Cybersecurity Meetup, presented by Huntress
Presented by:
ATLIS Cybersecurity Meetup: Phishing, Passkeys, and Practical Security on a School Budget
In this peer-led conversation, independent school technology leaders compare notes on the security issues showing up in their inboxes and on their to-do lists. The group digs into increasingly convincing AI-generated phishing, including spoofed head-of-school and HR messages, and trades approaches that work, from first-time-sender email banners to automated filtering tools and simulated phishing campaigns aimed at high-risk teams like finance. Participants who are further along share how they're moving to passwordless authentication, covering passkeys, Platform SSO on Mac, account recovery, and life after SMS-based MFA. The conversation also covers the harder edges: authenticating young students on shared devices, supporting faculty who won't use personal phones for MFA, reining in shadow IT and unapproved AI tools, getting leadership buy-in for tabletop exercises, and making meaningful security progress when budgets and hardware costs are working against you. It's a good listen for anyone who wants to know how peer schools are actually handling these challenges, not just what the vendor slide deck says.
Sponsored by Huntress.
Transcript
Yes.
So I am turning on the recording. Welcome everyone to the Atlas Cybersecurity
meetup. These are sponsored by Huntress, and we have a great friend from there
that's going to help moderate today. So her name is Natalie.
Natalie, thanks for being here with us. We appreciate you coming.
Thank you for having me. Hello, everyone. How are you today?
Anyone else excited?
I think we had a couple of the excitement ones.
Good. Awesome.
Another good question is where are you guys calling in from?
You guys can do chat, right?
Yeah, absolutely.
There's not that many of us. You can just unmute yourself and yell it out, because
we want this to be interactive. I know some of you joined a little bit later.
If you would like, today's all about conversation, so if you want to show your
beautiful smiling face on camera, we would welcome that. Oh, awesome.
All over the place. Denver, Colorado.
I'm going to be going to, I think Aurora, I think in
November. Mobile, yep. Well, I guess I should share where I'm at.
I'm in Tampa, Florida.
Nashville. Oh, I just got back from there. It is so hot.
How are you hotter than Florida? What are you guys doing up there, Brad?
Tim, finally broke today. It's only 87, I think.
Oh my gosh. It's been brutal the last two times. Oh, cool.
Someone's coming to Tampa. What are you coming to Tampa for?
I'm actually going to Sarasota, Port North.
My son works for the Atlanta Braves, so I'm going down to pick him up.
Very cool.
His season's over, got to drive him home.
Nice. Very cool. All right. We got you on some...
Oh, we got all across the country. Got Chicago, Redmond, Washington, Mobile,
Alabama. We're all over the place. That's awesome. So let me see.
I saw some of those questions that you got with things you guys wanted to talk to
about, and I captured it so that I wouldn't forget.
So let me get that to the right screen here.
I'm also going to drop those in the chat, and then I'm going to-
Good idea
... stop sharing mine just so that we can see each other.
Yeah. Okay.
All right. So uptick in phishing emails.
Is
there a particular kind that you guys are seeing? I don't know who typed that.
That was me.
Okay.
We're getting a lot of phishing emails that look like they're coming from the head
of school or coming from
the HR department on these oddities.
They have all the telltale signs of
it's a bad email address. It doesn't have the actual footer.
If you mouse over it, you hover over the link, you can see where it's going, and
it's redirecting to the wrong place.
And it's similar ones that are coming from similar email addresses, just
numbered off, like office staff632@gmail.com, and then office
staff538. You know what I mean? So our process has been
to flag them as phishing in the Google Admin console, basically, and
then delete them from all inboxes to clear them out so that we avoid people.
And then we'll take the offending email address and put it in
a blacklist, you know what I mean? To get it-
Yeah
... so that none of them. But because it's iterating on different versions-
Mm-hmm
... of a Google account, just with some numeric changes to it-
Yeah. It's like whack-a-mole
... it's like whack-a-mole. And I'm just wondering, A, if anyone has any other
systematic way of dealing with these? It's great because people are reporting them.
There's a lot of positives to take from it in terms of people are catching them,
they're not clicking on them, they're reporting them, they're sharing them out.
They're doing everything that you want.
It's just at the beginning of the school year, it was literally like whack-a-mole
for two weeks straight of dealing with these.
Wow. Anyone else dealing with this?
I can speak to this a little bit. So we just implemented in July 1 Abnormal
Security, which is not a free solution, but it did essentially eliminate that.
I would say eliminated 99% of those.
What is it, Abnormal?
Yeah, it's called Abnormal. And I would highly encourage, there's a nonprofit
called OETC. I'm actually trying to encourage them to talk to Atlas, but
their pricing was 50% less than going through our normal distributor.
So they made it certainly more affordable, because originally we were definitely
priced out.
The other issue is the, and there's flags that you can do on the back, I think in
Google on this is the
random calendar invites-
Mm
... that are going on people's calendars.
There seems to be an uptick in that as well.
I don't know whether they're necessarily phishing in this case, like these other
ones have been. But there is definitely, in terms of just annoying email
behaviors, those seem to be things that are kind of punching up the list a little
bit.
Yeah. That would actually match a lot of what we're seeing at Huntress with a lot
of times those random calendar invites.
That may even be an AI type of phish.
So hopefully you guys are using security awareness training.
You're not getting a lot of incidents based on that type of activity.
Because really that's your best defense against those kind of threats is the
security awareness training, honestly.
Is that it? Only two people? Only two of you are seeing an uptick in phishing
emails? I find that hard to believe.
I guess I would just add onto that, that the problem we're seeing is the phishing
emails are getting so good that we're actually finding that the training is not...
Unless they're really familiar with the company, they're just getting so good that
it's really hard to tell. We have people bring ones to us that we really have to
look to know if it's real or not.
Yeah.
So what advice are you giving them?
Again, we specifically purchased Abnormal because of this problem that was
automating most of it.
Yeah.
Sounds actually like we're in a similar shape. We're also Google.
We held off for a really long time, and finally we were like, there was just too
much, and they were getting too difficult-
To screen?
Yeah. And we are still doing the security awareness training.
I feel that the ones coming out are very good.
Yeah.
I think that's another one of those after effects of AI, just really lowering the
barrier. Fortunately, it also helps with the company you have.
I'm sure there's an AI component to that.
Awesome.
Our school was getting a fair number of emails and still does, but
we implemented a policy this past summer to
put a banner up on our emails that if they've never received email from that sender
before, they're alerted to the fact, oh, this email may look like it's somebody
from the organization. The email address will give it away, and the banner will
alert them that use extra caution in this situation.
It's a great idea.
Anything else on the phishing before we move on?
We'll go ahead and click your topics off.
All right. So cybersecurity audits for cloud.
So what is the question around that or the discussion y'all want to have?
Our organization is primarily
cloud-based apps.
But at the same time, we still feel the need that maybe we should
do a cybersecurity audit to see how robust is our firewall or how protected are our
clients and maybe the few virtual servers we have on site are
At the same time, we're also curious about some of the vendors we use with their
cloud services. How secure are they?
Has anybody done a cybersecurity audit to test some of their cloud
providers?
We have.
If anyone else has anything too...
But the cloud ones we did were mostly, so we use Entra for our
identity management. We use Google. So we had those both included in our audit.
We use Black Box, and they scan their website, things like that.
But it was really Entra and Google were the two we targeted.
Did you have to work with them to get permission to do some form of testing?
No. The way it worked is we essentially created super user accounts for
our auditor. So they logged in and gave us a list of 1,000 things they want us to
change that we're still working our way through.
Great.
Okay. Thank you.
Anyone else?
All right. So anyone have any exciting plans for Cyber Awareness Month coming
up in, geez, what, two weeks?
Sorry, can we go back to that one for just a second?
For sure.
Yeah. So Greg, just so that you're aware, you've probably seen Bob Olson
around at Atlas conferences over the years as a presenter.
And he is now with Hillco, and Atlas does have a partnership with them to offer
a highly discounted cybersecurity audit.
So you may just want to give him a call and see if what they're doing aligns with
the types of things that you're looking for.
He'll also be at our cyber workshop coming up in October.
But I dropped a link to it in the chat in case you're interested in, again, having
a conversation-
Great
... with him or looking into that audit.
And I would love-
Thank you very much
... to add that Bob is great. He worked actually with a previous company that we've
worked with.
Yes.
Thank you very much.
That's awesome. Well, actually related, someone also did ask, sorry, I should've
scrolled down, about anyone's finance office requiring SOC reports.
I can't read what that face meant, Greg.
Ours hasn't requested them, and I hope we don't.
Okay.
Awesome. All right. So, okay. And thanks for that, Ashley, because that
would be information I wouldn't have had yet.
So, fun plans for Cybersecurity Awareness Month.
Anyone got anything great happening?
I just put that out there just because, typically for us, October is when we do our
cybersecurity awareness training for all of our employees.
Just so that it doesn't get lost in the shuffle at the start or beginning of the
school year. So I'm just curious to see what other people are doing, if they are
sending out the typical training videos or anything like that, or anything
fun, exciting, that's more engaging than just those corporate training videos.
Nobody's doing anything fun. Ugh, come on, guys.
We just do ours through the year, so we don't specify special times.
Okay.
Do you do anything specific, though, for Cyber Awareness Month?
I like your Pac-Man poster.
Got it from a teacher that left.
The hole was ever by, I had to take him down to frame him up.
Awesome.
Oh, I see I got a new message on here.
Jen, you've come off mute. Tell everybody.
Yeah, anybody-
She may-
What were you saying?
I was just going to say, she may not be in a place where she can.
Okay.
I'm curious, too, what you guys are using, your ongoing.
Do you have a KnowBe4 or another type thing where all throughout the year you've
got touchpoints going out?
Mostly KnowBe4.
Yes.
Then we did that PhishER thing, or Phish ER,
whatever they call it.
So Gerald, not for your whole faculty, but we have revamped this year our
cyber offering from Atlas, our workshop that we do in October.
And for a while, we had done a Cyber 101. It was kind of a baseline thing.
So shameless plug, since you're asking about activities.
This one is really targeted, the first day, towards your senior leadership team,
which is a very new and different model.
So we're working on having other heads of schools, having CFOs come and talk about
some of these things, and really help get buy-in.
So when you need to do a tabletop exercise and you go learn all these great things,
and then you try to take it back, and the head of school's like, "Well, we don't
have any time for that ever to do... No, that's not important.
We've got to do this, this, this, this, and this." It helps create that environment
where they can hear from their peers, too.
And then the second day is still a more technical, hands-on deep dive specifically
for the tech audience. So first day, senior leaders. Second day, tech only.
It's virtual, on two consecutive Tuesdays coming up in October.
So if you're interested, check it out.
Okay. Thanks, Ashley.
Yeah. And you'll get to see me again.
Right, Ashley? Well, I guess the senior leaders will, so.
Okay.
Let's see. What else is next on our platform?
SSO, Mac, and are we talking about passkeys for Macs or just passkeys, passwordless
in general? Whoever posted this, you want to give a little more info?
I don't know who it was. Do you know, Ashley?
You're muted.
I'm muted, sorry.
Yep, you're muted.
That
was me.
Oh, okay.
I'm curious, really, if anyone has moved passwordless yet.
We're moving in this direction, but I'm looking for someone who's a step ahead of
us, and I'm struggling to find those people.
Gerald, what have you done with passkeys so far?
So, I lump platform SSO in there as well.
I don't know if people are familiar with that.
But on the Mac side, that basically replaces your login, so it uses your identity
provider. But for passkeys,
we've basically done them as testing for faculty.
Our really high-risk people all have YubiKeys.
So basically, our plan is to have passkeys for all faculty and staff by
February,
and completely replace passwords for them.
How do you recover or support people who may have borked their passkey or
don't have access? That's been my biggest concern or hesitation around that, is
I can reset a password. I don't know what the hell I do to troubleshoot passkeys.
Got it. So we're using Entra.
And
for faculty and staff, we're using what's called a...
If you guys haven't played with passkeys, this might help.
But we're using what's called a bounded passkey, which means it's per device.
So we chose that intentionally because we don't know what other people are syncing
with. But essentially, if someone messes up their passkey, we're setting up
temporary access. So if they mess it up where they can get into nothing, like they
have no device, we would just send them a temporary access pass, which gets them
in, which is the same mechanism we use when they're initially setting up their
account.
Hmm.
And again, that is Entra specific, so if you're using Google, it'd be similar to
the Google
backup codes, is what it'd be close to in Google.
Very interesting.
It looks like you're leading the pack on this one, Gerald.
Oh, well.
Oh, well. That's awesome, though. Yeah.
Gerald, can you tell us more about your process of, again, just the culture
piece and the steps that you guys took to get to where you are?
Sure. So part of this
I'm guessing no one else on this call is using Entra for their identity because
they're changing it, so they're not supporting text-based multi-factor
authentication anymore. And we thought about moving to apps, but we're like, well,
if we're going to switch, we might as well switch to something where we're not
going to have to switch again, hopefully, like a year down the line.
But yeah, again, we're really in the testing phase right now.
And the piece I would say, we have a plan, I think, for everything.
The piece that we're really getting stuck on is logging into shared computers.
We don't have a great solution for that without keeping passwords around for those.
Yeah.
But luckily,
students right now are the only ones who use it.
But,
yeah, so I don't know.
I could go into much more detail, but I don't know what sort of...
If there's specific questions, happy to answer them, but I don't know that people
want to hear me ramble about it forever.
Jen had a question.
Oh, sorry. Go ahead, Greg. Go ahead.
Jurosecures are using passkeys to log into the device?
So we're all Mac. The platform SSO keys that I spoke about or put on the
beginning of there, that's what they're using to log into the device.
So for faculty, we're going to be using what's called Secure Enclave.
It's basically they still have a local password to unlock the encryption on their
computer, and then they use a fingerprint. So they need both of those to log in.
But the advantage is there's no password going out anywhere, so there's nothing to
phish, right? There's no password going off the device ever.
In theory.
Okay.
I don't know if anybody else is interested, but I'd be interested in how you're
securely setting it up
with each user.
So
right now, what has happened is that
we're going to do what's called a campaign in Entra, and it's going to make it so
that people enroll in them on their devices.
But over time, we're going to set up conditional access policy so they're not going
to be able to log in using passwords.
Okay. Like the enrollment of the actual key because you're using YubiKeys?
Is that what you said you're using?
Oh, so we're using-- So actually, the people with YubiKeys actually won't be using
passkeys because YubiKeys are a level above passkeys.
So for our process for that, we did that mostly
right before summer. But basically, we met with
people one-on-one to set those up.
Oh, okay.
Because-
Okay
... I think unfortunately for passkeys, that's
we'll send out emails, instructions, and we're hoping we get 30% to do it, maybe on
their own, and we're figuring we're probably going to have to help the rest of the
people.
Yeah, because that's
where in the enrollment process is where a threat actor could slip in
with the passkeys. But Jen does have a question.
Apparently, Jen's fingerprints cannot be read digitally. I'm sorry, Jen.
And she wants to know if what you're doing negates authenticator.
So
what we are doing, it depends how you implement it.
So for us, because we're using bound passkeys, authenticator is still used on the
iPhone.
I think that's what you're asking.
But it does eliminate those codes in authenticator.
Yeah.
And you can implement passkeys with pins and not fingerprints, although we're not
really planning on doing that. But there might
be reasons for some people we have to do that.
Yeah.
Awesome.
All right. Just make a look over this and make sure I got all of the
questions. I don't think I missed anything from here.
Yeah. And y'all, anything else before we go onto some questions that we're throwing
out at you? Anything that's popped up in your head as we're having this discussion
or that you want to go into more?
All right.
Okay. So I think,
interesting, you all might be interested, what does everyone have on their radar?
So what cybersecurity issue is getting the most attention at your school right now?
I can call on people or you can just unmute and just throw out answers.
Maybe we already covered it.
Well, Greg put a question in here. Who has primary level students using MFA, just
passwords in use? I think he wants to know what kind of authentication you're doing
for primary level students.
Ours are just passwords. We haven't found a good way to do it.
Mm.
Not without losing little keys and whatever else.
It's the same for us, but I'd be interested to know if anyone has been able to do
that effectively, because that'd be great for us as well.
We are passwords as well, but after we finish our faculty, we are moving students
to passkeys, or is our plan.
Yeah. We have our upper-level students using MFA, but not our middle school
students. We don't really have grades one through four on campus.
So if you're using MFA with older students, what are they using as the second
factor?
Typically, their phone.
Yeah.
Is it an app or is it just text messages?
Authenticator a lot.
Currently, they can use text or SMS.
Mm-hmm. Do you have any equity issues there?
Or are there any, like does everyone have a phone?
That would be my biggest concern. That's always been our biggest concern with that,
not to mention the recent cracking on cellphone policies within schools.
You're taking the device out of the hands of the students that are actually...
So what plays off of what?
Yeah.
We're trying to navigate that, too.
Some students are in the exclusion list, and I certainly don't want to be in a
role of
determining, okay, who's taking inventory on who's got phones.
It's not a good place to be, I don't think.
Anyone else have anything to add?
Yeah. I think for us, part of the issue with implementing MFA or
passwordless for our primary students is we have shared devices for them, and so
it's a little bit trickier to implement that
in that scenario. We don't have any.
Again, trying to figure out what other method there is to,
I guess, make passwords or authentication easier for those kids without
jeopardizing security, right? There's always that balance and struggle between the
two.
I've heard Clever actually has something-
Yeah
... but I've not tried it, so I don't know.
The picture
MFA or like the animals thing, right? Yeah.
Yeah. To be honest, I don't even know exactly what it is, but they said they just
released something new.
Do most of you out there have passkeys as an option for students?
I think I mentioned, for us, we're doing it after we deal with faculty.
So no, right now we're just password only. Don't do any MFA on students.
Does anyone have any faculty who refuse to, or who either don't have a device or
refuse to use their device for MFA?
But also won't take a key, so they don't lose it and have to replace it?
No.
I really just don't want to give them a laptop anymore.
We've had a few who've refused to use their personal devices for the MFA,
but we've had YubiKeys available for them, so there's really no excuse for them to
back out. And then we
have quite a few of those YubiKeys anticipating this issue, and so we're
more than happy to replace them if they ever get lost, but-
Yeah, it's definitely our only solution so far.
Yeah.
We have one that doesn't have a cellphone, refuses to.
Two that don't have cellphones at all, and I don't know how they function. But...
We've had one that had a dumb phone before, so they were only
wanting to use-- And then we removed the ability to text using SMS as the
authentication, so we had to issue them a YubiKey.
So yeah, that's ended up being... Or there's been a few people who are like, "If
we're using our personal devices, then you have to pay for our cellphone.
You have to pay for a portion of our cellphone bill." And we're like, "Well, I'll
just give you a YubiKey instead." And yeah, then that was the end of that
discussion.
Sorry.
Sometimes I do want to get rid of mine.
So has anything happened, maybe in the school year, during the start of school,
that maybe exposed some kind of security weakness or some process you want to
improve?
Anyone?
I think for us, it's like shadow IT and just
reiterating what apps they can use and what-- Especially with new faculty coming in
as well. Some people come in with some preconceptions or some
platforms that they are very used to using, and that's not allowed in our
environment. So just, I guess reiterating what's allowed
to be used and what's not. And especially with AI as well, there's some people who
are used to using their own preferred AI platform, and we're telling them like,
"These are the only ones that are allowed to be used," and for what reason,
basically.
And how are you enforcing that?
It's tough. That's the hard part. It's like we have education piece down, but we
don't really have a way to really enforce it to the degree that we
want it to. Right? So
on our network, we can block those
sites, but it's not really device-based, so they can access it anytime outside of
the school. I know there's
new technology that's able to prevent that, whether it's through the browser
extension or
agent-based, but we don't have that implemented yet.
Was that something that's on your plan?
It is, yeah. We're kind of in the infancy of looking into that for next year.
But at the moment, it's on my radar right now, and I don't think it's really on
anyone else's radar at the moment.
Anyone else want to add to that or ask any questions about it?
I'm just scrolling through so I can see the faces, make sure you all are still
here.
So Jen has a question, and I'm guessing Jen's not somewhere where she can talk.
So she says she's curious, any education on home networks and bringing personal
software on campus?
I think that's a...
Maybe restate that a little, Jen. That's a little... Restate.
We've been having discussions about this a lot.
Okay, good. I thought I completely lost.
Yeah. They're looking for more guidance on filtering and more help for what they're
doing at home. So it really doesn't have to do with the school, but like they're
turning towards the school for an education piece.
Do you guys have any recommendations for...
Have you done any parent education events around this?
Let's start with just that piece, and then we can get into the other one.
Do you all recommend any particular
filtering or things like that?
We got out of doing that a long time ago.
It feels like it's coming back around though, Brad.
Yeah.
I feel like the hornet's nest is just getting stirred up a little bit more.
Yeah. Our PA has their own ideas of that, and they want to control that.
So PA has full grip on that right now.
Like our filter way back-
Is that the parent association?
... used to have a home license for it, but then we got rid of that one, and
they're just on their own now.
But most of the education, our PA, we have some PA members who are very anti-tech,
and so they are pushing that as hard as they can right now.
That's difficult.
Mm-hmm.
Like anti-AI. I mean-
Oh, they're not even anti-AI. They want screens gone.
Not just for their kids, for all kids.
Oh, well. I mean-
Yeah.
Yeah.
Well. Good-
And bringing it on campus, no, nobody brings anything to this campus.
There's a guest network that's completely isolated for them.
It's just another way for them to get into stuff they shouldn't be.
High school changed their thing.
That's a whole different thing, but over here, nobody can bring anything in.
Like we had Vanderbilt
graduate students working on grant writing today that had come in.
We had to find a way for them to connect,
because ours is locked to our devices and our devices only, with not even really an
option to connect something else.
Interesting.
So which of you, what cybersecurity task keep getting pushed down
your list that something you'd really like to get to, but that you haven't had the
cycles or maybe like you were saying earlier, Gerald, maybe it's only on your
radar, it's not in leadership, and up the chain on the radar.
What kind of stuff keeps getting pushed down the list because either more urgent
stuff is coming up or maybe you're running out of budget or you can't get
buy-in from the finance people. What are those things that you
want to talk about, those challenges?
Oh, Jen. "Getting admin to understand the importance of tabletop drills."
Yes, you are speaking my language. Those are so important.
Anyone else struggling with that as well?
It's literally what we're going to be doing, session one.
Yeah.
For the cyber workshop.
Yep. They're so important.
Are you guys doing tabletops?
Yes, no, maybe?
I think someone is, but I'm not.
Oh, goodness.
This is my first time with your group, so do you maintain like your incident
response plans and business continuity plans and things like that, or is that
outside the scope? Okay, so I see some heads shaking yes.
So what is your current method for testing that those plans are
going to hold the test of time when... Oh, God. Oh.
It's bad, y'all.
I'm so sorry. Yeah. I mean, those are so important.
It's just like, the way I like to describe it is it's the backup that you've never
tested that you can restore. Your incident response plan is just as good as the
last time you've run through it. You know?
Well, we're kind of unlucky this year, but enough stuff has happened in town, like
the ice storm, everything else, that everything was taken out anyway.
Oh, okay. Yeah. Anything would've-
We've tested it, so I'm sure people in Florida get it a little more because their
power goes out during storms and-
Yeah
... to have to already have that plan in place.
And it kind of gives you tests built in.
Yeah. It does. Yeah. But it's no fun to test your incident response plan or your
business continuity plan when you're having a disaster.
And when you can't get here to do it.
Yeah.
Exactly.
So is that something that would be near the top of your radar for any of you?
Something that you want to implement?
I don't see everyone's shaking their head yes.
We have it, we just need to test it more.
Okay.
So, following along that, what if your school could prioritize
three cyber practices this year? What would be those three
things that you guys would prioritize, and why? Let's not make it too easy.
Don't feel free to type.
Come on, guys. You have to have some data backups, okay?
Healthy paranoia. Okay.
What are your priorities right now?
I know for Jared it's the passkeys, right?
Would you say that's your top priority right now, Jared?
Yeah. Passkeys would be one, and the platform SSO would be two.
Mm-hmm.
I think that will easily fill our school year, so I don't know that we need a
third.
Okay. So maybe it's only two.
I don't know. With all the other competing priorities with tech and the size of a
lot of these departments, it may be one priority that they're working on-
Uh-huh
... for the year, because again, just the attention that AI is getting-
Yeah
... the vendor vettings, all the other things that are going on.
They're doing a lot out there.
Yeah. I'm sure.
So
I get to know you,
I see you first, Gerald, so I'll put you on the spot. What's the size of your team?
Is your team you? Do you have others?
No, I have others. I have a team of five other people on-
Okay
... and they're all on site. So very fortunate that we are at a point where we can
help everyone at the school.
Fantastic.
And we don't really need to outsource or have any consultants come in on a regular
basis. We'll try to get some extra help in for maintenance from time to time, like
in terms of setting up devices. But on a regular basis, throughout the school year,
I feel like we are pretty well-equipped to handle a lot of things at the school.
But that being said, that's more just on the maintenance side and not so much on
the security side.
Okay.
And
we have
MDRs and different devices that will help with that, but it's up to us to kind of
monitor everything as well.
Do your thing.
Yeah.
How big is your school?
We have about 275 employees, and we have
1,200 students.
What does that look like for you, Jared?
We have about 1,050 students and probably about two,
I'm guessing, 250 staff. But if we include coaches, it's probably another
100 to 150.
So we're sort of split into IT and tech.
On our IT side, we have three others besides me, and I split between the two,
although we just got approval to hire someone else.
Okay.
So we're adding.
Awesome. Okay. I see Brad. I don't know if you want me to just read what you wrote
or if you want to chat.
Which one? Oh, the-
The alerting, least privilege.
Yeah, we've got to fix alerting.
Least privilege.
Least privilege because everyone wants access to everything, and we tell them no.
Someone else gives it to them, and then people quit working with all my settings
they shouldn't be touching.
Dang it.
We need people in tech to stick to their thing and not mess with the rest of the
tech.
Yeah, it does. When I was a school IT director, VPNs were the bane of my existence.
Yep. I can see that.
Do you guys try to lock that down? Do you use VPNs, or is
the concern unauthorized or unwanted VPNs?
Like home, "This is my VPN that I use."
Some faculty use it to get in, so they can get to file servers.
Vendors.
A couple vendors. We only were down to three students now that still keep
somehow getting them on there.
They're crafty. I don't know what to tell you.
"Parents would set their kids with them so they could bypass our network security."
Oh, jeez.
How about you, Greg?
What are you prioritizing? What's your team look like?
We have one support admin, about 570 students.
Priority is to do a cybersecurity this year and deal with passkeys
and the,
what is it? The demise of SMS for texting or authentication,
and as well as the phone.
Better implement some-- We've got a bunch of emergency response systems that we're
tuning, tweaking, and enhancing.
Awesome.
So, what would you say
is harder than it sounds, harder to implement than it sounds, harder to get buy-in
on than it sounds? Something like that.
Harder to implement than it sounds?
Anything come to mind?
I think right now we're slowly copying what Bill did forever.
I don't know how long ago he did it and-
Yeah
... the software procurement and keeping up with what everyone's using.
Mm-hmm. Yeah, that can be a beast. But understanding what you have is really the
first step. So, have budget constraints
created some risk for you guys? Would you say a huge risk, mid, minor?
I'd say for us, that's been middle.
Okay.
Definitely budget constraints, especially with rising costs of hardware.
Mm-hmm.
This past last year has kind of made us-- We weren't able to get everything that we
needed. And so we had to make some adjustments and compromises when we were going
through procurement for this budget year.
Yeah.
And so I think just talking with our vendors as well, it's
still going to be an ongoing issue in the next couple of years as well.
So helping or
just letting the finance team know as well that our hardware costs are going to
increase in the next couple of years, and we need to anticipate that if we are
looking to refresh some more hardware. Yeah. So it's been annoying.
Yeah. I can understand that. Especially the hardware cost increase is just crazy.
The
secondary and tertiary effects of things like AI,
right? So, this would be good. Unless someone has something to add to that, a good
follow-on for you would be, what have you been able to improve, or have you been
able to improve things without purchasing another product or another piece of
hardware or another piece of software?
How have you gotten around those budgetary constraints?
Have you been able to, or
it just is what it is?
It's here and there. I think we're
just looking at the different parts of it, right?
Yeah.
The people, process, and technology parts of it, and just seeing-
Yeah
... what we can do with how we can improve our processes with what we have.
At a certain point, I do understand that we do need some new technology in place to
help with certain things, like if we were...
And just seeing where we can reduce the cost on that, whether there's open source
or free open source software to do things that's a little bit easier.
I've been trying to look into-
Yeah
... implementing password managers for our staff and faculty just to help with
managing passwords again-
Yeah
... or just reducing the amount of passwords being shared in open text and
everything.
So our way, we were looking at vendors and more mainstream
solutions. But-
Mm-hmm
... that might not work out, and we might need to look at something that's more
free and open source instead, and just on their own computer.
Nope.
Anyone else have any questions for him? Anything they want to add to that subject?
Right. So you guys did talk about phishing early on,
and I think we kind of touched on, Jared, I think it was you, on the phishing
being harder to detect, right? Yeah, it was you.
You talked about abnormal,
because they're generally...
AI has gotten rid of the grammar errors, the colloquialisms, right?
Because we have different things we say in different parts of the country, even,
right? So if you're in the Northeast, it's pop, and if you're down here in the
Southeast, it's soda, right? Or it might just be Coke, no matter what it is, right?
But AI's managed to get around all of that.
So have you been successful, or have you been able to...
Is the cybersecurity awareness training helping to deal with the influx of all this
phishing and the more realistic phishing that you all are seeing?
Are you doing phishing training besides video training?
Are you sending your own phish tests?
Anyone, all of you, whoever wants to answer.
I see you shaking your head, Gerald.
I'll just pick on you again since you're shaking your head.
You'll not stop shaking your head.
Okay, thanks.
Poor guy.
We are looking to do our phishing test this year.
Also we started using Check Point Security
for our phishing simulation and education.
Mm-hmm.
So just leveraging that, too. Also, I think other platforms do this as well, but I
think it's like Phish ER that takes in legitimate phishing email...
Or sorry, real live phishing emails and removing all of the-
Defangs them
... defangs them, exactly, and then sending them out as phishing tests.
I think those are very topical and very relevant to what people
are seeing. So I think that will help a lot.
And so that's kind of where we're headed at right now.
I think just from what the data that I'm getting from that platform as well
is
there are a lot of phishing emails that are targeting our finance team, for
example, and that would just make sense.
Yeah.
So I think we're probably going to have a bit more tailored, or more specific
simulated phishing emails targeting them over a period as well, and not just the
general ones that are coming out. So-
Right
... yeah. And then just I think also just doing that on a more periodic basis as
well.
Okay. Ogen's saying her last school, they had a policy in place that all new staff
and faculty were required to go through cybersecurity training.
Are you guys doing that kind of stuff as well in your schools?
We make everyone, regardless of if they're new or not.
Oh, okay.
Everyone would have to do it every year.
If they fall for one of the tests, then they have to take more.
If they fall for it again, they have to take a longer one, and it doesn't seem to
make much of a difference with them.
It seems to be more of, I guess, the Southern society thing about, "I don't want to
be embarrassed." Once someone falls for it and they get in trouble for it, then
everyone else starts paying attention.
They're like, "I don't want to be that person now." So word of mouth of someone
else getting in trouble seems to be the best thing that worked.
See, Brad, you could just start rumors.
Nobody would even have to-
Exactly
... you could just be like, "Oh, you."
And they don't know where my office is-
You're dead
... so they can't find me afterward.
We always had a Jim. There'll be a Jim.
Nice.
Exactly.
Yeah. I was going to ask, how do you handle repeat problems without creating a
punitive culture, but Brad's really leaning into that punitive culture.
We don't have to. They do it on their own. It's fantastic.
Don't punish anything.
Guilt goes a long way on their own.
I'm just wondering
Takeaways
-
Advanced Phishing Defense
Sophisticated phishing attacks are prompting schools to adopt automated AI-driven email security platforms like Abnormal Security alongside domain banners to block malicious messages beyond basic admin filtering.
-
Passwordless Authentication Adoption
Technology leaders are actively deploying passwordless authentication using Microsoft Entra, Mac Platform SSO, bounded passkeys, and physical YubiKeys to eliminate password-based vulnerabilities across faculty and staff.
-
Cloud Cybersecurity Audits
Schools are utilizing third-party cybersecurity audits to evaluate cloud identity providers, hosted applications, and vendor environments, ensuring structural protections across both cloud and remaining on-premise infrastructure.
-
Executive Tabletop Drills
Conducting tabletop incident response drills with senior leadership remains a critical priority for establishing administrative buy-in, clarifying communication protocols, and ensuring emergency operational readiness before real disasters occur.
-
Student Authentication Strategies
Implementing multi-factor authentication for students presents equity and operational challenges, driving schools to balance security with accessibility through device-bound passwords, picture-based logins, or emerging passkey frameworks.