to see where the podcast takes us today. Our
Hiram Cuevas:guest is a veteran K 12 cybersecurity leader with more
Hiram Cuevas:than 20 years of experience. She's nationally recognized in K
Hiram Cuevas:12 cybersecurity risk management and governance. Currently
Hiram Cuevas:serving as the Chief Information Security Officer for WASIPSE,
Hiram Cuevas:which is a Washington School District cooperative. It's my
Hiram Cuevas:pleasure to welcome April Mardach to the show. Please tell
Hiram Cuevas:us more about yourself and your journey that brought us here
Hiram Cuevas:today.
April Mardock:Sure. So I've been in K 12 a long time. I
April Mardock:originally actually started as a var doing support for back in
April Mardock:the day Solaris, Novell, Netware, a lot of old tools, and
April Mardock:slowly migrated to supporting Macs, which ended up with a lot
April Mardock:of K 12 customers. That time, I supported over 100 different
April Mardock:companies, small, medium, and large. So I got a lot of field
April Mardock:engineer experience, hands on, you know, setting up the whole
April Mardock:set stuff and troubleshooting and training users and all of
April Mardock:the things. And eventually, I ended up taking a position with
April Mardock:a local ESD, which is like a regional area that supports
April Mardock:school districts. So, like Washington has nine ESDs, and
April Mardock:the ESDs are partially state funded in a tiny way, like 5% of
April Mardock:their budget, and then the rest of their income comes from their
April Mardock:local school districts as they provide services. And so, I
April Mardock:provided regional services to K 12 s in my region, and since
April Mardock:basically '99, and in fact was involved in a bunch of Y2K
April Mardock:stuff. So I've been doing cyber for a long time. Did firewall
April Mardock:audits and configurations. I was on the techy side of things,
April Mardock:right? Doing an awful lot of support for soup to nuts, a
April Mardock:district that has no techs or one IT person. Who might also be
April Mardock:the science teacher? So you've got the small districts, the
April Mardock:medium districts, and the large districts. And eventually, I
April Mardock:ended up getting hired by the largest district in the state
April Mardock:here in Washington, Seattle. Worked for Seattle 15 years ish,
April Mardock:and then now I'm back at the state level, K 12, working for
April Mardock:WASI as their chief information security officer. And what's
April Mardock:cool about my job here is I am 50% internal facing, doing
April Mardock:cybersecurity and CISO work, helping with incident planning
April Mardock:and response, all of the normal kind of create a cybersecurity
April Mardock:program from scratch. But I'm also doing 50% external facing,
April Mardock:which allows me to do some of the national work with K 12 six,
April Mardock:and to work with districts across my state in helping bring
April Mardock:everybody to a higher degree of cybersecurity stability and
April Mardock:include postures. So, for instance, one of the things that
April Mardock:I think I'm about to get kicked off, I'm actually participating
April Mardock:as a lead in the state's cyber incident response team, so I'll
April Mardock:probably be heavily involved in K 12 support in that space, and
April Mardock:I'm also working with the state on putting together a
April Mardock:vulnerability management process where we will get an email and a
April Mardock:flag when a district has essentially-I don't know-you've
April Mardock:seen how many districts have gotten taken over by way of
April Mardock:exposing an Exchange server or a SharePoint server or something
April Mardock:like that that didn't get patched in a timely way, or just
April Mardock:didn't get removed because it was end of life. Right? Those
April Mardock:are kind of threats, and the state's going to work with me.
April Mardock:Maybe it's looking really, really likely on allowing WIC to
April Mardock:sort of coordinate that notification and helping
April Mardock:districts figure out what to do to mitigate their
April Mardock:vulnerabilities for those sort of extraordinary all hands
April Mardock:remote takeover risk kind of things. So super excited! It's
April Mardock:been a long journey, and I'm in a place where I can really move
April Mardock:the needle, both at the state and the national level. With the
April Mardock:K 12 six side, the technical working group there is a group
April Mardock:of K 12 geeks, security geeks from across the U.S. as well as
April Mardock:some folks that are not geeks, that help us with making sure
April Mardock:the messaging is understandable for any district. And that group
April Mardock:has come up with some amazing resources that are free to
April Mardock:anybody who wants to use them. Things like the "What to Do If
April Mardock:You're Compromised" checklist, where you can basically go
April Mardock:through and if you get a compromised account, it reminds
April Mardock:you of all the things to do-not just reset the password or flush
April Mardock:the sessions, but look and see if somebody connected an
April Mardock:application. Right? Look and see what rules might have been
April Mardock:configured. Look to see what else may have been done, because
April Mardock:as we all know, the attackers are getting more sophisticated.
April Mardock:So, that's a group that also came up with a 14 question
April Mardock:cybersecurity assessment that's really easy for small districts,
April Mardock:independent schools to do. That gives you like your top marching
April Mardock:orders for the top one or two things you should really focus
April Mardock:on for the year. Doesn't take a rocket scientist. Really
April Mardock:approachable. So that's been kind of one of my big goals: is
April Mardock:to try to make cybersecurity approachable for everybody, all
April Mardock:the districts, tiny or huge. Oh,
April Mardock:Kevin Warenda, TLIS: that's such important work. I saw recently
April Mardock:you posted an article on your LinkedIn feed. I think it was
April Mardock:you've interviewed 24 school districts who've been victims of
April Mardock:ransomware, and you kind of boiled that down into a really
April Mardock:approachable lens to think about this through like the three
April Mardock:doors that attackers come through. Maybe you could talk a
April Mardock:little bit about your findings there and how easy it is
April Mardock:actually to maybe think about securing those doors.
April Mardock:Yeah, when I was with my very large district, I
April Mardock:did not want to be next in the ransomware parade, and to do
April Mardock:that, I started asking folks at conferences and other places.
April Mardock:You know, after they presented about their event, you know how
April Mardock:did bad guys get in? You know, in the very beginning, the camel
April Mardock:got their nose under the tent. Where'd they poke their nose,
April Mardock:right? And it turned out that it was really only three answers,
April Mardock:and three answers that aren't rocket science. The first one
April Mardock:tends to be when, like I mentioned earlier, there's a
April Mardock:device or a system that's exposed to the internet and is
April Mardock:not patched in a timely way, whether that's a server like an
April Mardock:Exchange or SharePoint server, or it's a VPN appliance, it's a
April Mardock:firewall management port. Please tell me you've removed all the
April Mardock:management ports from internet. They should not be facing the
April Mardock:internet, but that's a different discussion. But anything that's
April Mardock:basically exposed to the internet that wasn't patched in
April Mardock:a timely way, or is end of life and doesn't have patches
April Mardock:anymore, right? So that's number one. It's keep those things
April Mardock:patched really quickly. And it used to be we said 30 days. Now
April Mardock:it's 14 days. I'd say if you can patch it within 48 hours, you're
April Mardock:in a better place. If there's a big announcement that says
April Mardock:people can take over your whole system through that device is
April Mardock:probably a good idea to patch it, especially those CISA known
April Mardock:exposed vulnerabilities are also known as CEVs. So that's door
April Mardock:number one. Door number two is where basically remote access is
April Mardock:possible, and it's either VPN or. Some kind of remote desktop
April Mardock:service, but there's no MFA required, meaning you don't have
April Mardock:to put in an authentication token. You don't get an SMS.
April Mardock:There's nothing other than a username and a password that
April Mardock:gives you full remote access to that district or that
April Mardock:organization, and that includes vendors. We're really bad about
April Mardock:letting vendors use the same account for all their texts, and
April Mardock:we don't make them use MFA because well, there's phone
April Mardock:issues, right? And we're terrible about enforcing our own
April Mardock:rules when we get pushback. And what that means is that vendors
April Mardock:have some bad habits too. They like to, for instance, reuse
April Mardock:password across clients. And so, if a password gets compromised,
April Mardock:whether it's a staff person's password or a vendor's password,
April Mardock:and that username and password can be used to log into that
April Mardock:district and have full remote access, that's a pretty big
April Mardock:hole, right? And so that's number two. The other one that
April Mardock:happens is phishing, which we all see phishing every day. We
April Mardock:run into that, but phishing grows legs and takes over your
April Mardock:organization if the user who gets the fish and responds to
April Mardock:the fish also has local administrator rights, because
April Mardock:what happens then is the fish lands, and the user's machine is
April Mardock:then taken over and used to crawl across and take over the
April Mardock:rest of the network, and sometimes the hygiene of that
April Mardock:organization is bad enough, where they've also used the same
April Mardock:administrator configuration password on all the devices. All
April Mardock:the staff devices get a password. All the student
April Mardock:machines might get a different password. But the problem is
April Mardock:when that password then gets compromised, it can be used to
April Mardock:take over every machine very quickly.
Bill Stites:You mentioned working with Solaris and with
Bill Stites:Novell, and I think at least Hiram and I-I'll leave Kevin out
Bill Stites:of this-but Hiram and I are the old gray beards in the room.
Bill Stites:We've been at this for a while. When you said that Hiram and I
Bill Stites:are both heard Novell, it was like ding ding, remembering from
Bill Stites:years past. And I just remember walking into our network room,
Bill Stites:our network closets and just the number of tools that we had that
Bill Stites:were on prem to deal with all of this patching that you're
Bill Stites:talking about, you know, and everything that was going on
Bill Stites:with that, the number of servers you were maintaining, so on and
Bill Stites:so forth. I want to get your thoughts on how that model, how
Bill Stites:that mode has changed with so much moving to the cloud now,
Bill Stites:and so much of what's out there going into the cloud, and what
Bill Stites:your thoughts are there, and what that means for, I'll say
Bill Stites:the due diligence that we need to do on our parts to make sure
Bill Stites:that our cloud services are configured properly, or our
Bill Stites:cloud providers are doing their due diligence, and I want to
Bill Stites:thank both K 12 six and CISA because I saw this on a K 12 six
Bill Stites:email just like I think yesterday or the day before that
Bill Stites:there's a new set of tools that were put out called Scuba. That
Bill Stites:is for those that don't know the acronyms because it's like
Bill Stites:acronym soup when we talk about this stuff. That is a secure
Bill Stites:cloud-based application. It's a set of tools and recommendations
Bill Stites:that they put out to help you evaluate these cloud services.
Bill Stites:So, with that said, what are your thoughts in everything that
Bill Stites:I mentioned there?
April Mardock:Okay, so I'll start with, although you've
April Mardock:probably pushed 75 or even 80% of your stuff to the cloud,
April Mardock:don't forget you still have on-prem entry points like the
April Mardock:firewall and like the firewall management ports. Make sure you
April Mardock:stay on top of keeping those patched. We don't think of them
April Mardock:as servers, right? We don't think of them as something that
April Mardock:needs to be patched, but they do. So that's stage one. Stage
April Mardock:two, vendors make mistakes too, and sometimes the vendor
April Mardock:defaults are terrible. And a case in point on this would be
April Mardock:if you guys saw what happened with Clark County Schools, one
April Mardock:of the attacks that they dealt with was somebody taking over
April Mardock:the student passwords. And at the time, the student passwords
April Mardock:were based on birth dates. And I will say a lot of school
April Mardock:districts use birth dates or something like it to configure
April Mardock:those initial passwords, and they don't always force password
April Mardock:changes when they do it. Here's the problem that makes a student
April Mardock:account easy to log into, easy to guess because you get the
April Mardock:user account, you get the password, which is their
April Mardock:birthdate, and you log in. Now here's where it gets ugly.
April Mardock:Everybody should be doing this who's a school district IT
April Mardock:manager, which is you need to log in as a student account and
April Mardock:look around and search for things like SPED or IEP or
April Mardock:discipline or all of the sensitive words right from a
April Mardock:student account and see what's been overshared, because what
April Mardock:happens with Clark County, as I understand it, is there were
April Mardock:Google work groups that a student could add themselves, or
April Mardock:a criminal using a student's account could add themselves to,
April Mardock:but either way, it's a problem. If a student can do this, it's
April Mardock:also problematic, and get access to all the content in that work
April Mardock:group. What that means is, if you can break in with a student
April Mardock:account and can search for all of that sensitive. Content you
April Mardock:can steal that sensitive content, and the default
April Mardock:configuration was problematic. I'll use a Microsoft example.
April Mardock:Microsoft made it so that when you shared a file in the earlier
April Mardock:days, it would share with everyone, whether they were
April Mardock:on-prem or in the cloud. And so you created this link. If that
April Mardock:link got out, it was visible. But here's where it gets ugly.
April Mardock:The AI search engines can now expose files that were shared
April Mardock:with everyone, internet access that you didn't intend to ever
April Mardock:share. Now, just because the person has privilege, because
April Mardock:you said allow it to either everyone or allow it to everyone
April Mardock:in the organization. Okay, think of this from a teacher point of
April Mardock:view. I want to share a file with the kids in my class, and
April Mardock:I'm going to share this file. And I'm not going to name all 30
April Mardock:kids that I want to send this file to. I'm going to share it
April Mardock:with everyone in the org. Right? That makes sense for a teacher.
April Mardock:Same thing happens for say somebody in IT. They want to
April Mardock:share something out to all the staff. They'll share it with
April Mardock:everyone in the org. Well, here's something that often
April Mardock:happens in K-12: the students and the staff are in the same
April Mardock:organization. When you share a file with everyone in the org,
April Mardock:it gets shared to everyone, staff and students. Sometimes
April Mardock:those files are sensitive. You don't intend it to get in the
April Mardock:wrong hands, but if you've shared it with wide open
April Mardock:privileges, now anyone with an account, and that means
April Mardock:criminals with accounts, can get to that file. So those are
April Mardock:mistakes kind of made in the early configuration where the
April Mardock:default sharing was too open, or the default for that group
April Mardock:membership is too open. It allows people to inject
April Mardock:themselves. All of those kinds of defaults in your tenant, your
April Mardock:Microsoft or your Google tenant can bite you because a it's
April Mardock:easier to steal accounts because the passwords are sometimes
April Mardock:either already know or easy to guess, and b those accounts if
April Mardock:you start searching for sensitive content will reveal
April Mardock:things you'd really rather they not reveal. So that's part one.
April Mardock:Part two is our vendors and the vendor stuff? Couple things
April Mardock:there. So make sure that when you're contracting with vendors,
April Mardock:if you give PII to vendors, this is one of the things I worked on
April Mardock:with K 12 six in the technical working group.
April Mardock:We actually created a document that you guys should have access
April Mardock:to. That is what I call lightweight vendor management,
April Mardock:and there's low risk vendors, medium risk vendors, and high
April Mardock:risk vendors, and we consider the high risk vendors vendors
April Mardock:that either have really sensitive student data, or are
April Mardock:operationally critical. If this thing goes down, we have trouble
April Mardock:teaching, or we have trouble keeping the buildings open, or
April Mardock:we have trouble bussing kids-it's something that will
April Mardock:really create a showstopper kind of situation. So those are the
April Mardock:high-risk vendors, and for the operationally high-risk vendors,
April Mardock:I ask questions like, "What kind of redundancy do you have if
April Mardock:there's a Microsoft outage in this region? Can you fail over
April Mardock:somewhere else? Or Amazon outage in this region? Can you fail
April Mardock:over somewhere else? Here's the sneaky part: Amazon and
April Mardock:Microsoft will charge you for that extra resiliency. So some
April Mardock:companies don't pay it. If they're an operationally
April Mardock:critical vendor, you want to start asking those questions.
Hiram Cuevas:We actually felt some of that when the incident
Hiram Cuevas:in the Strait of Hormuz occurred. About 22% of all data
Hiram Cuevas:traffic apparently goes through that area, and a lot of folks
Hiram Cuevas:were complaining at my school and a bunch of other schools.
Hiram Cuevas:You know what's going on with our SaaS applications, and I've
Hiram Cuevas:reminded them, hey, there's a lot going on, a lot of rerouting
Hiram Cuevas:of traffic, and sometimes that kind of stuff is out of our
Hiram Cuevas:hands, and we can't even control that because it's such a main
Hiram Cuevas:trunk of data.
April Mardock:Yeah, for sure. And outages, if it's
April Mardock:operationally critical to your org, you want to make sure that
April Mardock:that software that you are subscribing to has some
April Mardock:resilience built in, so that you have less outages as a result. I
April Mardock:have seen cases where, for instance, the West Side Amazon
April Mardock:West drops, or maybe some of their DNS functionality drops,
April Mardock:and all kinds of things break. Right. So, what you want is to
April Mardock:make sure that the vendor that you're putting your money in for
April Mardock:operationally critical stuff has resiliencies built in. Whether
April Mardock:it's incident response stuff, they have disaster recovery and
April Mardock:can come back. They have resiliency in their services.
April Mardock:You just want to make sure that's covered. And then on the
April Mardock:flip side of that, where it's sensitive data, those are
April Mardock:different questions, right? Number one, I want to make sure
April Mardock:that they can delete my data when I'm done, and that they
April Mardock:don't force me to send them a certified letter to say you must
April Mardock:delete my data because vendors see data as a long-term money
April Mardock:source, and they really don't like deleting it. They don't
April Mardock:like getting rid of it. They don't like purging it. They like
April Mardock:to feed it to their AI models and learn from it. And I really
April Mardock:want my data back when I'm done. The other thing that I'm
April Mardock:thinking about with vendors is: Do you really have to give them
April Mardock:all the data they're asking for? As an example. I stopped giving
April Mardock:vendors birth date data. Why? Most of the time, they can get
April Mardock:by with the graduation year. They don't need a birth date.
April Mardock:They just need basically a rough idea of what range the kid is
April Mardock:in. It's not always the case, right? I can't do that with
April Mardock:every vendor. There are a few cases where that's an exception.
April Mardock:But in general, why are we giving, for instance, vendors
April Mardock:parent home address information just because they ask for it? If
April Mardock:they don't have a legitimate reason to mail the parents, I
April Mardock:don't think they should have home address information. Maybe
April Mardock:email if the parents legitimately interacting with
April Mardock:them or registering with them or whatever for a portal, but do
April Mardock:they really need a home address? And I start asking that question
of vendors:Is why are you asking for this content? Maybe
of vendors:we used to give this to you, but maybe we shouldn't anymore.
of vendors:There isn't a reason to give vendors content that they really
of vendors:don't need for the purpose that we're hiring them for.
of vendors:Kevin Warenda, TLIS: Yeah, and it strikes me as you're asking
of vendors:your vendors about how resilient they are. I know we go the extra
of vendors:step too to ask for a software bill of materials. Like that
of vendors:understanding of their service is probably not just one thing;
of vendors:it's probably also reliant on their own third-party vendors.
of vendors:And so, if they're hosting their application in AWS West, it's
of vendors:good to understand. All right, then if you're tied to that
of vendors:region, that if that goes down, this service may also go down. I
of vendors:actually spend a lot of time having to educate my community
of vendors:when things stop working, as to why that's down. It's like,
of vendors:well, why is Canvas down? It's like, well, because Canvas is
of vendors:hosted on a third-party cloud that was down today on DNS
of vendors:issues. Like, so yeah, Canvas's issue is actually the
of vendors:infrastructure they're reliant on. So I think that's an
of vendors:important call out that you made there. It's like ask your
of vendors:vendors to describe their solution, what it's built on,
of vendors:and how it's configured. Not just from a resiliency and a
of vendors:data security or data residency perspective, but also just in
of vendors:terms of what makes up your service. What are you also
of vendors:contracting with, and what are your agreements with those
of vendors:vendors too? Because this is where we get into data residency
of vendors:or controllers and processors too, right? Depending on who
of vendors:that goes to, like if you're signing a contract with vendor
of vendors:A, well, if there's a sub processor involved there, like
of vendors:that data may actually go into that other third party, and that
of vendors:agreement survives that. So I think that's great that you're
of vendors:asking about that, and I would say expand that even to all
of vendors:aspects of that service offering to them. The
Bill Stites:one thing I will add to what you just said is
Bill Stites:that Hiram and I have been spending a lot of time working
Bill Stites:with one of the groups that partner with ATLIS a lot is
Bill Stites:nine, and what you're talking about is that vendor vetting,
Bill Stites:those sub processors. It's amazing when you get into that,
Bill Stites:you start looking at that not only from the resilience
Bill Stites:standpoint, but where's all that data going? And April, you said
Bill Stites:something that really resonated with me. When you start working
Bill Stites:with a lot of these vendors, you know how much information are
Bill Stites:you giving them? I think one of the things that often happens,
Bill Stites:and I can remember distinctly saying no to one of our vendors,
Bill Stites:was when they were asking for API level access to our
Bill Stites:information systems because they were connecting things that was
Bill Stites:providing direct service. It was like if we wanted to use this,
Bill Stites:this how it went in, and they were like, "Well, just give us
Bill Stites:API, you know, read write to all these scopes. And I'm like, "No,
Bill Stites:I'll give you read access, and I'll give you read access to
Bill Stites:these because you need to tell me why. And a lot of times, what
Bill Stites:I found is not for nothing. It's laziness on the part of the
Bill Stites:vendor to really work to only ask for what they need. They're
Bill Stites:like, you know what? Just give me as much as you can, and I'll
Bill Stites:figure out what I'm going to do with it later. With no thought,
Bill Stites:or maybe there is thought, and I'm just being naive to what
Bill Stites:they're actually requesting and what that actually opens up from
Bill Stites:that risk standpoint.
April Mardock:Well, there's another layer to that too: is
April Mardock:how long are they allowed to keep the data? And I know for
April Mardock:districts, we have a tendency to keep stuff as long as we
April Mardock:possibly can because at some point that turned out to be a
April Mardock:valuable thing. I'm going to argue the calculus has changed,
April Mardock:and keeping data, especially sensitive data like discipline
April Mardock:data longer than you need to is a liability, and so when you're
April Mardock:working with a vendor and you're giving them sensitive content,
April Mardock:you really ought to have a retention and archive and
April Mardock:removal process in place so that all the data doesn't stay there
April Mardock:forever. Case in point, a lot of us use payroll systems, right?
April Mardock:Payroll systems have like bank account information. How many
April Mardock:years of bank account information is in that system?
April Mardock:If it gets compromised, they might be going back 2030, years.
April Mardock:That becomes a problem if you don't have the ability to purge
April Mardock:the content safely and get rid of the content you aren't
April Mardock:legally required to keep, and you don't have a process for
April Mardock:managing that, whether it's in house or with a vendor. That
April Mardock:creates a big liability because when you are compromised, you're
April Mardock:going to have to go back and notify decades of employees and
April Mardock:or students if you haven't archived that content and pulled
April Mardock:it, especially out of the live systems. They do tend to
April Mardock:compromise the live systems first. They may eventually get
April Mardock:around to archives if you have to keep it for some legal
April Mardock:reason. It doesn't necessarily have to be in the live load,
April Mardock:right? You could put it in another database that you zip up
April Mardock:and tuck away for when you need it for something else, and maybe
April Mardock:that's password protected or some other way less accessible
April Mardock:to the attackers. But if it's all in your live system and it
April Mardock:goes back decades, you're going to be notifying decades of
April Mardock:people, and that's expensive. And it's not fair that it's not
April Mardock:their fault that you decided to keep data longer than you needed
April Mardock:to.
Hiram Cuevas:What's interesting about that is I don't know many
Hiram Cuevas:folks that actually ask vendors to delete their data. Schools,
Hiram Cuevas:in particular. I mean, when you have the transition of employees
Hiram Cuevas:coming in and out and in and out and in and out, how many of us
Hiram Cuevas:actually have done that due diligence of saying, "Hey, I
Hiram Cuevas:need to contact all my vendors within my tech stack to
Hiram Cuevas:eliminate these people or this group of students or whatever.
Hiram Cuevas:It's a massive undertaking, but it certainly is one that we need
Hiram Cuevas:to keep a top of mind,
April Mardock:and I would think of like a phase one, phase two
April Mardock:approach. Maybe you don't do it on a micro level for everyone
April Mardock:who leaves. There's often, at least in the state of
April Mardock:Washington, there's stuff we have to keep seven years after
April Mardock:they leave, or
Hiram Cuevas:correct,
April Mardock:however long it is. But you set up something
April Mardock:where all the records that are discipline records that get to a
April Mardock:certain age that have aged out can get pulled together, right?
April Mardock:You don't manage it as an individual, but you start
April Mardock:tagging and classifying data, and asking the vendors to do the
April Mardock:same so that they can appropriately dispose of data
April Mardock:without you micromanaging and saying, "Well, this person left
April Mardock:seven years ago. Let's go purge their stuff. I can't imagine a
April Mardock:small district taking that on, it's a big lift, but there are
April Mardock:ways we can still push the vendors to delete content in a
April Mardock:timely way. And the other thing is, when you change vendors and
April Mardock:you move data from System A to System B, don't move all of it
April Mardock:if you can avoid it. Use those opportunities when you're
April Mardock:changing vendors or doing upgrades to purge content you
April Mardock:don't legally have to keep. Whether that's the vendor doing
April Mardock:the work or you doing the work, I think it's something we need
April Mardock:to be more intentional about.
Hiram Cuevas:So, April, we've been looking at this at a very,
Hiram Cuevas:very high level, at 50,000 foot level, and I'd be curious if you
Hiram Cuevas:wouldn't mind opining on a situation that I think many
Hiram Cuevas:schools are dealing with this summer. I had a faculty member
Hiram Cuevas:come back to me after attending a conference, all sorts of great
Hiram Cuevas:ideas come out of conferences, and one of them had to do with
Hiram Cuevas:his interest in using App Scripts to develop an extension
Hiram Cuevas:for him to use with his students. And when I took a step
Hiram Cuevas:back, I was like, "Okay, App Scripts is open by default, and
Hiram Cuevas:I didn't realize it was open by default on the Google domain. So
Hiram Cuevas:that the first thing we did was we shut that down,
April Mardock:turn that off.
Hiram Cuevas:Yeah, and I'm curious what your opinion is in
Hiram Cuevas:general about the whole access to app scripts by anybody to
Hiram Cuevas:your Google domain, for better or for worse. I mean, this
Hiram Cuevas:teacher wants to do the right thing. He wants to try and reach
Hiram Cuevas:kids a certain way, and I think it's a great idea. I'm trying to
Hiram Cuevas:develop a sandbox, but we don't have the resources in order to
Hiram Cuevas:try and figure all that out when it just appears in the middle of
Hiram Cuevas:the summer. Be curious what your thoughts are.
April Mardock:So generally, it's one of those where I turn
April Mardock:off the ability for folks to enable it by default, and they
April Mardock:have to go through a vetting process, and most of the
April Mardock:districts I'm dealing with now have to legally review software
April Mardock:for accessibility anyway, and that includes stuff that you
April Mardock:would expose in a classroom, like your extension that you're
April Mardock:talking about, because the district I worked for was the
April Mardock:first district in the U.S. to get sued for not having a math
April Mardock:tutoring program that was intended for the student use was
April Mardock:not accessible by a blind parent at home, and it turned out some
April Mardock:of the district web pages also weren't accessible to blind
April Mardock:parents, and what it meant was that the district had to do a
April Mardock:formal intake process to avoid further lawsuits to make sure
April Mardock:that software met a certain minimum standard, and all
April Mardock:software had to go through that process. And the rule was
April Mardock:anything that the district purchased or anything that the
April Mardock:district deployed or allowed to be deployed, right? Like this
April Mardock:application that you're talking about, had to go through a
April Mardock:formal review process, and that has a checklist of things to
April Mardock:look at, whether it's accessibility, whether it's the
April Mardock:cybersecurity configuration, whether it's the privacy
April Mardock:concerns that might come with it, like any other extension
April Mardock:that you would deploy, you run it through the same process. If
April Mardock:that teacher wants to submit their custom written application
April Mardock:and go through the same vetting process, I would expect the
April Mardock:process to allow fair treatment of that in the same way they
April Mardock:would if they wanted to bring in a third-party tool. The problem
April Mardock:I run into is a little more esoteric. Is yes, I want to turn
April Mardock:it off and vet everything that I turn back on, and I want to have
April Mardock:an intake process to cover legal. But you're going to run
April Mardock:into CTE classes and other places where they want to do
April Mardock:that kind of programming and learn. Those skills and become
April Mardock:capable of doing this kind of work, and so what you'll end up
April Mardock:doing is creating special sandboxes for that, where you're
April Mardock:going to have to find a way around just saying no. And so I
April Mardock:understand it's a complicated ask.
April Mardock:Kevin Warenda, TLIS: I think it's ironic. I spent almost a
April Mardock:decade in public school supporting technology as well,
April Mardock:so there's definitely that angle of if there's a regulation or a
April Mardock:law or legal reason to do something, you can leverage that
April Mardock:as the excuse of why you're doing it to try to maybe deflect
April Mardock:the responsibility of that choice from the IT director. And
April Mardock:I find myself doing that now, even with our cyber liability
April Mardock:provider, right? So as independent schools, maybe we
April Mardock:don't have so much of that regulation or public school
April Mardock:requirements based on statutes and such, but I'm not above
April Mardock:using the cyber liability policy requirements to say no. Like the
April Mardock:reason we have MFA for everyone is not because I want to make
April Mardock:your lives harder; it's because it's required by our insurance
April Mardock:provider, or we have a vetting process for software and
April Mardock:applications because it's required by our cyber liability
April Mardock:provider, so it's ironic we have to use that as the tool to try
April Mardock:to deflect from why we're doing that. But it's for the right
April Mardock:reasons, and I think it's tough sometimes to try to educate
April Mardock:users as to why that's so important. I want to come back
April Mardock:to something you said earlier about the oversharing of
April Mardock:information. I think this is especially relevant now. I've
April Mardock:heard lots of talk. You were also talking about classifying
April Mardock:or categorizing data sets. This all speaks to this question now.
April Mardock:With these AI tools, especially generative AI tools that now can
April Mardock:work at machine speed, they are uncovering all this stuff that
April Mardock:is shared. And what I'm hearing is the recommendation is you
April Mardock:really have to get your data house in order before adopting
April Mardock:these types of tools for any kind of use, because otherwise
April Mardock:it's just going to find all those corners where you're
April Mardock:hiding stuff. And if it's not labeled, if it's not
April Mardock:categorized, I know Microsoft has a tool for this called
April Mardock:Purview. Right, you can actually classify and categorize what's
April Mardock:public, what's internal, what's confidential, and these tools
April Mardock:then can actually utilize those tags and classifications to
April Mardock:properly put things or expose where there might be issues.
April Mardock:They can
April Mardock:Kevin Warenda, TLIS: maybe you could talk a little bit of any
April Mardock:experience you have in that area or why this is so important in
April Mardock:the age of AI.
April Mardock:Two things I do recommend turning off those AI
April Mardock:search tools until you've done at least some searches and clean
April Mardock:up on your own. But the second layer to that, one of the
April Mardock:districts I work with did tag documents using the Microsoft
April Mardock:tools that were sensitive, and then use the DLP controls to
April Mardock:block the sharing and the emailing of those sensitive
April Mardock:documents out, and so that can prevent theft and overexposure
April Mardock:of content that probably shouldn't be shared. I will say
April Mardock:sometimes staff have I would call it semi legitimate reasons.
April Mardock:They might be in working on their doctorate in education and
April Mardock:they want data. They should be asking for that data formally
April Mardock:instead of just taking it. It's interesting to see who flags
April Mardock:that data loss prevention tool, but tagging that content is
April Mardock:getting easier and easier. You can give it examples of the kind
April Mardock:of content, especially if it's a form type content like a
April Mardock:transcript, a discipline form, all of those kinds of things.
April Mardock:You can teach the system, and it will actually automatically go
April Mardock:out and flag them, find them, and tag them for you, and then
April Mardock:you can treat them as appropriate. So yes, those tools
April Mardock:are getting better. I will say, two years ago, it was a real
April Mardock:pain to try to do this, and it's getting cleaner and cleaner as
April Mardock:you move along. I don't have enough experience in the Google
April Mardock:environment to know how easy that is to do in that space. I
April Mardock:suspect the tools are coming if they aren't already there to be
April Mardock:able to automatically flag content and prevent it from
April Mardock:being overshared, prevent it from being misused in that way.
Bill Stites:I'll go back to that piece with the Scuba Tools.
Bill Stites:I just literally got off a call yesterday because we went
Bill Stites:through a full audit of our Google domain
April Mardock:with Scuba.
Bill Stites:Well, Scuba Tools is what I'm going to use
Bill Stites:actually to validate what we did in our audit, we used another
Bill Stites:vendor that we've used, and this is now our third audit with them
Bill Stites:to go through all of that. And it really highlighted a bunch of
Bill Stites:the things that you mentioned with regard to the oversharing,
Bill Stites:the DLP controls. You know what you need to turn on and off, how
Bill Stites:you need to go through that type of audit, and I found that
Bill Stites:that's incredibly helpful for me and for my team because, as you
Bill Stites:mentioned, you're not as familiar with the Google
Bill Stites:environment, so you couldn't comment. Well, we don't live and
Bill Stites:breathe in these areas every day, and your role as a CISO is
Bill Stites:one that we hear coming up in schools whenever they talk about
Bill Stites:this vetting, they say, "Well, talk to your risk committee,
Bill Stites:talk to your CISO and your risk person. And I'm like, "That's
Bill Stites:just another hat that we put on over the course of our day, and
Bill Stites:we're trying to make the best guess in terms of." How we can
Bill Stites:go about doing that, and one of the things I'll credit Hiram for
Bill Stites:getting me started on is using AI to actually help with some of
Bill Stites:that work, whether that be in the evaluation or vetting of
Bill Stites:services, whether that be in some of the search work that
Bill Stites:you're talking about there. What would you recommend to people
Bill Stites:listening to have as their common tool belt of either
Bill Stites:partners or tools or things to consider as they put on that
Bill Stites:CISO hat that they are interchanging with their
Bill Stites:database administrator hat, their mobile device management
Bill Stites:hat? You know all those things. What can we put in our tool belt
Bill Stites:to help us with this work that we're doing to level it up a
Bill Stites:little bit for us?
April Mardock:So I'd go at a couple different angles. One
April Mardock:would be working with their local regional support agency if
April Mardock:they have one, like an ESD educational service district or
April Mardock:equivalent. If they have a state department of education that has
April Mardock:a cybersecurity focus. Sometimes some states have cybersecurity
April Mardock:resources at the state level. For the independents and the
April Mardock:smaller districts that don't have that support structure, you
April Mardock:can look to something like K 12 six that's providing guidance
April Mardock:around vendor management. I'm the chair of the technical
April Mardock:working group, and one of our next tasks after the Essentials
April Mardock:reboot will be that scuba report is amazing, but it's like 20
April Mardock:pages long and there's hundreds of entries in it that are red,
April Mardock:green, and yellow. And I find that a lot of the smaller
April Mardock:district folks are just overwhelmed by that report and
April Mardock:they don't know where to go next. And so K 12 six is going
April Mardock:to work on sort of a top 10 Microsoft tenant and top 10
April Mardock:Google tenant things to look for that are kind of urgent that we
April Mardock:need to make sure all districts are taken care of. So there's
April Mardock:sort of a crawl, walk, run approach to that, where you can
April Mardock:basically start with the simple stuff and work your way up.
April Mardock:Obviously, there are also vendors available that can help
April Mardock:even the smaller organizations that can do the number crunching
April Mardock:and give you something actionable. I don't have
April Mardock:specific vendor recommendations available, but I can say that
April Mardock:there are a number of them out there that are targeted to
April Mardock:helping small K 12 s do what they need to do. They realize
April Mardock:that K 12 s not just don't have a CSO. It might be the science
April Mardock:teacher who's doubling as the IT admin. It's a pretty constrained
April Mardock:environment, and they don't have the time or the resources to do
April Mardock:all the things a big district can do, even though they're
April Mardock:asked to. And so, how do they offload that? There are some
April Mardock:virtual CISO stuff out there as well. I will say, Security
April Mardock:Studio has a virtual CISO class for folks who want to bump up
April Mardock:their skill sets, and there's also folks who specialize in
April Mardock:like nonprofit support CISOs. So they're not looking to make a
April Mardock:dime on you; they're looking to help because they're in it for
April Mardock:the social benefit and the social good reasons, rather than
April Mardock:just you're another customer that can pad the dollars. That's
April Mardock:something I like to see as folks that are in it to try to make a
April Mardock:difference and provide resources at cost or just over cost that
April Mardock:help with both the assessment and the training and the support
April Mardock:to help folks get where they need to go.
April Mardock:Kevin Warenda, TLIS: Jeff, what I find so impressive is that the
April Mardock:scope of what you are responsible for supporting now.
April Mardock:It is very large, 750,000 people. All these districts, but
April Mardock:you really do maintain a focus on what makes that up is a lot
April Mardock:of small schools in some cases too, and that those don't always
April Mardock:have the resources. So I really appreciate that approach and
April Mardock:that focus that you have. I think you've even developed some
April Mardock:of your own tools to contribute too, right? Like I think you
April Mardock:have a AI chat bot that helps with tabletop exercises. Can you
April Mardock:talk maybe a little bit about what you're building yourself as
April Mardock:you're seeing the needs and the need for things that are free?
April Mardock:So I'm a gamer, and I came from a DND Dungeons
April Mardock:and Dragons kind of background, and I also am an emergency
April Mardock:operations center volunteer. I'm actually OxCom certified in ham.
April Mardock:I'm a ham extra, so I spent a fair amount of time in emergency
April Mardock:response work and getting like FEMA certified for all the ICS
April Mardock:stuff. And so what it means is I have a really strong background
April Mardock:in both gaming and in emergency response, and I combined that
April Mardock:with cybersecurity, and I created essentially a
April Mardock:facilitated game. It's more of an interactive cyber attack
April Mardock:story that you can interact with as a school district, or really
April Mardock:as anyone. It's a Gemini gem that will actually ask you some
April Mardock:questions. So it'll start out by saying, "What kind of org are
April Mardock:you? How big are you? Do you have an incident response plan?
April Mardock:Was it tested? When was the last time you tried restoring your
April Mardock:backups? All of those kinds of questions, right? There's like
April Mardock:six questions that ask for setup, and then it drops you
April Mardock:into a scenario where you've been attacked, and as you
April Mardock:respond, it will then respond in kind and provide. Options. It
April Mardock:rolls dice on success or failure. It'll give you bonuses
April Mardock:if you have a good approach, and it will give you a summary of
April Mardock:your performance at the end. And so, it's something that I can do
April Mardock:in person, and I've done it in person. I did it at the K 12 six
April Mardock:conference for somebody from I think I had about 30 states
April Mardock:represented at that session, and I did an interactive session
April Mardock:with the whole room pretending to be supporting one district,
April Mardock:and they would make decisions. and It goes through six injects,
April Mardock:and then at the end, it will give you a summary report. And
April Mardock:what's neat about that is it's adaptive; it never plays the
April Mardock:same way twice. It is intended to be a bit more strategic, so
April Mardock:it's going to ask questions about your communications and
April Mardock:how you would make a legal decision, and how transparent
April Mardock:you want to be as a district about the attack, and maybe some
April Mardock:of the extortion methods that the attackers may be using. Like
April Mardock:sometimes they'll call parents, right, and tell the parents
April Mardock:about what they've stolen. And it's fairly realistic. I will
warn you:you'll have a little bit of PTSD if you've been
warn you:through an attack, but I think it's a great learning
warn you:opportunity and it's free. It's on my LinkedIn. I'll reshare it,
warn you:and I think you have it in the links that you can provide for
warn you:the podcast. It's useful for any size organization, but I built
warn you:it for the little ones that really don't have anyone to do
warn you:this for them, and they can't afford a consultant to come in
warn you:and do it for them. You can also, if you want to stack the
warn you:deck a little, because IT directors, as a whole, myself
warn you:included, like to know what we're getting into before we
warn you:walk into an executive session. You can run through the scenario
warn you:once, figure out what all the injects are, get it to where you
warn you:like it, and then tell it to replay the same game. And so the
warn you:variability is less at that point, and you kind of know what
warn you:you're going to get into. So if you want to run that session
warn you:with your executive cabinet, you can. You can also ask it to be
warn you:more technical. You can adapt it on the fly and use it with your
warn you:IT teams. The other tool that I set up with permissions from our
warn you:friends at Black Hills Security is they have a backdoors and
warn you:breaches game that is great for IT teams to practice their
warn you:here's what I'm being presented with and here are the tools I
warn you:can do cybersecurity response with.
warn you:I turned it into a game where I set up a storyline where I walk
warn you:through what the attackers are doing over a period of time, and
warn you:then I line that up with the backdoors and breaches game,
warn you:where you have basically how does the attacker get in, how
warn you:does the attacker pivot and move to other machines, how do they
warn you:establish persistence, and how do they do exfiltration, how do
warn you:they steal stuff? There's an online version that is free that
warn you:you can play with your teams, and it's a great way to get the
warn you:IT teams practicing without having to deal with a real
warn you:event. So I kind of have both approaches. The Gemini Gem is a
warn you:little bit more strategic in its approach, and then if you do the
warn you:back doors and breaches thing, it's more tactical.
Hiram Cuevas:So April, in this entire conversation, you're kind
Hiram Cuevas:of preaching to the choir in terms of what we need to do,
Hiram Cuevas:let's say your audience is for CFOs and heads of school in
Hiram Cuevas:independent schools. Explain to them the challenges of the
Hiram Cuevas:staffing model that you currently see in independent
Hiram Cuevas:schools when it comes to cyber.
April Mardock:So most schools are what under 2500 kids. It's
April Mardock:like 75% or more. Those school districts and independent
April Mardock:schools really don't have the ability to tag somebody to be
April Mardock:cybersecurity full time. In fact, many of them don't even
April Mardock:have like a network tech that's formally trained in
April Mardock:cybersecurity, and so the risk is rarely elevated to the
April Mardock:boardroom. It doesn't make it into executive session, except
April Mardock:when maybe they go to renew an insurance policy if they have
April Mardock:one. And unfortunately, it doesn't get raised to the level
April Mardock:of risk that I think it represents to small districts
April Mardock:and independent schools. You are potentially at risk of not just
April Mardock:going offline, but potentially going under. There's a
April Mardock:significant percentage of districts and small businesses,
April Mardock:especially that literally stop operating after this happens. I
April Mardock:can give a case in point. I know of a you know the 403 Bs. It's a
April Mardock:retirement savings for educators. So one of the 400 3b
April Mardock:operators that was used in my region got ransomed. All the
April Mardock:systems were shut down. They didn't have adequate backups,
April Mardock:and they went under and didn't come back. It happens when a
April Mardock:ransom event happens. The business may cease to function.
April Mardock:You lose trust. You lose reputation with your community,
April Mardock:and potentially you lose your ability to function. You can't
April Mardock:do assessments. You lose your bus routing. I mean, think of
April Mardock:all the things that could go sideways if your systems were
April Mardock:all offline. And it's worth having that business continuity
April Mardock:conversation with. Anyway, because there's other reasons
April Mardock:stuff could go offline. It could be an extended power outage, but
April Mardock:you need to help them understand the consequences of systems
April Mardock:going offline in terms of availability, and then the
April Mardock:consequences in terms of lost trust and lack of enrollment as
April Mardock:a result, and the other pieces of that where maybe they can't
April Mardock:get it back. What if they can't get their bus routes back? What
April Mardock:if they can't get the payroll working? Payroll goes offline.
April Mardock:They can't pay folks. There's just so many high risk things
April Mardock:that come about as a result of not having eyes on this ball
April Mardock:that they either need to contract for that support and
April Mardock:make it a regular part of their process, or they need to train
April Mardock:somebody up, but they really do need to spend some amount of
April Mardock:resources on risk managing this. Otherwise, if they choose to
April Mardock:ignore it, unfortunately, you guys I think introd with it, or
April Mardock:I saw it recently. Maybe it was actually a K 12 six thing. It's
April Mardock:like one out of five has seen a cyber incident, so we're next.
April Mardock:It's another one of those. It's not if it's when, and so if they
April Mardock:don't pay attention to this, the risk just gets amplified. One
Bill Stites:of the things that I want to take this out of the
Bill Stites:boardroom and out of like the sea level, and I want to bring
Bill Stites:it down to how do you have these conversations with your staff,
Bill Stites:because we'll talk a lot about the COVID hangover, which was
Bill Stites:the wild west of apps and tools and things that everyone were
Bill Stites:signing up for. How do you have this conversation with maybe
Bill Stites:just below sea level, or when you get into the operational
Bill Stites:aspects of school, and then when you get into the classroom? How
Bill Stites:do you make it clear to them that I think, Kevin, you said
Bill Stites:this earlier. We're not saying no to simply say no. We're
Bill Stites:saying no for X, Y, and Z reasons. How do you suggest
Bill Stites:having those dialogs, those conversations with those groups?
April Mardock:That's sometimes a harder conversation because
April Mardock:they're trying to teach and they're under resourced and
April Mardock:scrambling to make do with the resources they have as well, but
April Mardock:part of this is they now know. For instance, MFA. MFA was a big
April Mardock:problem for a lot of schools, and MFA. There was a lot of
April Mardock:pushback of I don't want to get interrupted in the classroom. I
April Mardock:have little enough time to train my kids as it is. I don't want
April Mardock:to do it, but they realize everything that's important,
April Mardock:like their bank stuff, requires MFA, and then you pull it down
April Mardock:to brass tacks. Well, if you don't MFA, then anyone can log
April Mardock:in with your account and change where your paycheck gets
April Mardock:deposited. Right, employee self-service, and so all of a
April Mardock:sudden you make it relevant. It's a what's in it for me
April Mardock:approach. So then they realize, oh, if I don't have MFA, then my
April Mardock:paycheck could get redirected, and it has happened. I know of
April Mardock:districts where paychecks get redirected because they didn't
April Mardock:do MFA, and people have a tendency to reuse the same
April Mardock:password in multiple places, so it can get stolen from lots of
April Mardock:places. The example I used was it doesn't even require a
April Mardock:mistake on your part. Evite got broken into, and when Evite got
April Mardock:broken into, the bad guys stole the passwords in clear text. Do
April Mardock:you know how many district folks use their same username and
April Mardock:password from the district on the Evite site? Now the bad guy
April Mardock:knows your username and your password. If there's no MFA,
April Mardock:then they can use that username and password on every system
April Mardock:you've used that same password for, and so that means they can
April Mardock:redirect your paycheck. They can log in and steal your student's
April Mardock:data. They can log in and do everything you can do, and so
April Mardock:then they start to realize, oh yeah, maybe I should be thinking
April Mardock:about that differently. Applications are similar risks.
April Mardock:You can show them that the consequence of that loss is
April Mardock:significant enough to impede their ability to teach. It's a
April Mardock:cause and effect thing. It's a what's in it for me thing.
April Mardock:Kevin Warenda, TLIS: It seems like the theme of this podcast
April Mardock:today has been it's not rocket science, right? You're talking
April Mardock:about basic hygiene. You're talking about common sense
April Mardock:approaches. You're talking about things that don't require a lot
April Mardock:of technical expertise to pull off, and yet we all still need
April Mardock:to hear it again and again to internalize that and to put
April Mardock:these things into practice and to check these doors. April, one
April Mardock:of the things that you were talking about was the MFA piece.
April Mardock:One of the questions that I had that often comes up. I mentioned
April Mardock:the audit that we had done, and it came up in terms of part
Bill Stites:of that audit. I've read a lot that says frequent
Bill Stites:password changing is often more harmful than having a strong
Bill Stites:password that meets a certain character length has certain
Bill Stites:things in it, and then on top of that, having MFA is MFA and a
Bill Stites:strong password enough, or is there more needed? That
Bill Stites:frequency of password change. Is really what I'm curious about
Bill Stites:because I think you need to change your password every 30
Bill Stites:days, or you need to change your password every X number of days
Bill Stites:has diminished, and I want to know if that's true or if that's
Bill Stites:a falsehood that's just getting perpetuated out there, and that
Bill Stites:you should be changing password and have that MFA piece done.
April Mardock:So as much as I'd like to wave a magic wand and
April Mardock:make all the software that districts use single sign-on,
April Mardock:where there's a password that's managed in that way, that's not
April Mardock:happening. So if you think about it, 90% of the applications you
April Mardock:use are single sign-on, and that password rotation-let's say it's
April Mardock:once a year-that password rotation is fine. And in fact,
April Mardock:I'd even downgrade the MFA protected passwords and make
April Mardock:them simpler, make them fairly straightforward. And length
April Mardock:matters more than complexity, in my opinion. By the way, you
April Mardock:know, if it's a 14 character password, but you don't do the
April Mardock:crazy symbols, because all they're going to do is put $1
April Mardock:sign or a one at the end anyway. You know it. But here's the
April Mardock:problem I'm finding, and this happened with School Dude, so
April Mardock:School Dude got compromised, and again, clear text passwords were
April Mardock:stolen. And it was not at the time single sign-on. District
April Mardock:employees have a tendency to use, and school employees the
April Mardock:same username and password for all work things, and they'll
April Mardock:change it, and they change it everywhere that they use the
April Mardock:password. So I use J Smith, and I use Totem 223, and that gets
April Mardock:used everywhere. And the single sign-on systems, when I change
April Mardock:my password, let's say there's a compromise, you force folks to
April Mardock:change their password. It gets changed, but it doesn't get
April Mardock:changed in those things that are not managed by the single
April Mardock:sign-on. And as IT directors, we know some of the systems we have
April Mardock:aren't quite the single sign-on yet, whatever it is, HVAC, the
April Mardock:Access Badging system. I don't know what it is, but often there
April Mardock:are systems that are not single sign-on yet, and so I believe
April Mardock:you need to rotate passwords at least once a year, regardless of
April Mardock:MFA or not, because those passwords are reused elsewhere.
April Mardock:That's my argument. So I would suggest once a year, not every
April Mardock:30 days, but annually I think is important because single sign-on
April Mardock:and MFA is not in all the places.
April Mardock:Kevin Warenda, TLIS: Bill, it's worth noticing that NIST did
April Mardock:finally update their guidance on this topic. For a while, they
April Mardock:were stuck on the constant rotation, but finally realized
April Mardock:that you can rotate less often when there are additional
April Mardock:securing factors in place, and only change when there's
April Mardock:indicators of compromise or on a longer schedule. And that was
April Mardock:based on field work they did to say, yeah, what we're finding is
April Mardock:that kind of as April said, humans just put one extra
April Mardock:character at the end if there's no complexity requirement.
April Mardock:They're not making better passwords. They're more likely
April Mardock:to then write it down on a sticky note. So even NIST did
April Mardock:finally adjust their recommendations. But I think
April Mardock:April has a good balance there of still do it, especially if
April Mardock:there's an indicator of compromise. But I think what
April Mardock:April's pointing out is it's not that system that's actually the
April Mardock:issue. It's the reuse of that in other systems. If you're not
April Mardock:encouraging the use of a password manager, where you're
April Mardock:getting a unique password for every single different service,
April Mardock:which would obviously be the ideal, but not everyone's going
April Mardock:to do that. So I think that's good advice.
April Mardock:And I disagree with this. I think that you do
April Mardock:need to rotate at least once a year, and not just when it's
April Mardock:been compromised because of that fact that MFA really isn't in
April Mardock:all the places.
April Mardock:Kevin Warenda, TLIS: That's solid recommendation from the
April Mardock:field, from someone who's seen and talked to many districts
April Mardock:being compromised. That we'll take your word for that one for
April Mardock:sure. Are there any topics, programs, things that you wanted
April Mardock:the opportunity to talk about that we didn't ask about?
April Mardock:I would just say also look for cooperatives like
April Mardock:Waspsy in your region that can get you software and services,
April Mardock:whether it's cybersecurity services or some of the amazing
April Mardock:software tools out there for incident response or EDRs or
April Mardock:even managed service providers. I worry about the 24 by seven
April Mardock:problem. Most small orgs can't cover night, weekend, and
April Mardock:holidays when attacks happen, and the bad guys are even timing
April Mardock:nights, weekends, and holidays. So figure out how you can do
April Mardock:after hours response. And I strongly suggest folks think
April Mardock:about allowing their tools to automatically isolate either a
April Mardock:user or a machine. If it flags as compromised, shoot first, ask
April Mardock:questions later, check it in the morning. But you really need to
April Mardock:be thinking about isolating proactively, especially off
April Mardock:hours. But let the system isolate the user or the system
April Mardock:and follow up, rather than follow up, verify, and then
April Mardock:isolate. Because the bad guys are moving faster; they are AI
April Mardock:assisted, and if you leave that thing sitting for a whole spring
April Mardock:break, you may be in real trouble. So that's one of the
April Mardock:other things I want folks to think about: is being proactive
April Mardock:in those and look to your regional service agency, your
April Mardock:WISIPs of the world, for the tooling for that because they
April Mardock:often get amazing prices for that kind of stuff.
April Mardock:Kevin Warenda, TLIS: And it's a lot of great partners and
April Mardock:vendors. Work with the Atlas community, or the Atlas
April Mardock:community itself too, has a lot of that. So certainly, we are a
April Mardock:resource for independent schools to connect with those types of
April Mardock:vendors as well.
Bill Stites:I want to thank April. As I mentioned before, we
Bill Stites:came on every day. I've got emails, whether it's from K 12
Bill Stites:six or CISO or our New Jersey cybersecurity cell, and it can
Bill Stites:be drinking like a fire hose, and having her on to be able to
Bill Stites:talk about some of these really practical pieces that we focus
Bill Stites:in on really helps.
Hiram Cuevas:I'm really glad I made it to this episode because
Hiram Cuevas:the beach is calling my name, but this was definitely a
Hiram Cuevas:conversation that needed to be had, and I was grateful for the
Hiram Cuevas:opportunity to speak to you, April.
Hiram Cuevas:Kevin Warenda, TLIS: And I'll echo what Bill and Hiram said,
Hiram Cuevas:"Thank you, April, for joining us today. I think we'll maybe
Hiram Cuevas:wrap with a softball question: Is there a book or a podcast or
Hiram Cuevas:a white paper that you've read this summer or listened to that
Hiram Cuevas:you think is worth a share for our community?
April Mardock:I will have to say on the entertainment side of
April Mardock:things, because of the gaming influence, I'm enjoying the
April Mardock:Dungeon Crawler Carl series. It's giving me a perspective on
April Mardock:how to troubleshoot things in novel ways and thinking outside
April Mardock:the box. So, if you haven't already seen it, there's an
April Mardock:audio book and a regular book series that's becoming almost
April Mardock:viral, but it's worth a chance to step outside of yourself and
April Mardock:think outside the box, because some of the solutions that we're
April Mardock:asked to come up with, especially in small orgs, we
April Mardock:have to be really creative. And sometimes I need a little bit of
April Mardock:encouragement in that space.
April Mardock:Kevin Warenda, TLIS: I appreciate that, and thanks for
April Mardock:encouraging all of us, Bill Hiram. What's on your summer
April Mardock:reading list? Anything worth sharing? To be honest with you,
April Mardock:I'm just
Bill Stites:getting back off of a two week break where I
Bill Stites:did
Bill Stites:absolutely nothing. I didn't even
Bill Stites:read.
Bill Stites:I just kind of like laid in the sun. Hiram, hopefully you're
Bill Stites:going to get a bunch of that. My reading list consists of about
Bill Stites:200 emails that have piled up over the course of the last two
Bill Stites:weeks of being out.
Hiram Cuevas:I'm similar boat there, except I'm reading terms
Hiram Cuevas:of service agreements with different vendors.
Hiram Cuevas:Kevin Warenda, TLIS: All right, quite a lively bunch here.
Hiram Cuevas:April, thanks so much for joining us today and sharing
Hiram Cuevas:your expertise. If anyone wants to connect with you, what's the
Hiram Cuevas:best way to find you online or find what you're writing?
April Mardock:Catch me in LinkedIn and connect me there.
April Mardock:And then also anybody in the Washington areas, welcome to
April Mardock:ping me at cybersecurity at wasipsy. It's w sipc.org if they
April Mardock:want assistance in my state.
April Mardock:Kevin Warenda, TLIS: All right, thanks everyone for joining
April Mardock:another episode of Talking Technology with Atlas. See you
April Mardock:next time.
Peter Frank:This has been Talk Technology with Atlas, produced
Peter Frank:by the Association of Technology Leaders in independent schools.
Peter Frank:For more information about Atlas and Atlas membership, please
Peter Frank:visit theatlas.org. If you enjoyed this discussion, please
Peter Frank:subscribe, leave a review, and share this podcast with your
Peter Frank:colleagues in the independent school community. Thank you for
Peter Frank:listening.