Strengthening K-12 Cybersecurity and Vendor Risk Management with April Mardock
Presented by:
April Mardock, Chief Information Security Officer at WASIPC, joins the podcast to analyze the primary entry points targeted in K-12 ransomware incidents. The discussion offers actionable guidance on multi-factor authentication, vendor risk management, data retention policies, and using gamified tabletop exercises to prepare school leadership for cyber incidents.
- April’s LinkedIn profile and email address
- Cybersecurity tabletop simulation game (Gemini Gem), step into the hot seat of a live cyber attack and lead your team to safety
- I Asked 24 Ransomed School Districts How the Attackers Got In - There Were Only Three Answers, LinkedIn article that April authored
- K-12 SIX (K-12 Security Information Sharing and Analysis Center), threat intelligence community providing free K-12 cybersecurity guidance, checklist guides, and standards
- WISPC, public, non-profit agency in Washington state that provides technology solutions, data management, and cooperative purchasing services to K-12 schools
- Cyberforce|Q service from WISPC, building and implementing cybersecurity programs for organizations of all sizes
- Bluum service from WISPC, helping educators leverage technology to create a more effective and engaging student experience
- Cybersecurity & Infrastructure Security Agency (CISA), from the U.S. Department of Homeland Security; as the national coordinator for critical infrastructure security and resilience, CISA works with partners at every level to identify and manage risk to the cyber and physical infrastructure that Americans rely on every hour of every day. CISA works with partners to defend against today’s threats and collaborate to build a more secure and resilient infrastructure for the future.
- Secure Cloud Business Application (SCuBA), CISA project providing tailored cloud solutions guidance and secure configuration baselines (SCBs) for Microsoft 365 and Google Workspace applications. SCuBA’s guidance aims to protect information that organizations create, access, share, or store in cloud environments.
- Backdoors and Breaches, incident response card game
Transcript
Peter Frank:
Welcome to Talk Technology with Atlas, the show
Peter Frank:
that plugs you into the important topics and trends for
Peter Frank:
technology leaders, all through a unique independent school
Peter Frank:
lens. We'll hear stories from technology directors and other
Peter Frank:
special guests from the independent school community,
Peter Frank:
and provide you with focused learning and deep dive topics.
Peter Frank:
Kevin Warenda, TLIS: Hello, everyone, and welcome to Talking
Peter Frank:
Technology with Atlas. I'm Kevin Warendo, Director of Information
Peter Frank:
Technology Services at the Hofstra School in Lakeville,
Peter Frank:
Connecticut,
Bill Stites:
and I'm Bill Stites, the Director of
Bill Stites:
Technology at Montclair Kimberly Academy in Montclair, New
Bill Stites:
Jersey,
Hiram Cuevas:
and I'm Hiram Cuevas, the Director of
Hiram Cuevas:
Information Systems and Academic Technology at St. Christopher
Hiram Cuevas:
School in Richmond, Virginia.
Hiram Cuevas:
Kevin Warenda, TLIS: All right, gentlemen, I made it. The
Hiram Cuevas:
training wheels are off. Peter finally let me open the show by
Hiram Cuevas:
myself. Well, it's good to be rid of Peter. I think that's
Hiram Cuevas:
what we can say about that. Anything that pushes Peter to
Hiram Cuevas:
the side, I am all for.
Hiram Cuevas:
I'm speechless. I'm actually a big fan of Peter,
Hiram Cuevas:
so you know.
Bill Stites:
Oh, I'm Peter's biggest fan, and he knows it. I
Bill Stites:
just like giving him grief. Hiram and I, you and I, just
Bill Stites:
spent so much time with Peter. I don't even know where to begin.
Bill Stites:
Kevin Warenda, TLIS: Indeed, we did. Well, I'm preparing for a
Bill Stites:
totally new experience myself next week. At the end of the
Bill Stites:
week, my family, including our dog, will be piling into an RV
Bill Stites:
or rented to travel to the Midwest. My older daughter is
Bill Stites:
going to be competing in gymnastics at the Junior
Bill Stites:
Olympics.
Bill Stites:
Oh, awesome! Good for you. We've got campgrounds
Bill Stites:
mapped out. We've got a chartered fishing trip, and then
Bill Stites:
everything else is going to be quite the adventure. So, I'm
Bill Stites:
actually curious, Bill and Hiram, you have any epic road
Bill Stites:
trip memories worth sharing? So many people may know I've seen
Bill Stites:
all 30 baseball stadiums in the United States. We've generally
Bill Stites:
flown into different areas and mapped them around, and I will
Bill Stites:
tell you as far as a road trip goes. One, I'm extremely jealous
Bill Stites:
of what you're doing. I always wanted to get a camper and do
Bill Stites:
that because my retirement goal is to live the van life. I want
Bill Stites:
to get something kind of just be able to travel around like that.
Hiram Cuevas:
Teach a chum van-that's what you want,
Bill Stites:
exactly. But but based on the travels that I had,
Bill Stites:
the one thing I would highly recommend people to do: we flew
Bill Stites:
into Seattle, we drove over to Cannon Beach, Oregon, home of
Bill Stites:
the Goonies, where that was filmed, and then we drove down
Bill Stites:
the Pacific Coast to San Francisco, and that is a road
Bill Stites:
trip that I would take time and time again, some of the most
Bill Stites:
beautiful landscape, beautiful scenery, and one of the best
Bill Stites:
drives that I had. We were amazed because when we were
Bill Stites:
inland on one side, it was like 100 degrees, and as we made our
Bill Stites:
way back to the coast and over the mountains and came back
Bill Stites:
down, we literally saw a 50 degree switch in temperature
Bill Stites:
when we went from one side to the other, so prepare for all
Bill Stites:
and enjoy yourself. But it was a great road trip.
Hiram Cuevas:
I'm very jealous as well. Grace and I we drove
Hiram Cuevas:
across the country many years ago, did Bryce Canyon, Kings
Hiram Cuevas:
Canyon, and Sequoia, and then for our honeymoon we camped for
Hiram Cuevas:
two weeks out in the Pacific Northwest in Montana. So we knew
Hiram Cuevas:
we were going to get along after two weeks camping together. I
Hiram Cuevas:
think what you'll probably love the most is when you pass
Hiram Cuevas:
Kentucky. That's when the humidity starts to drop. It
Hiram Cuevas:
really is fascinating, and the dry air of the Midwest and the
Hiram Cuevas:
further west you go is just fabulous compared to the East
Hiram Cuevas:
Coast.
Hiram Cuevas:
Kevin Warenda, TLIS: All right. Well, speaking of going places,
Hiram Cuevas:
I'm excited to see where the podcast takes us today. Our
Hiram Cuevas:
guest is a veteran K 12 cybersecurity leader with more
Hiram Cuevas:
than 20 years of experience. She's nationally recognized in K
Hiram Cuevas:
12 cybersecurity risk management and governance. Currently
Hiram Cuevas:
serving as the Chief Information Security Officer for WASIPSE,
Hiram Cuevas:
which is a Washington School District cooperative. It's my
Hiram Cuevas:
pleasure to welcome April Mardach to the show. Please tell
Hiram Cuevas:
us more about yourself and your journey that brought us here
Hiram Cuevas:
today.
April Mardock:
Sure. So I've been in K 12 a long time. I
April Mardock:
originally actually started as a var doing support for back in
April Mardock:
the day Solaris, Novell, Netware, a lot of old tools, and
April Mardock:
slowly migrated to supporting Macs, which ended up with a lot
April Mardock:
of K 12 customers. That time, I supported over 100 different
April Mardock:
companies, small, medium, and large. So I got a lot of field
April Mardock:
engineer experience, hands on, you know, setting up the whole
April Mardock:
set stuff and troubleshooting and training users and all of
April Mardock:
the things. And eventually, I ended up taking a position with
April Mardock:
a local ESD, which is like a regional area that supports
April Mardock:
school districts. So, like Washington has nine ESDs, and
April Mardock:
the ESDs are partially state funded in a tiny way, like 5% of
April Mardock:
their budget, and then the rest of their income comes from their
April Mardock:
local school districts as they provide services. And so, I
April Mardock:
provided regional services to K 12 s in my region, and since
April Mardock:
basically '99, and in fact was involved in a bunch of Y2K
April Mardock:
stuff. So I've been doing cyber for a long time. Did firewall
April Mardock:
audits and configurations. I was on the techy side of things,
April Mardock:
right? Doing an awful lot of support for soup to nuts, a
April Mardock:
district that has no techs or one IT person. Who might also be
April Mardock:
the science teacher? So you've got the small districts, the
April Mardock:
medium districts, and the large districts. And eventually, I
April Mardock:
ended up getting hired by the largest district in the state
April Mardock:
here in Washington, Seattle. Worked for Seattle 15 years ish,
April Mardock:
and then now I'm back at the state level, K 12, working for
April Mardock:
WASI as their chief information security officer. And what's
April Mardock:
cool about my job here is I am 50% internal facing, doing
April Mardock:
cybersecurity and CISO work, helping with incident planning
April Mardock:
and response, all of the normal kind of create a cybersecurity
April Mardock:
program from scratch. But I'm also doing 50% external facing,
April Mardock:
which allows me to do some of the national work with K 12 six,
April Mardock:
and to work with districts across my state in helping bring
April Mardock:
everybody to a higher degree of cybersecurity stability and
April Mardock:
include postures. So, for instance, one of the things that
April Mardock:
I think I'm about to get kicked off, I'm actually participating
April Mardock:
as a lead in the state's cyber incident response team, so I'll
April Mardock:
probably be heavily involved in K 12 support in that space, and
April Mardock:
I'm also working with the state on putting together a
April Mardock:
vulnerability management process where we will get an email and a
April Mardock:
flag when a district has essentially-I don't know-you've
April Mardock:
seen how many districts have gotten taken over by way of
April Mardock:
exposing an Exchange server or a SharePoint server or something
April Mardock:
like that that didn't get patched in a timely way, or just
April Mardock:
didn't get removed because it was end of life. Right? Those
April Mardock:
are kind of threats, and the state's going to work with me.
April Mardock:
Maybe it's looking really, really likely on allowing WIC to
April Mardock:
sort of coordinate that notification and helping
April Mardock:
districts figure out what to do to mitigate their
April Mardock:
vulnerabilities for those sort of extraordinary all hands
April Mardock:
remote takeover risk kind of things. So super excited! It's
April Mardock:
been a long journey, and I'm in a place where I can really move
April Mardock:
the needle, both at the state and the national level. With the
April Mardock:
K 12 six side, the technical working group there is a group
April Mardock:
of K 12 geeks, security geeks from across the U.S. as well as
April Mardock:
some folks that are not geeks, that help us with making sure
April Mardock:
the messaging is understandable for any district. And that group
April Mardock:
has come up with some amazing resources that are free to
April Mardock:
anybody who wants to use them. Things like the "What to Do If
April Mardock:
You're Compromised" checklist, where you can basically go
April Mardock:
through and if you get a compromised account, it reminds
April Mardock:
you of all the things to do-not just reset the password or flush
April Mardock:
the sessions, but look and see if somebody connected an
April Mardock:
application. Right? Look and see what rules might have been
April Mardock:
configured. Look to see what else may have been done, because
April Mardock:
as we all know, the attackers are getting more sophisticated.
April Mardock:
So, that's a group that also came up with a 14 question
April Mardock:
cybersecurity assessment that's really easy for small districts,
April Mardock:
independent schools to do. That gives you like your top marching
April Mardock:
orders for the top one or two things you should really focus
April Mardock:
on for the year. Doesn't take a rocket scientist. Really
April Mardock:
approachable. So that's been kind of one of my big goals: is
April Mardock:
to try to make cybersecurity approachable for everybody, all
April Mardock:
the districts, tiny or huge. Oh,
April Mardock:
Kevin Warenda, TLIS: that's such important work. I saw recently
April Mardock:
you posted an article on your LinkedIn feed. I think it was
April Mardock:
you've interviewed 24 school districts who've been victims of
April Mardock:
ransomware, and you kind of boiled that down into a really
April Mardock:
approachable lens to think about this through like the three
April Mardock:
doors that attackers come through. Maybe you could talk a
April Mardock:
little bit about your findings there and how easy it is
April Mardock:
actually to maybe think about securing those doors.
April Mardock:
Yeah, when I was with my very large district, I
April Mardock:
did not want to be next in the ransomware parade, and to do
April Mardock:
that, I started asking folks at conferences and other places.
April Mardock:
You know, after they presented about their event, you know how
April Mardock:
did bad guys get in? You know, in the very beginning, the camel
April Mardock:
got their nose under the tent. Where'd they poke their nose,
April Mardock:
right? And it turned out that it was really only three answers,
April Mardock:
and three answers that aren't rocket science. The first one
April Mardock:
tends to be when, like I mentioned earlier, there's a
April Mardock:
device or a system that's exposed to the internet and is
April Mardock:
not patched in a timely way, whether that's a server like an
April Mardock:
Exchange or SharePoint server, or it's a VPN appliance, it's a
April Mardock:
firewall management port. Please tell me you've removed all the
April Mardock:
management ports from internet. They should not be facing the
April Mardock:
internet, but that's a different discussion. But anything that's
April Mardock:
basically exposed to the internet that wasn't patched in
April Mardock:
a timely way, or is end of life and doesn't have patches
April Mardock:
anymore, right? So that's number one. It's keep those things
April Mardock:
patched really quickly. And it used to be we said 30 days. Now
April Mardock:
it's 14 days. I'd say if you can patch it within 48 hours, you're
April Mardock:
in a better place. If there's a big announcement that says
April Mardock:
people can take over your whole system through that device is
April Mardock:
probably a good idea to patch it, especially those CISA known
April Mardock:
exposed vulnerabilities are also known as CEVs. So that's door
April Mardock:
number one. Door number two is where basically remote access is
April Mardock:
possible, and it's either VPN or. Some kind of remote desktop
April Mardock:
service, but there's no MFA required, meaning you don't have
April Mardock:
to put in an authentication token. You don't get an SMS.
April Mardock:
There's nothing other than a username and a password that
April Mardock:
gives you full remote access to that district or that
April Mardock:
organization, and that includes vendors. We're really bad about
April Mardock:
letting vendors use the same account for all their texts, and
April Mardock:
we don't make them use MFA because well, there's phone
April Mardock:
issues, right? And we're terrible about enforcing our own
April Mardock:
rules when we get pushback. And what that means is that vendors
April Mardock:
have some bad habits too. They like to, for instance, reuse
April Mardock:
password across clients. And so, if a password gets compromised,
April Mardock:
whether it's a staff person's password or a vendor's password,
April Mardock:
and that username and password can be used to log into that
April Mardock:
district and have full remote access, that's a pretty big
April Mardock:
hole, right? And so that's number two. The other one that
April Mardock:
happens is phishing, which we all see phishing every day. We
April Mardock:
run into that, but phishing grows legs and takes over your
April Mardock:
organization if the user who gets the fish and responds to
April Mardock:
the fish also has local administrator rights, because
April Mardock:
what happens then is the fish lands, and the user's machine is
April Mardock:
then taken over and used to crawl across and take over the
April Mardock:
rest of the network, and sometimes the hygiene of that
April Mardock:
organization is bad enough, where they've also used the same
April Mardock:
administrator configuration password on all the devices. All
April Mardock:
the staff devices get a password. All the student
April Mardock:
machines might get a different password. But the problem is
April Mardock:
when that password then gets compromised, it can be used to
April Mardock:
take over every machine very quickly.
Bill Stites:
You mentioned working with Solaris and with
Bill Stites:
Novell, and I think at least Hiram and I-I'll leave Kevin out
Bill Stites:
of this-but Hiram and I are the old gray beards in the room.
Bill Stites:
We've been at this for a while. When you said that Hiram and I
Bill Stites:
are both heard Novell, it was like ding ding, remembering from
Bill Stites:
years past. And I just remember walking into our network room,
Bill Stites:
our network closets and just the number of tools that we had that
Bill Stites:
were on prem to deal with all of this patching that you're
Bill Stites:
talking about, you know, and everything that was going on
Bill Stites:
with that, the number of servers you were maintaining, so on and
Bill Stites:
so forth. I want to get your thoughts on how that model, how
Bill Stites:
that mode has changed with so much moving to the cloud now,
Bill Stites:
and so much of what's out there going into the cloud, and what
Bill Stites:
your thoughts are there, and what that means for, I'll say
Bill Stites:
the due diligence that we need to do on our parts to make sure
Bill Stites:
that our cloud services are configured properly, or our
Bill Stites:
cloud providers are doing their due diligence, and I want to
Bill Stites:
thank both K 12 six and CISA because I saw this on a K 12 six
Bill Stites:
email just like I think yesterday or the day before that
Bill Stites:
there's a new set of tools that were put out called Scuba. That
Bill Stites:
is for those that don't know the acronyms because it's like
Bill Stites:
acronym soup when we talk about this stuff. That is a secure
Bill Stites:
cloud-based application. It's a set of tools and recommendations
Bill Stites:
that they put out to help you evaluate these cloud services.
Bill Stites:
So, with that said, what are your thoughts in everything that
Bill Stites:
I mentioned there?
April Mardock:
Okay, so I'll start with, although you've
April Mardock:
probably pushed 75 or even 80% of your stuff to the cloud,
April Mardock:
don't forget you still have on-prem entry points like the
April Mardock:
firewall and like the firewall management ports. Make sure you
April Mardock:
stay on top of keeping those patched. We don't think of them
April Mardock:
as servers, right? We don't think of them as something that
April Mardock:
needs to be patched, but they do. So that's stage one. Stage
April Mardock:
two, vendors make mistakes too, and sometimes the vendor
April Mardock:
defaults are terrible. And a case in point on this would be
April Mardock:
if you guys saw what happened with Clark County Schools, one
April Mardock:
of the attacks that they dealt with was somebody taking over
April Mardock:
the student passwords. And at the time, the student passwords
April Mardock:
were based on birth dates. And I will say a lot of school
April Mardock:
districts use birth dates or something like it to configure
April Mardock:
those initial passwords, and they don't always force password
April Mardock:
changes when they do it. Here's the problem that makes a student
April Mardock:
account easy to log into, easy to guess because you get the
April Mardock:
user account, you get the password, which is their
April Mardock:
birthdate, and you log in. Now here's where it gets ugly.
April Mardock:
Everybody should be doing this who's a school district IT
April Mardock:
manager, which is you need to log in as a student account and
April Mardock:
look around and search for things like SPED or IEP or
April Mardock:
discipline or all of the sensitive words right from a
April Mardock:
student account and see what's been overshared, because what
April Mardock:
happens with Clark County, as I understand it, is there were
April Mardock:
Google work groups that a student could add themselves, or
April Mardock:
a criminal using a student's account could add themselves to,
April Mardock:
but either way, it's a problem. If a student can do this, it's
April Mardock:
also problematic, and get access to all the content in that work
April Mardock:
group. What that means is, if you can break in with a student
April Mardock:
account and can search for all of that sensitive. Content you
April Mardock:
can steal that sensitive content, and the default
April Mardock:
configuration was problematic. I'll use a Microsoft example.
April Mardock:
Microsoft made it so that when you shared a file in the earlier
April Mardock:
days, it would share with everyone, whether they were
April Mardock:
on-prem or in the cloud. And so you created this link. If that
April Mardock:
link got out, it was visible. But here's where it gets ugly.
April Mardock:
The AI search engines can now expose files that were shared
April Mardock:
with everyone, internet access that you didn't intend to ever
April Mardock:
share. Now, just because the person has privilege, because
April Mardock:
you said allow it to either everyone or allow it to everyone
April Mardock:
in the organization. Okay, think of this from a teacher point of
April Mardock:
view. I want to share a file with the kids in my class, and
April Mardock:
I'm going to share this file. And I'm not going to name all 30
April Mardock:
kids that I want to send this file to. I'm going to share it
April Mardock:
with everyone in the org. Right? That makes sense for a teacher.
April Mardock:
Same thing happens for say somebody in IT. They want to
April Mardock:
share something out to all the staff. They'll share it with
April Mardock:
everyone in the org. Well, here's something that often
April Mardock:
happens in K-12: the students and the staff are in the same
April Mardock:
organization. When you share a file with everyone in the org,
April Mardock:
it gets shared to everyone, staff and students. Sometimes
April Mardock:
those files are sensitive. You don't intend it to get in the
April Mardock:
wrong hands, but if you've shared it with wide open
April Mardock:
privileges, now anyone with an account, and that means
April Mardock:
criminals with accounts, can get to that file. So those are
April Mardock:
mistakes kind of made in the early configuration where the
April Mardock:
default sharing was too open, or the default for that group
April Mardock:
membership is too open. It allows people to inject
April Mardock:
themselves. All of those kinds of defaults in your tenant, your
April Mardock:
Microsoft or your Google tenant can bite you because a it's
April Mardock:
easier to steal accounts because the passwords are sometimes
April Mardock:
either already know or easy to guess, and b those accounts if
April Mardock:
you start searching for sensitive content will reveal
April Mardock:
things you'd really rather they not reveal. So that's part one.
April Mardock:
Part two is our vendors and the vendor stuff? Couple things
April Mardock:
there. So make sure that when you're contracting with vendors,
April Mardock:
if you give PII to vendors, this is one of the things I worked on
April Mardock:
with K 12 six in the technical working group.
April Mardock:
We actually created a document that you guys should have access
April Mardock:
to. That is what I call lightweight vendor management,
April Mardock:
and there's low risk vendors, medium risk vendors, and high
April Mardock:
risk vendors, and we consider the high risk vendors vendors
April Mardock:
that either have really sensitive student data, or are
April Mardock:
operationally critical. If this thing goes down, we have trouble
April Mardock:
teaching, or we have trouble keeping the buildings open, or
April Mardock:
we have trouble bussing kids-it's something that will
April Mardock:
really create a showstopper kind of situation. So those are the
April Mardock:
high-risk vendors, and for the operationally high-risk vendors,
April Mardock:
I ask questions like, "What kind of redundancy do you have if
April Mardock:
there's a Microsoft outage in this region? Can you fail over
April Mardock:
somewhere else? Or Amazon outage in this region? Can you fail
April Mardock:
over somewhere else? Here's the sneaky part: Amazon and
April Mardock:
Microsoft will charge you for that extra resiliency. So some
April Mardock:
companies don't pay it. If they're an operationally
April Mardock:
critical vendor, you want to start asking those questions.
Hiram Cuevas:
We actually felt some of that when the incident
Hiram Cuevas:
in the Strait of Hormuz occurred. About 22% of all data
Hiram Cuevas:
traffic apparently goes through that area, and a lot of folks
Hiram Cuevas:
were complaining at my school and a bunch of other schools.
Hiram Cuevas:
You know what's going on with our SaaS applications, and I've
Hiram Cuevas:
reminded them, hey, there's a lot going on, a lot of rerouting
Hiram Cuevas:
of traffic, and sometimes that kind of stuff is out of our
Hiram Cuevas:
hands, and we can't even control that because it's such a main
Hiram Cuevas:
trunk of data.
April Mardock:
Yeah, for sure. And outages, if it's
April Mardock:
operationally critical to your org, you want to make sure that
April Mardock:
that software that you are subscribing to has some
April Mardock:
resilience built in, so that you have less outages as a result. I
April Mardock:
have seen cases where, for instance, the West Side Amazon
April Mardock:
West drops, or maybe some of their DNS functionality drops,
April Mardock:
and all kinds of things break. Right. So, what you want is to
April Mardock:
make sure that the vendor that you're putting your money in for
April Mardock:
operationally critical stuff has resiliencies built in. Whether
April Mardock:
it's incident response stuff, they have disaster recovery and
April Mardock:
can come back. They have resiliency in their services.
April Mardock:
You just want to make sure that's covered. And then on the
April Mardock:
flip side of that, where it's sensitive data, those are
April Mardock:
different questions, right? Number one, I want to make sure
April Mardock:
that they can delete my data when I'm done, and that they
April Mardock:
don't force me to send them a certified letter to say you must
April Mardock:
delete my data because vendors see data as a long-term money
April Mardock:
source, and they really don't like deleting it. They don't
April Mardock:
like getting rid of it. They don't like purging it. They like
April Mardock:
to feed it to their AI models and learn from it. And I really
April Mardock:
want my data back when I'm done. The other thing that I'm
April Mardock:
thinking about with vendors is: Do you really have to give them
April Mardock:
all the data they're asking for? As an example. I stopped giving
April Mardock:
vendors birth date data. Why? Most of the time, they can get
April Mardock:
by with the graduation year. They don't need a birth date.
April Mardock:
They just need basically a rough idea of what range the kid is
April Mardock:
in. It's not always the case, right? I can't do that with
April Mardock:
every vendor. There are a few cases where that's an exception.
April Mardock:
But in general, why are we giving, for instance, vendors
April Mardock:
parent home address information just because they ask for it? If
April Mardock:
they don't have a legitimate reason to mail the parents, I
April Mardock:
don't think they should have home address information. Maybe
April Mardock:
email if the parents legitimately interacting with
April Mardock:
them or registering with them or whatever for a portal, but do
April Mardock:
they really need a home address? And I start asking that question
of vendors:
Is why are you asking for this content? Maybe
of vendors:
we used to give this to you, but maybe we shouldn't anymore.
of vendors:
There isn't a reason to give vendors content that they really
of vendors:
don't need for the purpose that we're hiring them for.
of vendors:
Kevin Warenda, TLIS: Yeah, and it strikes me as you're asking
of vendors:
your vendors about how resilient they are. I know we go the extra
of vendors:
step too to ask for a software bill of materials. Like that
of vendors:
understanding of their service is probably not just one thing;
of vendors:
it's probably also reliant on their own third-party vendors.
of vendors:
And so, if they're hosting their application in AWS West, it's
of vendors:
good to understand. All right, then if you're tied to that
of vendors:
region, that if that goes down, this service may also go down. I
of vendors:
actually spend a lot of time having to educate my community
of vendors:
when things stop working, as to why that's down. It's like,
of vendors:
well, why is Canvas down? It's like, well, because Canvas is
of vendors:
hosted on a third-party cloud that was down today on DNS
of vendors:
issues. Like, so yeah, Canvas's issue is actually the
of vendors:
infrastructure they're reliant on. So I think that's an
of vendors:
important call out that you made there. It's like ask your
of vendors:
vendors to describe their solution, what it's built on,
of vendors:
and how it's configured. Not just from a resiliency and a
of vendors:
data security or data residency perspective, but also just in
of vendors:
terms of what makes up your service. What are you also
of vendors:
contracting with, and what are your agreements with those
of vendors:
vendors too? Because this is where we get into data residency
of vendors:
or controllers and processors too, right? Depending on who
of vendors:
that goes to, like if you're signing a contract with vendor
of vendors:
A, well, if there's a sub processor involved there, like
of vendors:
that data may actually go into that other third party, and that
of vendors:
agreement survives that. So I think that's great that you're
of vendors:
asking about that, and I would say expand that even to all
of vendors:
aspects of that service offering to them. The
Bill Stites:
one thing I will add to what you just said is
Bill Stites:
that Hiram and I have been spending a lot of time working
Bill Stites:
with one of the groups that partner with ATLIS a lot is
Bill Stites:
nine, and what you're talking about is that vendor vetting,
Bill Stites:
those sub processors. It's amazing when you get into that,
Bill Stites:
you start looking at that not only from the resilience
Bill Stites:
standpoint, but where's all that data going? And April, you said
Bill Stites:
something that really resonated with me. When you start working
Bill Stites:
with a lot of these vendors, you know how much information are
Bill Stites:
you giving them? I think one of the things that often happens,
Bill Stites:
and I can remember distinctly saying no to one of our vendors,
Bill Stites:
was when they were asking for API level access to our
Bill Stites:
information systems because they were connecting things that was
Bill Stites:
providing direct service. It was like if we wanted to use this,
Bill Stites:
this how it went in, and they were like, "Well, just give us
Bill Stites:
API, you know, read write to all these scopes. And I'm like, "No,
Bill Stites:
I'll give you read access, and I'll give you read access to
Bill Stites:
these because you need to tell me why. And a lot of times, what
Bill Stites:
I found is not for nothing. It's laziness on the part of the
Bill Stites:
vendor to really work to only ask for what they need. They're
Bill Stites:
like, you know what? Just give me as much as you can, and I'll
Bill Stites:
figure out what I'm going to do with it later. With no thought,
Bill Stites:
or maybe there is thought, and I'm just being naive to what
Bill Stites:
they're actually requesting and what that actually opens up from
Bill Stites:
that risk standpoint.
April Mardock:
Well, there's another layer to that too: is
April Mardock:
how long are they allowed to keep the data? And I know for
April Mardock:
districts, we have a tendency to keep stuff as long as we
April Mardock:
possibly can because at some point that turned out to be a
April Mardock:
valuable thing. I'm going to argue the calculus has changed,
April Mardock:
and keeping data, especially sensitive data like discipline
April Mardock:
data longer than you need to is a liability, and so when you're
April Mardock:
working with a vendor and you're giving them sensitive content,
April Mardock:
you really ought to have a retention and archive and
April Mardock:
removal process in place so that all the data doesn't stay there
April Mardock:
forever. Case in point, a lot of us use payroll systems, right?
April Mardock:
Payroll systems have like bank account information. How many
April Mardock:
years of bank account information is in that system?
April Mardock:
If it gets compromised, they might be going back 2030, years.
April Mardock:
That becomes a problem if you don't have the ability to purge
April Mardock:
the content safely and get rid of the content you aren't
April Mardock:
legally required to keep, and you don't have a process for
April Mardock:
managing that, whether it's in house or with a vendor. That
April Mardock:
creates a big liability because when you are compromised, you're
April Mardock:
going to have to go back and notify decades of employees and
April Mardock:
or students if you haven't archived that content and pulled
April Mardock:
it, especially out of the live systems. They do tend to
April Mardock:
compromise the live systems first. They may eventually get
April Mardock:
around to archives if you have to keep it for some legal
April Mardock:
reason. It doesn't necessarily have to be in the live load,
April Mardock:
right? You could put it in another database that you zip up
April Mardock:
and tuck away for when you need it for something else, and maybe
April Mardock:
that's password protected or some other way less accessible
April Mardock:
to the attackers. But if it's all in your live system and it
April Mardock:
goes back decades, you're going to be notifying decades of
April Mardock:
people, and that's expensive. And it's not fair that it's not
April Mardock:
their fault that you decided to keep data longer than you needed
April Mardock:
to.
Hiram Cuevas:
What's interesting about that is I don't know many
Hiram Cuevas:
folks that actually ask vendors to delete their data. Schools,
Hiram Cuevas:
in particular. I mean, when you have the transition of employees
Hiram Cuevas:
coming in and out and in and out and in and out, how many of us
Hiram Cuevas:
actually have done that due diligence of saying, "Hey, I
Hiram Cuevas:
need to contact all my vendors within my tech stack to
Hiram Cuevas:
eliminate these people or this group of students or whatever.
Hiram Cuevas:
It's a massive undertaking, but it certainly is one that we need
Hiram Cuevas:
to keep a top of mind,
April Mardock:
and I would think of like a phase one, phase two
April Mardock:
approach. Maybe you don't do it on a micro level for everyone
April Mardock:
who leaves. There's often, at least in the state of
April Mardock:
Washington, there's stuff we have to keep seven years after
April Mardock:
they leave, or
Hiram Cuevas:
correct,
April Mardock:
however long it is. But you set up something
April Mardock:
where all the records that are discipline records that get to a
April Mardock:
certain age that have aged out can get pulled together, right?
April Mardock:
You don't manage it as an individual, but you start
April Mardock:
tagging and classifying data, and asking the vendors to do the
April Mardock:
same so that they can appropriately dispose of data
April Mardock:
without you micromanaging and saying, "Well, this person left
April Mardock:
seven years ago. Let's go purge their stuff. I can't imagine a
April Mardock:
small district taking that on, it's a big lift, but there are
April Mardock:
ways we can still push the vendors to delete content in a
April Mardock:
timely way. And the other thing is, when you change vendors and
April Mardock:
you move data from System A to System B, don't move all of it
April Mardock:
if you can avoid it. Use those opportunities when you're
April Mardock:
changing vendors or doing upgrades to purge content you
April Mardock:
don't legally have to keep. Whether that's the vendor doing
April Mardock:
the work or you doing the work, I think it's something we need
April Mardock:
to be more intentional about.
Hiram Cuevas:
So, April, we've been looking at this at a very,
Hiram Cuevas:
very high level, at 50,000 foot level, and I'd be curious if you
Hiram Cuevas:
wouldn't mind opining on a situation that I think many
Hiram Cuevas:
schools are dealing with this summer. I had a faculty member
Hiram Cuevas:
come back to me after attending a conference, all sorts of great
Hiram Cuevas:
ideas come out of conferences, and one of them had to do with
Hiram Cuevas:
his interest in using App Scripts to develop an extension
Hiram Cuevas:
for him to use with his students. And when I took a step
Hiram Cuevas:
back, I was like, "Okay, App Scripts is open by default, and
Hiram Cuevas:
I didn't realize it was open by default on the Google domain. So
Hiram Cuevas:
that the first thing we did was we shut that down,
April Mardock:
turn that off.
Hiram Cuevas:
Yeah, and I'm curious what your opinion is in
Hiram Cuevas:
general about the whole access to app scripts by anybody to
Hiram Cuevas:
your Google domain, for better or for worse. I mean, this
Hiram Cuevas:
teacher wants to do the right thing. He wants to try and reach
Hiram Cuevas:
kids a certain way, and I think it's a great idea. I'm trying to
Hiram Cuevas:
develop a sandbox, but we don't have the resources in order to
Hiram Cuevas:
try and figure all that out when it just appears in the middle of
Hiram Cuevas:
the summer. Be curious what your thoughts are.
April Mardock:
So generally, it's one of those where I turn
April Mardock:
off the ability for folks to enable it by default, and they
April Mardock:
have to go through a vetting process, and most of the
April Mardock:
districts I'm dealing with now have to legally review software
April Mardock:
for accessibility anyway, and that includes stuff that you
April Mardock:
would expose in a classroom, like your extension that you're
April Mardock:
talking about, because the district I worked for was the
April Mardock:
first district in the U.S. to get sued for not having a math
April Mardock:
tutoring program that was intended for the student use was
April Mardock:
not accessible by a blind parent at home, and it turned out some
April Mardock:
of the district web pages also weren't accessible to blind
April Mardock:
parents, and what it meant was that the district had to do a
April Mardock:
formal intake process to avoid further lawsuits to make sure
April Mardock:
that software met a certain minimum standard, and all
April Mardock:
software had to go through that process. And the rule was
April Mardock:
anything that the district purchased or anything that the
April Mardock:
district deployed or allowed to be deployed, right? Like this
April Mardock:
application that you're talking about, had to go through a
April Mardock:
formal review process, and that has a checklist of things to
April Mardock:
look at, whether it's accessibility, whether it's the
April Mardock:
cybersecurity configuration, whether it's the privacy
April Mardock:
concerns that might come with it, like any other extension
April Mardock:
that you would deploy, you run it through the same process. If
April Mardock:
that teacher wants to submit their custom written application
April Mardock:
and go through the same vetting process, I would expect the
April Mardock:
process to allow fair treatment of that in the same way they
April Mardock:
would if they wanted to bring in a third-party tool. The problem
April Mardock:
I run into is a little more esoteric. Is yes, I want to turn
April Mardock:
it off and vet everything that I turn back on, and I want to have
April Mardock:
an intake process to cover legal. But you're going to run
April Mardock:
into CTE classes and other places where they want to do
April Mardock:
that kind of programming and learn. Those skills and become
April Mardock:
capable of doing this kind of work, and so what you'll end up
April Mardock:
doing is creating special sandboxes for that, where you're
April Mardock:
going to have to find a way around just saying no. And so I
April Mardock:
understand it's a complicated ask.
April Mardock:
Kevin Warenda, TLIS: I think it's ironic. I spent almost a
April Mardock:
decade in public school supporting technology as well,
April Mardock:
so there's definitely that angle of if there's a regulation or a
April Mardock:
law or legal reason to do something, you can leverage that
April Mardock:
as the excuse of why you're doing it to try to maybe deflect
April Mardock:
the responsibility of that choice from the IT director. And
April Mardock:
I find myself doing that now, even with our cyber liability
April Mardock:
provider, right? So as independent schools, maybe we
April Mardock:
don't have so much of that regulation or public school
April Mardock:
requirements based on statutes and such, but I'm not above
April Mardock:
using the cyber liability policy requirements to say no. Like the
April Mardock:
reason we have MFA for everyone is not because I want to make
April Mardock:
your lives harder; it's because it's required by our insurance
April Mardock:
provider, or we have a vetting process for software and
April Mardock:
applications because it's required by our cyber liability
April Mardock:
provider, so it's ironic we have to use that as the tool to try
April Mardock:
to deflect from why we're doing that. But it's for the right
April Mardock:
reasons, and I think it's tough sometimes to try to educate
April Mardock:
users as to why that's so important. I want to come back
April Mardock:
to something you said earlier about the oversharing of
April Mardock:
information. I think this is especially relevant now. I've
April Mardock:
heard lots of talk. You were also talking about classifying
April Mardock:
or categorizing data sets. This all speaks to this question now.
April Mardock:
With these AI tools, especially generative AI tools that now can
April Mardock:
work at machine speed, they are uncovering all this stuff that
April Mardock:
is shared. And what I'm hearing is the recommendation is you
April Mardock:
really have to get your data house in order before adopting
April Mardock:
these types of tools for any kind of use, because otherwise
April Mardock:
it's just going to find all those corners where you're
April Mardock:
hiding stuff. And if it's not labeled, if it's not
April Mardock:
categorized, I know Microsoft has a tool for this called
April Mardock:
Purview. Right, you can actually classify and categorize what's
April Mardock:
public, what's internal, what's confidential, and these tools
April Mardock:
then can actually utilize those tags and classifications to
April Mardock:
properly put things or expose where there might be issues.
April Mardock:
They can
April Mardock:
Kevin Warenda, TLIS: maybe you could talk a little bit of any
April Mardock:
experience you have in that area or why this is so important in
April Mardock:
the age of AI.
April Mardock:
Two things I do recommend turning off those AI
April Mardock:
search tools until you've done at least some searches and clean
April Mardock:
up on your own. But the second layer to that, one of the
April Mardock:
districts I work with did tag documents using the Microsoft
April Mardock:
tools that were sensitive, and then use the DLP controls to
April Mardock:
block the sharing and the emailing of those sensitive
April Mardock:
documents out, and so that can prevent theft and overexposure
April Mardock:
of content that probably shouldn't be shared. I will say
April Mardock:
sometimes staff have I would call it semi legitimate reasons.
April Mardock:
They might be in working on their doctorate in education and
April Mardock:
they want data. They should be asking for that data formally
April Mardock:
instead of just taking it. It's interesting to see who flags
April Mardock:
that data loss prevention tool, but tagging that content is
April Mardock:
getting easier and easier. You can give it examples of the kind
April Mardock:
of content, especially if it's a form type content like a
April Mardock:
transcript, a discipline form, all of those kinds of things.
April Mardock:
You can teach the system, and it will actually automatically go
April Mardock:
out and flag them, find them, and tag them for you, and then
April Mardock:
you can treat them as appropriate. So yes, those tools
April Mardock:
are getting better. I will say, two years ago, it was a real
April Mardock:
pain to try to do this, and it's getting cleaner and cleaner as
April Mardock:
you move along. I don't have enough experience in the Google
April Mardock:
environment to know how easy that is to do in that space. I
April Mardock:
suspect the tools are coming if they aren't already there to be
April Mardock:
able to automatically flag content and prevent it from
April Mardock:
being overshared, prevent it from being misused in that way.
Bill Stites:
I'll go back to that piece with the Scuba Tools.
Bill Stites:
I just literally got off a call yesterday because we went
Bill Stites:
through a full audit of our Google domain
April Mardock:
with Scuba.
Bill Stites:
Well, Scuba Tools is what I'm going to use
Bill Stites:
actually to validate what we did in our audit, we used another
Bill Stites:
vendor that we've used, and this is now our third audit with them
Bill Stites:
to go through all of that. And it really highlighted a bunch of
Bill Stites:
the things that you mentioned with regard to the oversharing,
Bill Stites:
the DLP controls. You know what you need to turn on and off, how
Bill Stites:
you need to go through that type of audit, and I found that
Bill Stites:
that's incredibly helpful for me and for my team because, as you
Bill Stites:
mentioned, you're not as familiar with the Google
Bill Stites:
environment, so you couldn't comment. Well, we don't live and
Bill Stites:
breathe in these areas every day, and your role as a CISO is
Bill Stites:
one that we hear coming up in schools whenever they talk about
Bill Stites:
this vetting, they say, "Well, talk to your risk committee,
Bill Stites:
talk to your CISO and your risk person. And I'm like, "That's
Bill Stites:
just another hat that we put on over the course of our day, and
Bill Stites:
we're trying to make the best guess in terms of." How we can
Bill Stites:
go about doing that, and one of the things I'll credit Hiram for
Bill Stites:
getting me started on is using AI to actually help with some of
Bill Stites:
that work, whether that be in the evaluation or vetting of
Bill Stites:
services, whether that be in some of the search work that
Bill Stites:
you're talking about there. What would you recommend to people
Bill Stites:
listening to have as their common tool belt of either
Bill Stites:
partners or tools or things to consider as they put on that
Bill Stites:
CISO hat that they are interchanging with their
Bill Stites:
database administrator hat, their mobile device management
Bill Stites:
hat? You know all those things. What can we put in our tool belt
Bill Stites:
to help us with this work that we're doing to level it up a
Bill Stites:
little bit for us?
April Mardock:
So I'd go at a couple different angles. One
April Mardock:
would be working with their local regional support agency if
April Mardock:
they have one, like an ESD educational service district or
April Mardock:
equivalent. If they have a state department of education that has
April Mardock:
a cybersecurity focus. Sometimes some states have cybersecurity
April Mardock:
resources at the state level. For the independents and the
April Mardock:
smaller districts that don't have that support structure, you
April Mardock:
can look to something like K 12 six that's providing guidance
April Mardock:
around vendor management. I'm the chair of the technical
April Mardock:
working group, and one of our next tasks after the Essentials
April Mardock:
reboot will be that scuba report is amazing, but it's like 20
April Mardock:
pages long and there's hundreds of entries in it that are red,
April Mardock:
green, and yellow. And I find that a lot of the smaller
April Mardock:
district folks are just overwhelmed by that report and
April Mardock:
they don't know where to go next. And so K 12 six is going
April Mardock:
to work on sort of a top 10 Microsoft tenant and top 10
April Mardock:
Google tenant things to look for that are kind of urgent that we
April Mardock:
need to make sure all districts are taken care of. So there's
April Mardock:
sort of a crawl, walk, run approach to that, where you can
April Mardock:
basically start with the simple stuff and work your way up.
April Mardock:
Obviously, there are also vendors available that can help
April Mardock:
even the smaller organizations that can do the number crunching
April Mardock:
and give you something actionable. I don't have
April Mardock:
specific vendor recommendations available, but I can say that
April Mardock:
there are a number of them out there that are targeted to
April Mardock:
helping small K 12 s do what they need to do. They realize
April Mardock:
that K 12 s not just don't have a CSO. It might be the science
April Mardock:
teacher who's doubling as the IT admin. It's a pretty constrained
April Mardock:
environment, and they don't have the time or the resources to do
April Mardock:
all the things a big district can do, even though they're
April Mardock:
asked to. And so, how do they offload that? There are some
April Mardock:
virtual CISO stuff out there as well. I will say, Security
April Mardock:
Studio has a virtual CISO class for folks who want to bump up
April Mardock:
their skill sets, and there's also folks who specialize in
April Mardock:
like nonprofit support CISOs. So they're not looking to make a
April Mardock:
dime on you; they're looking to help because they're in it for
April Mardock:
the social benefit and the social good reasons, rather than
April Mardock:
just you're another customer that can pad the dollars. That's
April Mardock:
something I like to see as folks that are in it to try to make a
April Mardock:
difference and provide resources at cost or just over cost that
April Mardock:
help with both the assessment and the training and the support
April Mardock:
to help folks get where they need to go.
April Mardock:
Kevin Warenda, TLIS: Jeff, what I find so impressive is that the
April Mardock:
scope of what you are responsible for supporting now.
April Mardock:
It is very large, 750,000 people. All these districts, but
April Mardock:
you really do maintain a focus on what makes that up is a lot
April Mardock:
of small schools in some cases too, and that those don't always
April Mardock:
have the resources. So I really appreciate that approach and
April Mardock:
that focus that you have. I think you've even developed some
April Mardock:
of your own tools to contribute too, right? Like I think you
April Mardock:
have a AI chat bot that helps with tabletop exercises. Can you
April Mardock:
talk maybe a little bit about what you're building yourself as
April Mardock:
you're seeing the needs and the need for things that are free?
April Mardock:
So I'm a gamer, and I came from a DND Dungeons
April Mardock:
and Dragons kind of background, and I also am an emergency
April Mardock:
operations center volunteer. I'm actually OxCom certified in ham.
April Mardock:
I'm a ham extra, so I spent a fair amount of time in emergency
April Mardock:
response work and getting like FEMA certified for all the ICS
April Mardock:
stuff. And so what it means is I have a really strong background
April Mardock:
in both gaming and in emergency response, and I combined that
April Mardock:
with cybersecurity, and I created essentially a
April Mardock:
facilitated game. It's more of an interactive cyber attack
April Mardock:
story that you can interact with as a school district, or really
April Mardock:
as anyone. It's a Gemini gem that will actually ask you some
April Mardock:
questions. So it'll start out by saying, "What kind of org are
April Mardock:
you? How big are you? Do you have an incident response plan?
April Mardock:
Was it tested? When was the last time you tried restoring your
April Mardock:
backups? All of those kinds of questions, right? There's like
April Mardock:
six questions that ask for setup, and then it drops you
April Mardock:
into a scenario where you've been attacked, and as you
April Mardock:
respond, it will then respond in kind and provide. Options. It
April Mardock:
rolls dice on success or failure. It'll give you bonuses
April Mardock:
if you have a good approach, and it will give you a summary of
April Mardock:
your performance at the end. And so, it's something that I can do
April Mardock:
in person, and I've done it in person. I did it at the K 12 six
April Mardock:
conference for somebody from I think I had about 30 states
April Mardock:
represented at that session, and I did an interactive session
April Mardock:
with the whole room pretending to be supporting one district,
April Mardock:
and they would make decisions. and It goes through six injects,
April Mardock:
and then at the end, it will give you a summary report. And
April Mardock:
what's neat about that is it's adaptive; it never plays the
April Mardock:
same way twice. It is intended to be a bit more strategic, so
April Mardock:
it's going to ask questions about your communications and
April Mardock:
how you would make a legal decision, and how transparent
April Mardock:
you want to be as a district about the attack, and maybe some
April Mardock:
of the extortion methods that the attackers may be using. Like
April Mardock:
sometimes they'll call parents, right, and tell the parents
April Mardock:
about what they've stolen. And it's fairly realistic. I will
warn you:
you'll have a little bit of PTSD if you've been
warn you:
through an attack, but I think it's a great learning
warn you:
opportunity and it's free. It's on my LinkedIn. I'll reshare it,
warn you:
and I think you have it in the links that you can provide for
warn you:
the podcast. It's useful for any size organization, but I built
warn you:
it for the little ones that really don't have anyone to do
warn you:
this for them, and they can't afford a consultant to come in
warn you:
and do it for them. You can also, if you want to stack the
warn you:
deck a little, because IT directors, as a whole, myself
warn you:
included, like to know what we're getting into before we
warn you:
walk into an executive session. You can run through the scenario
warn you:
once, figure out what all the injects are, get it to where you
warn you:
like it, and then tell it to replay the same game. And so the
warn you:
variability is less at that point, and you kind of know what
warn you:
you're going to get into. So if you want to run that session
warn you:
with your executive cabinet, you can. You can also ask it to be
warn you:
more technical. You can adapt it on the fly and use it with your
warn you:
IT teams. The other tool that I set up with permissions from our
warn you:
friends at Black Hills Security is they have a backdoors and
warn you:
breaches game that is great for IT teams to practice their
warn you:
here's what I'm being presented with and here are the tools I
warn you:
can do cybersecurity response with.
warn you:
I turned it into a game where I set up a storyline where I walk
warn you:
through what the attackers are doing over a period of time, and
warn you:
then I line that up with the backdoors and breaches game,
warn you:
where you have basically how does the attacker get in, how
warn you:
does the attacker pivot and move to other machines, how do they
warn you:
establish persistence, and how do they do exfiltration, how do
warn you:
they steal stuff? There's an online version that is free that
warn you:
you can play with your teams, and it's a great way to get the
warn you:
IT teams practicing without having to deal with a real
warn you:
event. So I kind of have both approaches. The Gemini Gem is a
warn you:
little bit more strategic in its approach, and then if you do the
warn you:
back doors and breaches thing, it's more tactical.
Hiram Cuevas:
So April, in this entire conversation, you're kind
Hiram Cuevas:
of preaching to the choir in terms of what we need to do,
Hiram Cuevas:
let's say your audience is for CFOs and heads of school in
Hiram Cuevas:
independent schools. Explain to them the challenges of the
Hiram Cuevas:
staffing model that you currently see in independent
Hiram Cuevas:
schools when it comes to cyber.
April Mardock:
So most schools are what under 2500 kids. It's
April Mardock:
like 75% or more. Those school districts and independent
April Mardock:
schools really don't have the ability to tag somebody to be
April Mardock:
cybersecurity full time. In fact, many of them don't even
April Mardock:
have like a network tech that's formally trained in
April Mardock:
cybersecurity, and so the risk is rarely elevated to the
April Mardock:
boardroom. It doesn't make it into executive session, except
April Mardock:
when maybe they go to renew an insurance policy if they have
April Mardock:
one. And unfortunately, it doesn't get raised to the level
April Mardock:
of risk that I think it represents to small districts
April Mardock:
and independent schools. You are potentially at risk of not just
April Mardock:
going offline, but potentially going under. There's a
April Mardock:
significant percentage of districts and small businesses,
April Mardock:
especially that literally stop operating after this happens. I
April Mardock:
can give a case in point. I know of a you know the 403 Bs. It's a
April Mardock:
retirement savings for educators. So one of the 400 3b
April Mardock:
operators that was used in my region got ransomed. All the
April Mardock:
systems were shut down. They didn't have adequate backups,
April Mardock:
and they went under and didn't come back. It happens when a
April Mardock:
ransom event happens. The business may cease to function.
April Mardock:
You lose trust. You lose reputation with your community,
April Mardock:
and potentially you lose your ability to function. You can't
April Mardock:
do assessments. You lose your bus routing. I mean, think of
April Mardock:
all the things that could go sideways if your systems were
April Mardock:
all offline. And it's worth having that business continuity
April Mardock:
conversation with. Anyway, because there's other reasons
April Mardock:
stuff could go offline. It could be an extended power outage, but
April Mardock:
you need to help them understand the consequences of systems
April Mardock:
going offline in terms of availability, and then the
April Mardock:
consequences in terms of lost trust and lack of enrollment as
April Mardock:
a result, and the other pieces of that where maybe they can't
April Mardock:
get it back. What if they can't get their bus routes back? What
April Mardock:
if they can't get the payroll working? Payroll goes offline.
April Mardock:
They can't pay folks. There's just so many high risk things
April Mardock:
that come about as a result of not having eyes on this ball
April Mardock:
that they either need to contract for that support and
April Mardock:
make it a regular part of their process, or they need to train
April Mardock:
somebody up, but they really do need to spend some amount of
April Mardock:
resources on risk managing this. Otherwise, if they choose to
April Mardock:
ignore it, unfortunately, you guys I think introd with it, or
April Mardock:
I saw it recently. Maybe it was actually a K 12 six thing. It's
April Mardock:
like one out of five has seen a cyber incident, so we're next.
April Mardock:
It's another one of those. It's not if it's when, and so if they
April Mardock:
don't pay attention to this, the risk just gets amplified. One
Bill Stites:
of the things that I want to take this out of the
Bill Stites:
boardroom and out of like the sea level, and I want to bring
Bill Stites:
it down to how do you have these conversations with your staff,
Bill Stites:
because we'll talk a lot about the COVID hangover, which was
Bill Stites:
the wild west of apps and tools and things that everyone were
Bill Stites:
signing up for. How do you have this conversation with maybe
Bill Stites:
just below sea level, or when you get into the operational
Bill Stites:
aspects of school, and then when you get into the classroom? How
Bill Stites:
do you make it clear to them that I think, Kevin, you said
Bill Stites:
this earlier. We're not saying no to simply say no. We're
Bill Stites:
saying no for X, Y, and Z reasons. How do you suggest
Bill Stites:
having those dialogs, those conversations with those groups?
April Mardock:
That's sometimes a harder conversation because
April Mardock:
they're trying to teach and they're under resourced and
April Mardock:
scrambling to make do with the resources they have as well, but
April Mardock:
part of this is they now know. For instance, MFA. MFA was a big
April Mardock:
problem for a lot of schools, and MFA. There was a lot of
April Mardock:
pushback of I don't want to get interrupted in the classroom. I
April Mardock:
have little enough time to train my kids as it is. I don't want
April Mardock:
to do it, but they realize everything that's important,
April Mardock:
like their bank stuff, requires MFA, and then you pull it down
April Mardock:
to brass tacks. Well, if you don't MFA, then anyone can log
April Mardock:
in with your account and change where your paycheck gets
April Mardock:
deposited. Right, employee self-service, and so all of a
April Mardock:
sudden you make it relevant. It's a what's in it for me
April Mardock:
approach. So then they realize, oh, if I don't have MFA, then my
April Mardock:
paycheck could get redirected, and it has happened. I know of
April Mardock:
districts where paychecks get redirected because they didn't
April Mardock:
do MFA, and people have a tendency to reuse the same
April Mardock:
password in multiple places, so it can get stolen from lots of
April Mardock:
places. The example I used was it doesn't even require a
April Mardock:
mistake on your part. Evite got broken into, and when Evite got
April Mardock:
broken into, the bad guys stole the passwords in clear text. Do
April Mardock:
you know how many district folks use their same username and
April Mardock:
password from the district on the Evite site? Now the bad guy
April Mardock:
knows your username and your password. If there's no MFA,
April Mardock:
then they can use that username and password on every system
April Mardock:
you've used that same password for, and so that means they can
April Mardock:
redirect your paycheck. They can log in and steal your student's
April Mardock:
data. They can log in and do everything you can do, and so
April Mardock:
then they start to realize, oh yeah, maybe I should be thinking
April Mardock:
about that differently. Applications are similar risks.
April Mardock:
You can show them that the consequence of that loss is
April Mardock:
significant enough to impede their ability to teach. It's a
April Mardock:
cause and effect thing. It's a what's in it for me thing.
April Mardock:
Kevin Warenda, TLIS: It seems like the theme of this podcast
April Mardock:
today has been it's not rocket science, right? You're talking
April Mardock:
about basic hygiene. You're talking about common sense
April Mardock:
approaches. You're talking about things that don't require a lot
April Mardock:
of technical expertise to pull off, and yet we all still need
April Mardock:
to hear it again and again to internalize that and to put
April Mardock:
these things into practice and to check these doors. April, one
April Mardock:
of the things that you were talking about was the MFA piece.
April Mardock:
One of the questions that I had that often comes up. I mentioned
April Mardock:
the audit that we had done, and it came up in terms of part
Bill Stites:
of that audit. I've read a lot that says frequent
Bill Stites:
password changing is often more harmful than having a strong
Bill Stites:
password that meets a certain character length has certain
Bill Stites:
things in it, and then on top of that, having MFA is MFA and a
Bill Stites:
strong password enough, or is there more needed? That
Bill Stites:
frequency of password change. Is really what I'm curious about
Bill Stites:
because I think you need to change your password every 30
Bill Stites:
days, or you need to change your password every X number of days
Bill Stites:
has diminished, and I want to know if that's true or if that's
Bill Stites:
a falsehood that's just getting perpetuated out there, and that
Bill Stites:
you should be changing password and have that MFA piece done.
April Mardock:
So as much as I'd like to wave a magic wand and
April Mardock:
make all the software that districts use single sign-on,
April Mardock:
where there's a password that's managed in that way, that's not
April Mardock:
happening. So if you think about it, 90% of the applications you
April Mardock:
use are single sign-on, and that password rotation-let's say it's
April Mardock:
once a year-that password rotation is fine. And in fact,
April Mardock:
I'd even downgrade the MFA protected passwords and make
April Mardock:
them simpler, make them fairly straightforward. And length
April Mardock:
matters more than complexity, in my opinion. By the way, you
April Mardock:
know, if it's a 14 character password, but you don't do the
April Mardock:
crazy symbols, because all they're going to do is put $1
April Mardock:
sign or a one at the end anyway. You know it. But here's the
April Mardock:
problem I'm finding, and this happened with School Dude, so
April Mardock:
School Dude got compromised, and again, clear text passwords were
April Mardock:
stolen. And it was not at the time single sign-on. District
April Mardock:
employees have a tendency to use, and school employees the
April Mardock:
same username and password for all work things, and they'll
April Mardock:
change it, and they change it everywhere that they use the
April Mardock:
password. So I use J Smith, and I use Totem 223, and that gets
April Mardock:
used everywhere. And the single sign-on systems, when I change
April Mardock:
my password, let's say there's a compromise, you force folks to
April Mardock:
change their password. It gets changed, but it doesn't get
April Mardock:
changed in those things that are not managed by the single
April Mardock:
sign-on. And as IT directors, we know some of the systems we have
April Mardock:
aren't quite the single sign-on yet, whatever it is, HVAC, the
April Mardock:
Access Badging system. I don't know what it is, but often there
April Mardock:
are systems that are not single sign-on yet, and so I believe
April Mardock:
you need to rotate passwords at least once a year, regardless of
April Mardock:
MFA or not, because those passwords are reused elsewhere.
April Mardock:
That's my argument. So I would suggest once a year, not every
April Mardock:
30 days, but annually I think is important because single sign-on
April Mardock:
and MFA is not in all the places.
April Mardock:
Kevin Warenda, TLIS: Bill, it's worth noticing that NIST did
April Mardock:
finally update their guidance on this topic. For a while, they
April Mardock:
were stuck on the constant rotation, but finally realized
April Mardock:
that you can rotate less often when there are additional
April Mardock:
securing factors in place, and only change when there's
April Mardock:
indicators of compromise or on a longer schedule. And that was
April Mardock:
based on field work they did to say, yeah, what we're finding is
April Mardock:
that kind of as April said, humans just put one extra
April Mardock:
character at the end if there's no complexity requirement.
April Mardock:
They're not making better passwords. They're more likely
April Mardock:
to then write it down on a sticky note. So even NIST did
April Mardock:
finally adjust their recommendations. But I think
April Mardock:
April has a good balance there of still do it, especially if
April Mardock:
there's an indicator of compromise. But I think what
April Mardock:
April's pointing out is it's not that system that's actually the
April Mardock:
issue. It's the reuse of that in other systems. If you're not
April Mardock:
encouraging the use of a password manager, where you're
April Mardock:
getting a unique password for every single different service,
April Mardock:
which would obviously be the ideal, but not everyone's going
April Mardock:
to do that. So I think that's good advice.
April Mardock:
And I disagree with this. I think that you do
April Mardock:
need to rotate at least once a year, and not just when it's
April Mardock:
been compromised because of that fact that MFA really isn't in
April Mardock:
all the places.
April Mardock:
Kevin Warenda, TLIS: That's solid recommendation from the
April Mardock:
field, from someone who's seen and talked to many districts
April Mardock:
being compromised. That we'll take your word for that one for
April Mardock:
sure. Are there any topics, programs, things that you wanted
April Mardock:
the opportunity to talk about that we didn't ask about?
April Mardock:
I would just say also look for cooperatives like
April Mardock:
Waspsy in your region that can get you software and services,
April Mardock:
whether it's cybersecurity services or some of the amazing
April Mardock:
software tools out there for incident response or EDRs or
April Mardock:
even managed service providers. I worry about the 24 by seven
April Mardock:
problem. Most small orgs can't cover night, weekend, and
April Mardock:
holidays when attacks happen, and the bad guys are even timing
April Mardock:
nights, weekends, and holidays. So figure out how you can do
April Mardock:
after hours response. And I strongly suggest folks think
April Mardock:
about allowing their tools to automatically isolate either a
April Mardock:
user or a machine. If it flags as compromised, shoot first, ask
April Mardock:
questions later, check it in the morning. But you really need to
April Mardock:
be thinking about isolating proactively, especially off
April Mardock:
hours. But let the system isolate the user or the system
April Mardock:
and follow up, rather than follow up, verify, and then
April Mardock:
isolate. Because the bad guys are moving faster; they are AI
April Mardock:
assisted, and if you leave that thing sitting for a whole spring
April Mardock:
break, you may be in real trouble. So that's one of the
April Mardock:
other things I want folks to think about: is being proactive
April Mardock:
in those and look to your regional service agency, your
April Mardock:
WISIPs of the world, for the tooling for that because they
April Mardock:
often get amazing prices for that kind of stuff.
April Mardock:
Kevin Warenda, TLIS: And it's a lot of great partners and
April Mardock:
vendors. Work with the Atlas community, or the Atlas
April Mardock:
community itself too, has a lot of that. So certainly, we are a
April Mardock:
resource for independent schools to connect with those types of
April Mardock:
vendors as well.
Bill Stites:
I want to thank April. As I mentioned before, we
Bill Stites:
came on every day. I've got emails, whether it's from K 12
Bill Stites:
six or CISO or our New Jersey cybersecurity cell, and it can
Bill Stites:
be drinking like a fire hose, and having her on to be able to
Bill Stites:
talk about some of these really practical pieces that we focus
Bill Stites:
in on really helps.
Hiram Cuevas:
I'm really glad I made it to this episode because
Hiram Cuevas:
the beach is calling my name, but this was definitely a
Hiram Cuevas:
conversation that needed to be had, and I was grateful for the
Hiram Cuevas:
opportunity to speak to you, April.
Hiram Cuevas:
Kevin Warenda, TLIS: And I'll echo what Bill and Hiram said,
Hiram Cuevas:
"Thank you, April, for joining us today. I think we'll maybe
Hiram Cuevas:
wrap with a softball question: Is there a book or a podcast or
Hiram Cuevas:
a white paper that you've read this summer or listened to that
Hiram Cuevas:
you think is worth a share for our community?
April Mardock:
I will have to say on the entertainment side of
April Mardock:
things, because of the gaming influence, I'm enjoying the
April Mardock:
Dungeon Crawler Carl series. It's giving me a perspective on
April Mardock:
how to troubleshoot things in novel ways and thinking outside
April Mardock:
the box. So, if you haven't already seen it, there's an
April Mardock:
audio book and a regular book series that's becoming almost
April Mardock:
viral, but it's worth a chance to step outside of yourself and
April Mardock:
think outside the box, because some of the solutions that we're
April Mardock:
asked to come up with, especially in small orgs, we
April Mardock:
have to be really creative. And sometimes I need a little bit of
April Mardock:
encouragement in that space.
April Mardock:
Kevin Warenda, TLIS: I appreciate that, and thanks for
April Mardock:
encouraging all of us, Bill Hiram. What's on your summer
April Mardock:
reading list? Anything worth sharing? To be honest with you,
April Mardock:
I'm just
Bill Stites:
getting back off of a two week break where I
Bill Stites:
did
Bill Stites:
absolutely nothing. I didn't even
Bill Stites:
read.
Bill Stites:
I just kind of like laid in the sun. Hiram, hopefully you're
Bill Stites:
going to get a bunch of that. My reading list consists of about
Bill Stites:
200 emails that have piled up over the course of the last two
Bill Stites:
weeks of being out.
Hiram Cuevas:
I'm similar boat there, except I'm reading terms
Hiram Cuevas:
of service agreements with different vendors.
Hiram Cuevas:
Kevin Warenda, TLIS: All right, quite a lively bunch here.
Hiram Cuevas:
April, thanks so much for joining us today and sharing
Hiram Cuevas:
your expertise. If anyone wants to connect with you, what's the
Hiram Cuevas:
best way to find you online or find what you're writing?
April Mardock:
Catch me in LinkedIn and connect me there.
April Mardock:
And then also anybody in the Washington areas, welcome to
April Mardock:
ping me at cybersecurity at wasipsy. It's w sipc.org if they
April Mardock:
want assistance in my state.
April Mardock:
Kevin Warenda, TLIS: All right, thanks everyone for joining
April Mardock:
another episode of Talking Technology with Atlas. See you
April Mardock:
next time.
Peter Frank:
This has been Talk Technology with Atlas, produced
Peter Frank:
by the Association of Technology Leaders in independent schools.
Peter Frank:
For more information about Atlas and Atlas membership, please
Peter Frank:
visit theatlas.org. If you enjoyed this discussion, please
Peter Frank:
subscribe, leave a review, and share this podcast with your
Peter Frank:
colleagues in the independent school community. Thank you for
Peter Frank:
listening.