<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.techlearning.com/feeds/tag/cyber-security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from Tech & Learning in Cyber-security ]]></title>
                <link>https://www.techlearning.com/technology/security/cyber-security</link>
        <description><![CDATA[ All the latest cyber-security content from the Tech & Learning team ]]></description>
                                    <lastBuildDate>Tue, 24 Mar 2026 09:00:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Better Safe Than Sorry: A Gold-Standard Approach To Cybersecurity ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/technology/cyber-security/better-safe-than-sorry-a-gold-standard-approach-to-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ Conversations with Kevin Hogan:  Charles Franklin, Assistant Superintendent of Technology & Information Services at Cypress-Fairbanks ISD in Texas, shares his district's gold-standard approach to cybersecurity and data privacy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZDRTbkmVQpKVkmE9fExUzF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iANtxp3kifXFCDmogYNKjm-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Mar 2026 09:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 24 Mar 2026 10:02:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kevin Hogan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ &lt;p&gt;&lt;strong&gt;Kevin Hogan&lt;/strong&gt; is a forward-thinking media executive with more than 25 years of experience building brands and audiences online, in print, and face-to-face. Kevin has been reporting on education technology for more than 20 years. Previously, he was Editor-at-Large at eSchool News and Managing Director of Content for Tech &amp; Learning.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/iANtxp3kifXFCDmogYNKjm-1280-80.png">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[kevin hogan and charles franklin]]></media:description>                                                            <media:text><![CDATA[kevin hogan and charles franklin]]></media:text>
                                <media:title type="plain"><![CDATA[kevin hogan and charles franklin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iANtxp3kifXFCDmogYNKjm-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/Y6su1ZuCN9I" allowfullscreen></iframe></div></div><p><em>Watch the video above or download/listen below.</em></p><iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px; margin-bottom: 20px; border-radius: 6px; overflow: hidden;" class="position-center" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/f5199f5e-48a7-4bdf-82d7-0ee0f5bfce23/"></iframe><p>When Charles Franklin thinks about his role as a technology leader in one of Texas's largest school districts, everything starts with security. Not because it's the most exciting topic in edtech — he'd readily admit it isn't — but because it underpins everything else the district tries to accomplish. </p><p>"Security is widespread around everything that we do," Franklin says. "Even if it's not directly related, there's always some interdependency." </p><p>His district is one of only nine in Texas to earn the Trusted Learning Environment (TLE) certification from CoSN, a rigorous credential that requires districts to document and provide evidence of their cybersecurity controls — and then recertify every two years. </p><p>The process, Franklin explains, is less about impressing a review board and more about creating institutional discipline. "It's not just that we're saying we're doing something," he says. "We're showing that we're doing it and somebody is reviewing it." That accountability structure also communicates something important to the community: the district takes student data seriously.</p><p>On the data privacy side, Franklin's team maintains a dedicated staff member focused exclusively on vendor agreements — a significant investment, but one that pays dividends. Every vendor relationship is governed by a formal data privacy agreement that scopes what data can be collected, how long it's retained, and who bears liability in the event of a breach. The district also leverages the Student Data Privacy Consortium (SDPC) and One EdTech to vet products and adopt existing agreements rather than negotiating from scratch each time.</p><p>For smaller districts without those resources, Franklin points to state-level organizations such as TETL — Texas Education Technology Leaders — as a starting point. Through those networks, districts can access templates, share best practices, and connect with peers who have already done the hard work. </p><p>Looking ahead, the district is launching a Virtual Pathways program to attract and retain students in a competitive enrollment environment, and a major data lake project designed to help administrators make smarter, evidence-based decisions across curriculum, finance, and student outcomes.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5 Tips To Launching A Cyber Champions Program ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/5-tips-to-launching-a-cyber-champions-program</link>
                                                                            <description>
                            <![CDATA[ INNOVATIVE LEADER AWARD - Dr. Shanique Worthey discusses her impressive Cyber Champions program and shares how to launch a similar digital citizenship program in your district. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rbC3oviXDG32JFX8CwnnqL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8RLkSmMMY3kdABiLT6PorF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 May 2025 09:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 28 Jul 2026 18:08:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sascha Zuger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gHQk3x9WMA66CvfWv6PdTH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8RLkSmMMY3kdABiLT6PorF-1280-80.jpg">
                                                            <media:credit><![CDATA[Dr. Shanique Worthey]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Dr. Shanique Worthey (&lt;em&gt;bottom right&lt;/em&gt;) and a few of her Cyber Champions ]]></media:description>                                                            <media:text><![CDATA[cyber champions]]></media:text>
                                <media:title type="plain"><![CDATA[cyber champions]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8RLkSmMMY3kdABiLT6PorF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When Dr. Shanique Worthey launched her Cyber Champions program, she had no idea just how many students would jump at the chance to participate in the digital citizenship program.</p><p>“As we began collaborating last summer for the Cyber Champions, we expected a group of 25 or so,” says Worthey, Manager of Security Awareness and Engagement for Georgia’s DeKalb County School District, which serves 92,066 students across 137 schools. “Instead, we had about 100 students immediately apply to be a part of this initiative to virtually meet monthly to talk about different topics such as cybersecurity, artificial intelligence, and being a good digital citizen.”</p><p>For her efforts, Worthey was recently recognized as Innovative Educational Technology Specialist at the <a href="https://www.techlearningevents.com/innovativeleaderawards/8357164" target="_blank"><u><strong>Southeast Regional Leadership Summit</strong></u></a> as part of the <a href="https://www.techlearningevents.com/innovativeleaderawards/categoriesanddeadlines" target="_blank"><u><strong>Tech & Learning’s Innovative Leader Awards</strong></u></a>. </p><p>Worthey discusses her impressive Cyber Champions program and shares five tips to launch a similar digital citizenship program in your district.</p><h2 id="a-winning-gameplan-for-cyber-champions">A Winning Gameplan for Cyber Champions </h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1856px;"><p class="vanilla-image-block" style="padding-top:59.38%;"><img id="Qc5Pcj9H79aF3B2prNENTW" name="Worthey2" alt="cyber champions" src="https://cdn.mos.cms.futurecdn.net/Qc5Pcj9H79aF3B2prNENTW.jpg" mos="" align="middle" fullscreen="" width="1856" height="1102" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Dr. Shanique Worthey)</span></figcaption></figure><p>Worthey launched Cyber Champions with Eric Logan, Director of Information Security, but its immediate success made the duo realize they would need reinforcements to achieve their goal.</p><p>”The numbers were definitely overwhelming,” Worthey says, adding she was thrilled when a dozen teachers volunteered their time to help. “We recruited teachers to help us facilitate virtual meetings and run small breakout rooms to dive deep into the lesson shared in the monthly meeting. We’re hoping to pay them in a future cohort, but we're not there yet. So at the moment we are relying on their enthusiasm and willingness to participate in such an initiative.”</p><p>With such a wide age range, one common digital topic was presented each time with breakout rooms providing space to scale participation by grade level.</p><p>“When I first started out, I was tweaking plans from Microsoft and Common Sense Media about AI and cybersecurity,” Worthey says. “I created a template for the teachers to align to the grade level of their group of four to six students. I wanted to celebrate, not micromanage our volunteers, so I gave them the autonomy to use their expertise in their respective fields to help students understand.”</p><h2 id="building-leaders-the-domino-effect">Building Leaders—The Domino Effect</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1795px;"><p class="vanilla-image-block" style="padding-top:64.90%;"><img id="d2EgC8Wg4bHhMVVAMG72Vg" name="Worthey4" alt="cyber champions" src="https://cdn.mos.cms.futurecdn.net/d2EgC8Wg4bHhMVVAMG72Vg.jpg" mos="" align="middle" fullscreen="" width="1795" height="1165" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Dr. Shanique Worthey)</span></figcaption></figure><p>Empowering and growing leaders extended beyond the volunteer teachers. Student participants not only put in the time to learn the technology-based lessons, they actively teach others in their school community what they learn.</p><p>“They're definitely our ambassadors,” says Worthey. “They're our champions for cybersecurity and AI. They act as a liaison between us and the other students. After the monthly meeting, students are required to create their own presentation based on the information they learned with us and share it with their classmates. That’s why we call them our Cyber Champions.”</p><p>Strength in numbers proves true at DeKalb. Worthey’s team reaches out not only to peers and classmates, but shares lessons with parents, teachers, the local community and beyond.  </p><p>“Some of the students may get selected to present at the PTA or during their school’s morning announcements. Some participate in monthly tech cafes for the community, where they get to present to parents and visitors,” says Worthey. “Many Cyber Champions compete in our tech fair competition, placing in their respective categories. They are highlighted outside of the school community—one was even a participant in the student panel for Tech & Learning.”</p><p>Keeping the monthly message relatable and easy to digest helps kids pass the information on to others, a proven technique for ensuring lessons land and are remembered.</p><p>“We talk about topics like privacy and reading privacy statements,” says Worthey. “We talk about using artificial intelligence—who's behind those chatbots? Ask teachers if now is an appropriate time to use AI and use it as a brainstorming partner, not for answers. We theme it to what is happening for the kids to make it relevant, so over the holidays we discussed how to shop safely online.”</p><p>Worthey promotes the continuation and expansion of the program by using the champions’ own words. </p><p>“As part of our closeout ceremony, I asked our students to create a 30-60 second video to help recruit other students,” she says. “I'm definitely enjoying watching their videos, to learn their feedback and what their thoughts are on the program.”</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1246px;"><p class="vanilla-image-block" style="padding-top:65.89%;"><img id="tPajdrKsSR7mtwCGCoK4in" name="Worthey6" alt="cyber champions" src="https://cdn.mos.cms.futurecdn.net/tPajdrKsSR7mtwCGCoK4in.jpg" mos="" align="middle" fullscreen="" width="1246" height="821" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Dr. Shanique Worthey)</span></figcaption></figure><h2 id="5-tips-to-launching-cyber-champions-in-your-district">5 Tips to Launching Cyber Champions in your District</h2><p>Worthey and Logan share tips on developing a successful Cyber Champions program to boost digital citizenship and understanding. </p><p><strong>1. Offer Opportunities to Hone Soft Skills</strong></p><p>Soft skills such as communication, collaboration, and presenting in front of an audience creates opportunities for students to shine and really be leaders in the field. By working on those soft skills, students will be more comfortable when looking for jobs, interviewing for college, presenting at competitions, and giving classroom reports.</p><p><strong>2. Build Model Students</strong></p><p>Breaking information into smaller, digestible pieces helps students easily share lessons with peers in the classroom. “When we discuss using AI in an ethical and responsible way, students can model proper behavior when using the tech and show others how to be a good digital citizen,” says Worthey.</p><p><strong>3. Bring in Subject Matter Experts </strong></p><p>Worthey has reached out to the local FBI office and shared with them about the Cyber Champions program, explaining that they were looking for ways to partner with the FBI to bring strategies for online security awareness to the table to share with the students. </p><p><strong>4. Create Career Pathway Awareness</strong></p><p>“A lot of our vendors, such as Microsoft, Google, Fortnite, and others have a lot of opportunities for training students interested in careers in cyber security and IT,” says Worthey. “It's a level of experience and knowledge that they have access to through Cyber Champions, so once they go to college or into the workforce, they are already a step ahead.”</p><p><strong>5. Offer Volunteers a Choice of Recognition</strong></p><p>“I created a form asking teacher-volunteers how they’d like to be rewarded for their time,” says Worthey. “Some like personal recognition — a mention at year-end celebration, some wanted items boasting the Cyber Champions logo, some preferred a district-wide news flash, while others would like a gift card.”</p><h2 id="the-tools-they-use">The Tools They Use</h2><ul><li>Microsoft Teams</li><li>Canva</li><li>Common Sense Media</li><li>Fortnight</li><li>Google</li></ul><ul><li><a href="https://www.techlearningevents.com/innovativeleaderawards/home" target="_blank"><strong>Innovative Leader Award</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ K-12 Cybersecurity in the Age of AI: Taking Back Control ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/k-12-cybersecurity-in-the-age-of-ai-taking-back-control</link>
                                                                            <description>
                            <![CDATA[ How districts can take charge of their cybersecurity strategy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QWrsNihXSqtcAhCLRFBYuc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Vw5FgECb6JgFsd9oX2Q6kQ-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Apr 2025 09:00:10 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 11:02:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ray Bendici ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Vw5FgECb6JgFsd9oX2Q6kQ-1280-80.png">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[webinar]]></media:description>                                                            <media:text><![CDATA[webinar]]></media:text>
                                <media:title type="plain"><![CDATA[webinar]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Vw5FgECb6JgFsd9oX2Q6kQ-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI isn't just a buzzword, and K-12 cybersecurity isn't just about blocking threats; it's about securing data from AI-driven risks while ensuring districts retain full control. As AI adoption grows, schools must take control to prevent misuse, protect data, and enforce accountability through technology, without adding complexity.</p><p>Sponsored by itopia, this webinar, which took place on April 8, 2025, explored how districts can take charge of their cybersecurity strategy, ensuring proactive threat prevention, responsible AI adoption, and total data control, with a platform such as itopia’s <a href="https://itopia.com/itopia-secureclass/" target="_blank" rel="nofollow"><u><strong>SecureClass</strong></u></a>. With fully customizable access controls, SecureCless helps you determine exactly what's allowed, down to the details.</p><p>Hosted by Tech & Learning’s Content and Brand Director Christine Weiser, the discussion featured Kyle Berger, Chief Technology Officer at Grapevine-Colleyville ISD, and Jena Draper, Chief Innovation Officer at Itopia.</p><p><a href="https://futureb2b.ondemand.goldcast.io/on-demand/fadc757b-aed2-4332-83b5-e63038a63459" target="_blank" rel="nofollow"><u><strong>Watch the replay here</strong></u></a></p><h2 id="key-takeaways">Key Takeaways</h2><p><strong>AI Adoption and Cybersecurity Risks</strong>: AI is rapidly being adopted in education,  far exceeding that of previous technologies such as the internet or social media, however, this growth brings increased cybersecurity risks. Schools need to secure data from AI-driven threats and maintain control over their systems. “Tools have now embedded AI into their platform, sometimes with us knowing it and accepting those terms, and sometimes without us accepting or knowing those terms,” said Draper. “It has created this extreme risk for us." This necessitates continuous review and adaptation of cybersecurity strategies.</p><p><strong>Balancing AI Adoption and Security</strong>: "AI is going to be embedded in jobs that are existing today,” said Berger. “Jobs that have always been around are adapting." Consequently, schools cannot simply block AI due to its increasing importance in preparing students for the future workforce. Instead, they must find ways to enable AI use while mitigating risks.</p><p><strong>Threat Landscape</strong>: The threat landscape is evolving, with bad actors increasingly using AI for malicious purposes. Schools need tools and strategies to defend against these advanced threats.</p><p><strong>Data Control</strong>: A significant focus for schools and AI should be data control. “It just comes down to what data can be shared with that AI tool, right?” said Draper. “If I'm just typing in silly things about cats or something, it doesn't really matter. But if I'm starting to put my personal information in there, whether it's knowingly or unknowingly, then that's what creates the risk.” To that extent, Itopia's SecureClass allows schools to control what data can be shared with AI tools, such as blocking copy/paste, uploads/downloads, and camera/microphone access.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1189px;"><p class="vanilla-image-block" style="padding-top:53.99%;"><img id="R2p7wjVPPtasSKAqJYUh8Y" name="Screenshot 2025-04-10 151116" alt="itopia" src="https://cdn.mos.cms.futurecdn.net/R2p7wjVPPtasSKAqJYUh8Y.png" mos="" align="middle" fullscreen="" width="1189" height="642" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p><strong>Chromebook Security</strong>: A misconception exists that Chromebooks are inherently secure. However, as their use increases, so does the risk. “It's not just students that are using these devices anymore,” said Berger. “The more usage you see, the more targets and threat actors are gonna start trying to find ways to get to it.” Ensuring that your cybersecurity protection works for all devices is critical.</p><p><strong>Fighting AI with AI</strong>: The webinar emphasized the need to use AI to fight AI threats. “We've got a massive database of over 8 billion endpoints, and we're watching these threats as they are suspicious events so that they don't become problematic for you in the future,” said Draper. “So anytime a URL has any kind of suspicious activity, we go ahead and block it with our extension in real time, and we unblock it proactively as we get information that allows us to feel that that is no longer a risk to you. So we've blocked over 18 million websites in just the last 90 days for suspicious activity around malware and phishing. This is no easy task. But securing AI and then using AI to secure it is all part of what SecureClass's underlying mission is.”</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1396px;"><p class="vanilla-image-block" style="padding-top:55.95%;"><img id="gVw3U6L7dSk7GbXHzZBjRC" name="Screenshot 2025-04-11 094918" alt="itopia" src="https://cdn.mos.cms.futurecdn.net/gVw3U6L7dSk7GbXHzZBjRC.png" mos="" align="middle" fullscreen="" width="1396" height="781" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><ul><li><a href="https://www.techlearning.com/news/tech-and-learning-webinars" target="_blank"><strong>Tech & Learning Webinars</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Student-Led Security Operation Centers ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/student-led-cybersecurity-centers</link>
                                                                            <description>
                            <![CDATA[ A growing number of universities are employing students at their Security Operations Center. Here’s what that looks like in practice. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6LQhBJMoZaVw8WwH5cWcmP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAk9ghuGwdSCzDhH2ZnTfN-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Apr 2025 09:00:10 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 11:13:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp; Learning contributor. A journalist, &lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology can make that more effective. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/gAk9ghuGwdSCzDhH2ZnTfN-1280-80.png">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A lock on a keyboard.]]></media:description>                                                            <media:text><![CDATA[A lock on a keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[A lock on a keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAk9ghuGwdSCzDhH2ZnTfN-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tim Kircher, a junior cybersecurity student at the University of South Florida, jumped at the chance to get real-world experience at the institution’s Security Operations Center (SOC).  </p><p>“It opened my eyes to a lot of the opportunities and broad paths within cybersecurity,” says Kircher, who is an intern at the University of South Florida’s SOC. He adds that working at the SOC empowers him and other students. “It gives us the tools and the abilities to think outside the box and think critically while also learning the critical and technical tools of cybersecurity.” </p><p>Kircher is one of many across the country who is benefiting from an increasingly popular strategy of recruiting students to help secure school networks from the ever-increasing number of cybersecurity threats. The strategy was<strong> </strong><a href="https://news.microsoft.com/source/features/digital-transformation/how-universities-are-tapping-students-and-ai-to-fight-the-growing-threat-of-cybercrime" target="_blank"><u><strong>recently highlighted by Microsoft</strong></u></a> in a blog post on digital transformation. </p><p>The approach is a win-win that both prepares students with real-world experience and helps universities in their ongoing cybersecurity efforts, say those who have been involved with these types of SOCs. </p><h2 id="the-benefits-of-student-cybersecurity-involvement">The Benefits of Student Cybersecurity Involvement </h2><p>For students like him, Kircher says getting involved with an SOC is an important opportunity to start networking in the field, in addition to learning hands-on skills. He adds that the students who work in these centers also give back to their universities. </p><p>“The beauty of our program is that we can take the burden off of our organizations that receive such a large number of security alerts,” he says. </p><p>Corey J. Lee, a security CTO at Microsoft, says he is always being asked how to get started in cybersecurity. “From my vantage point, the best place to start is in one of these security operations centers.” He adds this is because many of those hiring for cybersecurity roles, even early career roles, require applicants to have a wide range of experience with different digital threats. “Working in a security operations center, you get exposure to a large number of security domain areas, identity, email security, endpoint security, network security, etc.” </p><p>Participating in a student SOC can also help students meet the experience requirements of many jobs. </p><p>“A lot of early in career opportunities expect cybersecurity professionals to have three to five years of experience,” Lee says. “What we're seeing is if a student has been working in their student SOCs for three years, and maybe starting in high school, or they've done this throughout their career in college, they're graduating with three to four years of cybersecurity experience.” </p><h2 id="starting-a-student-supported-soc-at-your-school">Starting A Student-Supported SOC At Your School </h2><p>Developing a student-involved SOC at your school can be all about matching students with the right roles in your cybersecurity scheme. </p><p>Ryan Irving,  who manages the student SOC at the University of South Florida, says doing this involves finding the right balance. </p><p>“We want to get students exposed to real-world, hands-on events and alerts and give them the chance to investigate and triage. But we want to limit the risk to the organization as well as to the students,” he says. “So what we do here is we focus predominantly on the level one triage. So we will identify an alert from any given tool. We'll investigate it, we'll do our thing on it. We'll run it down as far as we can, and then whatever we identify via assets, users, open source intelligence on IP addresses, other investigative artifacts, things like that, we will curate that we will create a report, and we'll escalate that.” </p><p>While these types of measures are important, it’s also critical to help students who are interested in cybersecurity develop the skills they need while working at a student-led SOC. Lee notes that in his experience, oftentimes a passion for learning outshines existing knowledge. </p><p>“The talent shortage that we're dealing with right now isn't just about a deficit in humans. It's also a deficit in folks that are interested and willing to learn more and to go into some of the emerging spaces,” he says. “So I can't stress it enough that harnessing the curiosity that exists from students is an opportunity to fill gaps in security operation teams.” </p><ul><li><a href="https://www.techlearning.com/news/5-cybersecurity-for-schools-from-cisas-deputy-assistant-director" target="_blank"><strong>5 Cybersecurity Tips For Schools From CISA’s Deputy Assistant Director</strong></a></li><li><a href="https://www.techlearning.com/news/malicious-qr-codes-5-ways-to-protect-educators-and-students" target="_blank"><strong>Malicious QR Codes: 5 Ways To Protect Educators and Students</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware 2.0: Recent Hacking Trends and How To Guard Against Them ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/ransomware-2-0-recent-hacking-trends-and-how-to-guard-against-them</link>
                                                                            <description>
                            <![CDATA[ Ransomware methods and strategies are evolving but there are still low-cast interventions to counter these attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">f9knA6AshU9w76UmseEvYc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nU6QktF93a5vVmHYv5V5Vb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Mar 2025 09:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 19:17:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp; Learning contributor. A journalist, &lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology can make that more effective. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nU6QktF93a5vVmHYv5V5Vb-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by joffi from Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Binary code on a computer]]></media:description>                                                            <media:text><![CDATA[Binary code on a computer]]></media:text>
                                <media:title type="plain"><![CDATA[Binary code on a computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nU6QktF93a5vVmHYv5V5Vb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ransomware and other attacks continue to be a major threat for schools. Education is an appealing target for hackers because of the level of student data school networks often contain. </p><p>A new cybersecurity report from Travelers, a cyber insurance company, found that ransomware attacks<strong> </strong><a href="http://us.cisionone.cision.com/c/eJwszUuOwyAQBNDTwA6rDW0-CxbZ-BoR4PaYiT8J4ES5_SjRbF-pqiYvbULQnHxvEBC07h1ffFQkgXAApCn0gYJUylhQUQ2DoRR59trEZGZMYXaDufYIg7LSOpwdQ6h5olt-iC3klUoVOqVorbPzLH7bfbl1n4CvfmntXpm6MDkyOb5ery4d5XnWvNezhD1Rl46NyTGuxw-T4wOFBImilfCk73B6RyqiLYVCE4XuR2l8oykHUWilUEnkyX_h-g9MXTQ4qXnxJby7SPuUU2YI89nOQju1zyevrRBtn_ZE2mmreyFh1gIDWREognAWwPQOlZKGP738CwAA__9g0Gh6" target="_blank" rel="nofollow"><u><strong>increased by 32% from Q3 to Q4</strong></u></a> last year. Schools saw similar trends, with 82% of K-12 organizations experiencing cyber incidents during the 18-month study period, according to the <a href="https://learn.cisecurity.org/2025-k12-cybersecurity-report-download" target="_blank" rel="nofollow"><u><strong>2025 State of K-12 Cybersecurity Report</strong></u></a> from the Center for Internet Security (CIS). </p><p>Randy Rose, VP of Security Operations & Intelligence at CIS, discusses the recent trends in ransomware and cybersecurity, and shares advice for how schools can continue to overcome these attacks and keep their networks and data safe. </p><h2 id="increase-of-malvertisement-attacks">Increase of "Malvertisement" Attacks</h2><p>"Malvertisements," ransomware attacks that gain entry to school networks through malicious code hidden in advertisements, have become more common, serving as the vector for malware 63% of the time. These attacks can utilize watering hole adware attacks, in which malicious code is snuck into the ads of reputable sites that teachers or students might commonly visit from their school devices. </p><p>“These advertisers tend to be criminal actors who specialize in early entry, so they gain access to systems,” Rose says. “Typically, what ends up happening is they rent ad space, usually through a third party.” </p><p>Newspaper ad space can be sold multiple times by various reputable companies but eventually, someone sells the space accidentally to a hacker. </p><p>“So a couple of layers down, you end up with a criminal actor who's buying that ad space, and they're putting malicious code into those ads,” Rose says. “When you visit that website, your browser, which is building the website on the fly, is actually executing code that's in that advertisement. That code is looking for a vulnerability in your browser or on your local system.” </p><h2 id="the-rise-of-ransomware-groups">The Rise of Ransomware Groups </h2><p>The Travelers report highlights the emergence of 55 new ransomware groups in 2024. Many of these hacker groups were supported by nation-state resources, while others were more loosely affiliated groups of cyber outlaws with complementary skill sets. </p><p>“Ransomware in particular, it's hard to pin down specifically who's doing what, because the actors that are associated with one group might not have a particular loyalty to that group, and they might operate under multiple ransomware organizations at a time,” Rose says. “If I'm one of those initial access brokers, and I'm really good at gaining access into networks, I might sell my access to four or five different ransomware affiliates.” </p><h2 id="personalized-ransom-demands">Personalized Ransom Demands</h2><p>When hacking groups obtain sensitive information about students and teachers they don’t always just threaten the school or district. </p><p>“We've seen with a couple of ransomware groups where they specifically target teachers and students' parents, and go after them to try to get them to put pressure on the schools to pay,” Rose says. “When they go after the stakeholders, that's a triple extortion attempt.” </p><p>In addition, human vulnerability is often targeted in the initial attacks. According to the CIS report, cyber threat actors target human behavior 45% more often than technical vulnerabilities.</p><h2 id="keeping-networks-safe">Keeping Networks Safe</h2><p>Rose recommends schools follow the CIS <a href="https://www.cisecurity.org/insights/white-papers/cis-community-defense-model-2-0" target="_blank" rel="nofollow"><u><strong>Community Defense Model</strong></u></a> resource. While he knows that funding are tight, basic security measures can go a long way. </p><p>“If you put just essential security controls in place, you offset your risk by 90%,” he says. “Even as threats are becoming more sophisticated, you're really setting yourself up for success by focusing on the simple tasks.”</p><p>In addition to action such as making sure there is an offline backup of data and that all apps are regularly updated, culture is important, particularly a culture that doesn’t stigmatize reports of potential hacks. ​​ </p><p>“Some of the best chief information security officers and IT directors that we know really have a no judgment, no punishment policy,” he says. These technology school leaders let their stakeholders know they can “come to us and share the things that are going on, and we'll work it together," he adds. "You're not going to get in trouble for highlighting a security issue with us.” </p><ul><li><a href="https://www.techlearning.com/news/5-cybersecurity-for-schools-from-cisas-deputy-assistant-director" target="_blank"><strong>5 Cybersecurity Tips For Schools From CISA’s Deputy Assistant Director </strong></a></li><li><a href="https://www.techlearning.com/news/hackers-are-after-student-data-heres-why" target="_blank"><strong>Hackers Are After Student Data. Here’s Why</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Making Students Part of Your Security Operations Center ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/making-students-part-of-your-security-operations-center</link>
                                                                            <description>
                            <![CDATA[ How to strengthen your security operations center with student employees and provide them educational opportunities at the same time. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EuP78btsNAdaJ7z8BY7rV8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XXUKdUqkK3xSpJiVSgXatF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 Nov 2024 10:00:30 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 12:06:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp; Learning contributor. A journalist, &lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology can make that more effective. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XXUKdUqkK3xSpJiVSgXatF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A student at a security operations center]]></media:description>                                                            <media:text><![CDATA[A student at a security operations center]]></media:text>
                                <media:title type="plain"><![CDATA[A student at a security operations center]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XXUKdUqkK3xSpJiVSgXatF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Don’t underestimate student talent, says Jay James, the Security Operations Center (SOC) Director at Auburn University, who built the center at Auburn over the last decade. Part of the center's mission is to employee students to help with cybersecurity as a way of strengthening the efficacy of the SOC but also providing students with hands-on experience in the field. </p><p>Creating a SOC to respond to increasing attacks on schools and universities was <a href="https://www.techlearning.com/news/malicious-qr-codes-5-ways-to-protect-educators-and-students" target="_blank" rel="nofollow"><u><strong>one of the strategies Microsoft highlighted</strong></u></a> in its recent cyber threat intelligence brief <a href="https://www.microsoft.com/en-us/security/blog/2024/10/10/cyber-signals-issue-8-education-under-siege-how-cybercriminals-target-our-schools/" target="_blank"><u><strong>Cyber Signals</strong></u></a>. </p><p>Here are James’ tips for putting students at the center of the SOC at your institution. </p><h2 id="staffing-your-security-operations-center-soc-with-students-establishing-scope">Staffing Your Security Operations Center (SOC) With Students: Establishing Scope  </h2><p>As any cybersecurity professional knows, one of the big challenges of creating a SOC is resources. Before you even start, you want to think about how you are going to direct the limited resources you have, James says. </p><p>To do this, he advises really asking yourself why you are creating the center. “Is it for more compliance reasons -- where you have to make sure that you have a SOC in place? Are you trying to look for certain threats? Are you trying to protect certain types of data?” he says. Once you’ve identified that “why,” you can prioritize resources. </p><p>The next step is developing your specific metrics for success, James says. He adds that if you’re trying to sell the idea of a SOC at your institution, the student and education component can be really appealing to various stakeholders.</p><h2 id="building-student-roles">Building Student Roles</h2><p>For the student component, you need to also build a program that is specific to students. </p><p>“So when you hire a student, they're in a program where they can thoroughly get trained in cybersecurity basics, how to be a SOC analyst, and how to really thrive in the work that they're going to be doing in the SOC,” James says.</p><p>He adds that you also want to develop specific student-centered employee training for new student hires. “Having a specialized training program for students is going to be necessary because they're getting up to speed pretty quickly and they're also learning how to work in a professional environment, something that a lot of the students have not had the opportunity to do,” he says. </p><h2 id="complementing-the-curriculum">Complementing The Curriculum</h2><p>Work that students do in the SOC at Auburn is not directly linked to their degrees or a graduation requirement, but James works with professors in relevant fields so he knows what skills students have and how students can build on these while working at the SOC. </p><p>“We understand what they're learning in the class, and we provide additional training,” he says. “It’s a win-win. We’re getting these very brilliant students that are able to support us and keep the campus more secure but they are also gaining hands-on skills that would be much harder for them to get if they were not in the program.” </p><p>Students also get the opportunity to work on projects of their choosing, gaining valuable experience in the process. “As long as they’re doing their day-to-day triage of security alerts and incidents, we give them the opportunity to focus on a project that would help support us, but it's also a great resume builder for them," James says. </p><h2 id="recruiting-students-to-soc">Recruiting Students To SOC </h2><p>When you first start working with students at a SOC, James says you may have to devote more time to recruitment, which was the case in his experience. He advises connecting with the departments in which cybersecurity classes are housed in your university for help with recruitment. </p><p>Reaching out to student organizations can also be effective. </p><p>“If there is a hacking club or if there is a women in business or minorities in business and/or women in technology, or minorities in technology club, all of those types of organizations have students that you can pull from,” he says. “After it's established, and after students start to experience the benefits of the SOC, they start selling it for you.” </p><ul><li><a href="https://www.techlearning.com/news/malicious-qr-codes-5-ways-to-protect-educators-and-students" target="_blank"><strong>Malicious QR Codes: 5 Ways To Protect Educators and Students</strong></a><a href="https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert" target="_blank">5 </a></li><li><a href="https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert" target="_blank"><strong>Cybersecurity Tips from CoSN’s CEO and a Digital Security Expert</strong></a><a href="https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert" target="_blank"><strong></strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malicious QR Codes: 5 Ways To Protect Educators and Students  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/malicious-qr-codes-5-ways-to-protect-educators-and-students</link>
                                                                            <description>
                            <![CDATA[ Hackers are increasingly attacking schools with malicious QR codes but good old-fashioned cyber awareness can help combat the threat. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Kq3aH5Tq2W7XQfwvapiETh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/c6ZoAwetDhe2LgkQWEtrKb-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Nov 2024 10:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 04 Nov 2025 19:59:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp; Learning contributor. A journalist, &lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology can make that more effective. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/c6ZoAwetDhe2LgkQWEtrKb-1280-80.png">
                                                            <media:credit><![CDATA[Image by Gerd Altmann from Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An illustration of a phone with a QR code on it. ]]></media:description>                                                            <media:text><![CDATA[An illustration of a phone with a QR code on it. ]]></media:text>
                                <media:title type="plain"><![CDATA[An illustration of a phone with a QR code on it. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/c6ZoAwetDhe2LgkQWEtrKb-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>QR codes have become more common in and beyond education. Teachers use these instead of printed handouts and many are regularly placed on fliers advertising university or school events. So it shouldn’t be a surprise that hackers have begun looking for ways to exploit QR codes. </p><p>One way they do this is by hanging fraudulent QR code links in real life or by including malicious QR codes in gifs or as part of fliers sent in emails. Since spam blockers have more trouble recognizing images, and because it's common for school announcements to include QR codes, this is a particular concern for education.</p><p>Over the past year, Microsoft Defender for Office 365 blocked more than 15,000 emails per day targeting the educator sector with malicious QR codes. Microsoft highlighted the threat of malicious QR codes in its latest cyber threat intelligence brief, <a href="https://www.microsoft.com/en-us/security/blog/2024/10/10/cyber-signals-issue-8-education-under-siege-how-cybercriminals-target-our-schools/" target="_blank"><u><strong>Cyber Signals</strong></u></a>. </p><p>Jay James, the Security Operations Center (SOC) Director at Auburn University, and Corey Lee, Security Chief and Technology Officer at Microsoft, both share tips for ways in which classroom educators, administrators, and students can help limit the threat posed by malicious QR codes. </p><h2 id="1-avoiding-malicious-qr-codes-slow-down">1. Avoiding Malicious QR Codes: Slow Down </h2><p>Lee says one important step to avoiding unintentionally opening a malicious link through a QR code is just taking a moment to examine the source of the QR code. </p><p>“It sounds cliché, but really slowing down to speed up is one consideration,” he says, adding that he knows it's challenging with everything that is going on for educators during the day, but it’s important to remember. “We think most QR codes are scanned and clicked because things are just so fast-paced.” </p><h2 id="2-apply-lessons-from-other-cybersecurity-training">2. Apply Lessons From Other Cybersecurity Training </h2><p>Required cybersecurity training in many educational settings have taught us to recognize potential phishing attacks. James says these same lessons apply to potentially recognizing a malicious QR code. </p><p>After you’ve slowed down to assess the source of the QR code, start looking for the same warning signs that might make you suspicious of a link. You might ask yourself, “Is this something I’m supposed to receive?” James says. If the school president or principal doesn’t usually email you, maybe that’s your first sign something is suspect.  </p><p>You should also ask, “Is this something that I'm getting from a sense of urgency?” James says, since a requirement that the user act quickly is often part of phishing attempts. </p><h2 id="3-report-things-you-re-unsure-about">3. Report Things You’re Unsure About </h2><p>As with standard phishing emails, when it comes to QR codes sometimes educators may be unsure of the source. Legitimate emails often seem strange and phishing attempts may look pretty good. </p><p>“If you are an educator, faculty, or staff, feel free to report things to your cybersecurity team or your technology team because they would love to hear about it even if it's a false-positive," James says. "We'd rather get more  reports than less and clear up any questions that you may have." </p><h2 id="4-evolve-your-cybersecurity-training-to-include-qr-codes">4. Evolve Your Cybersecurity Training To Include QR Codes</h2><p>Lee says some organizations have been using the same cybersecurity training for some time. These trainings need to evolve to focus on the latest threats and/or the latest vectors bad guys use to trick users, including malicious QR codes, which also will continue to evolve. </p><p>In addition to updating these trainings, Lee recommends institutions run phishing simulations and provide targeted training. The idea is to test your school community using similar tactics that a bad actor might use. “Then, based on how the user did, we're going to provide them targeted training,” Lee says. </p><h2 id="5-get-students-involved">5. Get Students Involved </h2><p>Awareness training around the potential for malicious QR code use and other cybersecurity lessons should be extended to students as well, both Lee and James say. They also say students can help combat bad actors. </p><p>James employs students in his SOC. The students get real-world job experience of the type they might obtain in an internship and James is able to tap into a rich talent pool. He says getting students evolved was "a game changer." </p><p>He adds, “Don't underestimate the talent that they can bring to the table to help secure our organizations.” </p><ul><li><a href="https://www.techlearning.com/news/5-cybersecurity-for-schools-from-cisas-deputy-assistant-director"><strong>Best Free QR Code Sites for Teachers</strong></a></li><li><strong></strong><a href="https://www.techlearning.com/news/5-cybersecurity-for-schools-from-cisas-deputy-assistant-director" target="_blank"><strong>5 Cybersecurity Tips For Schools From CISA’s Deputy Assistant Director</strong></a><a href="https://www.techlearning.com/how-to/best-free-qr-code-sites-for-teachers" target="_blank"><strong></strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malware and Phishing: What Educators Need to Know ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/malware-and-phishing-what-educators-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Malware and phishing attempts are a constant assault on school security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">25G7SHSnsuvqPSXjMFQwS7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QZX5V2YGeVZLFU9MsTurqL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Oct 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 18:32:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Millington ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/X8Ab6Hyhv3eKDWCduzWcvU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Michael Millington is a senior staff writer for Tech &amp;amp; Learning. A writer and editor with over a decade of experience, his focus on bringing actionable information to those in need is the driving force behind his work. When not researching new advancements in technology, Michael likes to practice his Italian and train his dog Cyril.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QZX5V2YGeVZLFU9MsTurqL-1280-80.jpg">
                                                            <media:credit><![CDATA[Pexels]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing and malware attacks will constantly test educational cybersecurity]]></media:description>                                                            <media:text><![CDATA[Phishing and malware attacks will constantly test educational cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing and malware attacks will constantly test educational cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QZX5V2YGeVZLFU9MsTurqL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <h2 id="how-vulnerable-are-schools-to-malicious-intrusion">How Vulnerable are Schools to Malicious Intrusion?</h2><p>As educational technology use grows, so too do cybersecurity risks of being breached and hacked. Schools and districts become more vulnerable with more technology being used, especially with the emergence of artificial intelligence. </p><p>Jena Draper, Chief Innovation Officer at itopia, discusses two hugely intrusive culprits: phishing and malware.</p><p>Malware and phishing attempts are constant, an almost relentless assault on the security of a school and its inhabitants. Students, teachers, administrators, and even some families can be subjected to these data attacks and breaches. According to itopia, over the past 90 days there have been more than 15 million malware attempts made on schools alone. This alarming number shows that student data is constantly under siege and needs to be protected at all times.</p><p>“Data privacy is adjacent to cybersecurity,” says Draper. “What we do is we have a number of databases as well as our own AI crawlers, and we actively look at over 1 billion domains in real time. If we see even one event of suspicious activity (which has a bunch of different classifications), we block it automatically. In the past 90 days, we have actively blocked 15.961 million malware threats.”</p><p>Millions of sites are working to embed malicious software into school systems on a regular basis, either through malware or phishing attacks, which involve tricking users into providing security access. But how much of this is known to regular internet users?</p><p>“This is not normal consumer information,” says Draper. “The reason why I bring this up, as far as the data points, is that the average consumer, the average school district, the average normal human, does not know about this. We know our data is out there. We know there’s some kind of risk. But we don’t really know how hackers are using our data, how they’re getting to us, and how they are using AI to improve their abilities to access [that information].”</p><p>So there are unseen digital threats all around us. In an age where everything is connected and everything is digital, how do we begin to protect ourselves?</p><p>“Districts need to move from reactive to proactive,” Draper says. “The consensus across all the districts I’ve interviewed in the last couple of months is we have a lot of tools, and we need to start consolidating. Not only do all these tools have a cost associated with them, but there’s also time associated as well. We don’t have the time to manage all these tools and look at the data and hopefully figure out whether a site or a program is a real threat or not.”</p><h2 id="why-are-data-breaches-so-frequent">Why are Data Breaches So Frequent?</h2><p>It is no secret that technology has flooded into the educational space unlike ever before. With the advent of various forms of technology, there also came with it new ways for hackers to steal data and commit heinous acts. </p><p>“COVID amplified our technology use,” says Draper. “So much money flooded into edtech because of the ESSER dollars. It was the perfect catalyst for cybersecurity to go nuts. It accelerated how many vendors and tools were out there, but it also created so many surfaces and endpoints for hackers to get into.”</p><p>Because of the plethora of new programs and devices being introduced to education, focusing on cybersecurity is even more important than ever. We may not see the danger clearly, but it is there and it is constantly working against us. We must remain vigilant in protecting the information of our students, our teachers, and ourselves.</p><h2 id="what-can-school-districts-do-to-protect-themselves">What Can School Districts Do to Protect Themselves?</h2><p>School districts cannot shy away from using technology in the classroom, but with the threats looming in regard to information safety, the question of protection is more important now than ever. </p><p>"School districts aiming to strengthen cybersecurity should start by assessing their risk and readiness,” Draper says. “The <a href="https://www.cybersecurityrubric.org/use-the-rubric" target="_blank"><u><strong>Cybersecurity Rubric (CR)</strong></u></a> by the Cybersecurity Coalition for Education (CC4E), is a great tool for evaluating their posture against NIST categories. Macs and Windows need more layers of protection and are costlier to secure than Chromebooks, which primarily require Google Workspace for Education and an added threat detection layer. Considering cybersecurity expenses in device refresh plans can significantly impact district budgets."</p><ul><li><a href="https://www.techlearning.com/news/best-cybersecurity-lessons-and-activities-for-k-12-education" target="_blank"><strong>Best Cybersecurity Lessons and Activities for K-12 Education</strong></a></li><li><a href="https://www.techlearning.com/how-to/cybersecurity-in-the-classroom-what-teachers-can-do" target="_blank"><strong>Cybersecurity in the Classroom: What Teachers Can Do</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Top 4 State Edtech Trends According To SETDA  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/the-top-4-state-edtech-trends-according-to-setda</link>
                                                                            <description>
                            <![CDATA[ State edtech leaders are thinking about AI and cybersecurity a lot these days, according to a new SETDA survey. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ob68b3iRsWxU5rV9ABQDdJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G3izkkqfzUtbi472K2PqyD-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Sep 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 18:47:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp; Learning contributor. A journalist, &lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology can make that more effective. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/G3izkkqfzUtbi472K2PqyD-1280-80.png">
                                                            <media:credit><![CDATA[Image by Joseph Mucira from Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An illustration of various peole using technology]]></media:description>                                                            <media:text><![CDATA[An illustration of various peole using technology]]></media:text>
                                <media:title type="plain"><![CDATA[An illustration of various peole using technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G3izkkqfzUtbi472K2PqyD-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The 2024 State Edtech trends survey from SETDA reveals state edtech leaders are increasingly focused on AI but remain concerned about cybersecurity and connectivity issues. </p><p>SETDA, a nonprofit organization representing state and territory edtech leaders, recently released its <a href="https://www.setda.org/" target="_blank"><u><strong>annual state edtech trends report.</strong></u></a> While there were few surprises in the report, Julia Fallon, executive director of SETDA, says it paints a clearer picture of where edtech is from the perspective of state edtech leaders. </p><p>Here are the top 2024 edtech trends that emerged in the report. </p><h2 id="1-states-are-issuing-ai-policies">1. States Are Issuing AI Policies</h2><p>AI was the second-biggest priority for state leaders, trailing only cybersecurity. The survey also showed that states are getting more serious about their response to AI. </p><p>For last year’s survey, the number of respondents who said their state had developed a guidance for AI in education was a mere 2%. This year that number grew dramatically to 59%. States such as Washington and <a href="https://www.techlearning.com/how-to/4-lessons-from-californias-teaching-with-ai-guidance" target="_blank"><u><strong>California led the charge with AI policies</strong></u></a>, but now more than 20 states have official policies. </p><p>Fallon expects even more states to issue guidance by the end of the school year. She notes that these policies need to be flexible. For example, Washington has had several iterations of its policy as AI is evolving. </p><p>“It's not just a static policy. It's literally going to be an evolving policy as they work through things, or new things come on the scene when it comes to the AI space,” Fallon says. </p><h2 id="2-cybersecurity-remains-the-biggest-priority">2. Cybersecurity Remains The Biggest Priority</h2><p>AI may get more headlines but cybersecurity remains the No. 1 concern among state educator leaders. </p><p>“It’s the nerd toast,” Fallon says. “It’s the stuff that the IT folks are really always very concerned about. But unless you're impacted by a cybersecurity breach or something [similar] you're probably not thinking about it very much, even though everybody plays a part in mitigation.” </p><p>Despite how serious the issue of cybersecurity is, fewer state leaders believe their state is providing sufficient funding to support cybersecurity efforts compared to previous years the survey was conducted. </p><p>Fallon says state education leaders should look for areas in which they can support schools and districts in cybersecurity mitigation efforts, particularly rural and underfunded districts. This will look different in different contexts yet may include helping smaller districts contract the work of a cybersecurity specialist or providing support at the state level, she adds.</p><h2 id="3-home-connectivity-remains-top-unmet-need">3. Home Connectivity Remains Top Unmet Need </h2><p>Home internet connectivity for students and their families was the top unmet need across states. This was followed closely by funding concerns as federal pandemic funds expire this fall. </p><p>“People really need to understand why home access is still a thing,” Fallon says. “A lot of people are thinking, 'Well, the pandemic's done, or at least mostly over, and we're all back kind of in the world.'” </p><p>As educators well know, internet access for students remains vital as ever for homework, research, communication with teachers and peers, and more. Fallon says educators should continue to reinforce the need to other stakeholders, and state leaders should be reminded of how critical it is to continue providing internet accessibility to students. </p><h2 id="4-state-office-of-educational-technology-are-on-the-rise">4. State Office of Educational Technology Are On The Rise </h2><p>The percentage of state leaders who reported that their state has an office of educational technology increased by 10 percentage points over the past two years (from 55% to 65%). Fallon says states should continue to add these positions. </p><p>“<a href="https://www.techlearning.com/news/the-2024-national-educational-technology-plan-is-out-heres-what-you-need-to-know" target="_blank"><u><strong>The National Edtech plan</strong></u></a>, which was launched in January of 2024 by the U.S. Department of Education, recommends that states have an Office of Edtech,” Fallon says. The plan also called for districts to have someone coordinating edtech initiatives. </p><p>This head of this office can change because of who is elected governor, so continuity can be a challenge during an election year. Nonetheless, Fallon says the key for these positions to be successful is to provide meaningful individualized guidance to districts rather than any kind of blanket approach, which tends not be applicable in different contexts. </p><ul><li><a href="https://www.techlearning.com/news/creating-a-responsible-ai-policy-top-10-things-to-know"><strong>Building An AI-Friendly Infrastructure in Schools</strong></a></li><li><a href="https://www.techlearning.com/news/building-an-ai-friendly-infrastructure-in-schools" target="_blank"><strong></strong></a><a href="https://www.techlearning.com/news/creating-a-responsible-ai-policy-top-10-things-to-know" target="_blank"><strong>Creating a Responsible AI Policy: Top 10 Things to Know</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How A Two-Pronged Approach Helped To Protect Student (and Staff) Data ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/how-a-two-pronged-approach-helped-to-protect-student-and-staff-data</link>
                                                                            <description>
                            <![CDATA[ INNOVATIVE LEADER AWARD - One district has gone about protecting school and staff data by addressing the issue in two distinct ways. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N3vHrX7FUyECoUhQ4WfpkR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BdAX2dv7dGmQCkkzSMxG4P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Sep 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 19:01:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Millington ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/X8Ab6Hyhv3eKDWCduzWcvU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Michael Millington is a senior staff writer for Tech &amp;amp; Learning. A writer and editor with over a decade of experience, his focus on bringing actionable information to those in need is the driving force behind his work. When not researching new advancements in technology, Michael likes to practice his Italian and train his dog Cyril.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BdAX2dv7dGmQCkkzSMxG4P-1280-80.jpg">
                                                            <media:credit><![CDATA[Pexels.com]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two women look at data on a computer]]></media:description>                                                            <media:text><![CDATA[Two women look at data on a computer]]></media:text>
                                <media:title type="plain"><![CDATA[Two women look at data on a computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BdAX2dv7dGmQCkkzSMxG4P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As we send our children to school, we provide them with varying levels of data that, if left unchecked, could cause unnecessary problems for students late on in life. Plenty of ways are available to try and protect information, but should schools be collecting and holding onto that much data in the first place?</p><p>Beverly Miller, Assistant Director of Schools for Administration/Chief Technology Officer for Greeneville City Schools in Greeneville, Tennessee, and recent winner of a Tech & Learning <a href="https://www.techlearningevents.com/regionalsummits/awards" target="_blank"><u><strong>Innovative Leader Award</strong></u></a> for Best Implementation of Data Privacy, discusses how much student information schools should keep and the questions we should be asking about collection policies.</p><h2 id="why-are-we-collecting-so-much-data">‘Why Are We Collecting So Much Data?’</h2><p>Thousands of students attend hundreds of schools every year, and each one has data collected in some way in the process. Miller saw this practice as a disservice to students and wondered whether schools should be collecting all of the data that they do.</p><p>“As a forty-year technologist, about 15 years ago, I really started to become concerned about the massive amounts of information that we had on both students and the adults who work in a school district,” says Miller. “Long before the real focus on data security and data privacy became such an industry focus, we started working in my little school district in the Appalachian mountains of Tennessee. I started assembling a team of district leaders and district employees. We started by conducting a paper data records inventory. What I became immediately concerned with is the records we had.”</p><p>Gathering information on students and teachers isn’t out of the ordinary for a school or an educational system, but Miller took issue with what kinds of data schools were collecting and how long they were holding onto it.</p><p>“Along the way, what I started to realize was that we had social security numbers on people all throughout our community because so many had graduated from the Greenville City school system (including our existing students),” she says. “So I really started digging at that time saying ‘Why in the world do we even collect student’s social security numbers?’”</p><h2 id="a-two-pronged-approach-to-data-security">A Two-Pronged Approach to Data Security</h2><p>Collecting data for a school might not be alarming, but keeping it forever might pose a significant risk to anyone who has attended or is attending that school. The same goes for former and current employees. </p><p>To protect both former and current students and staff, Miller led a district-wide initiative to limit access to critical data and bolster security.</p><p>“[Our school] became one of the very first schools<strong> </strong><a href="https://www.techlearning.com/how-to/6-steps-to-remove-social-security-numbers-from-student-data"><u><strong>to completely eliminate student social security numbers</strong></u></a><strong>,</strong>” Miller says. “We went so far as to delete them electronically. We no longer ask parents for that information. But then we went back through all of those historical paper records and shredded all instances of the social security numbers coming up. It just put the district and the individuals at such risk. We made sure that if we were ever breached that the data would include only the absolute minimal data that we needed on people.”</p><p>The district also partnered with Scribbles Software to convert roughly 50 years of paper records into a digital system, only accessible in a secure cloud. This streamlined the records management process and made it easier for designated staff to find what they were looking for quickly, and significantly improved security by eliminating the concerns that come with paper-based records systems, such as data being accessed by unauthorized personnel. </p><p>The multiple security measures embedded into the cloud-based system also reduces the likelihood of sensitive information falling into the wrong hands. Both of the initiatives above are examples of how Miller’s proactive approach is ensuring student and district data remains private and secure. </p><h2 id="using-data-mitigation-to-reduce-risk">Using Data Mitigation to Reduce Risk</h2><p>As technology continues to evolve, our information becomes more susceptible to breaches everyday. Yet no matter where your school is, controlling the data you keep can be an attainable goal.</p><p>“Even though we’re a small rural community school district in eastern Tennessee, I think we have built a model that could very well be replicated and scaled up or down based on school district size,” Miller says, noting her two-pronged approach. “From this point forward, we will have this process in place. It’s just a matter of how dedicated people would be in order to take care of the data. I think of things from a corporate standpoint. People always have a need or use for [information], so they’re always going to find a way to dig information out of you. But from a school standpoint, where things like ransomware attacks are so rampant, having less information to give would actually be more helpful.”</p><p>Personal information needs to be protected no matter what. With a template like this in place, students can learn in peace without fearing their data will fall into the wrong hands.</p><ul><li><a href="https://www.techlearning.com/tag/innovative-leader-awards" target="_blank"><strong>Innovative Leader Awards</strong></a></li><li><a href="https://www.techlearning.com/news/keeping-student-and-teacher-data-safe-and-secure" target="_blank"><strong>Keeping Student and Teacher Data Safe and Secure</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Keeping Student and Teacher Data Safe and Secure  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/keeping-student-and-teacher-data-safe-and-secure</link>
                                                                            <description>
                            <![CDATA[ INNOVATIVE LEADER AWARD - Student data can be more secure by taking steps such as monitoring data privacy agreements and implementing multifactor authentication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uEamjBDnCUrWB4DA3EQy93</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dv3eeJbD2gLqN73yA5mayn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Aug 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 07 Nov 2025 02:04:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Millington ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/X8Ab6Hyhv3eKDWCduzWcvU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Michael Millington is a senior staff writer for Tech &amp;amp; Learning. A writer and editor with over a decade of experience, his focus on bringing actionable information to those in need is the driving force behind his work. When not researching new advancements in technology, Michael likes to practice his Italian and train his dog Cyril.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dv3eeJbD2gLqN73yA5mayn-1280-80.jpg">
                                                            <media:credit><![CDATA[Pexels.com]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data security]]></media:description>                                                            <media:text><![CDATA[Data security]]></media:text>
                                <media:title type="plain"><![CDATA[Data security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dv3eeJbD2gLqN73yA5mayn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data security is a big concern with the amount of technology being introduced to schools in recent years. Knowing how to keep information safe and secure is important, but how can that happen with so many advances in technology being made on a regular basis?</p><p>Christine Jones, Coordinator of Educational Technology for the Palmdale School District in California and recent winner of a Tech & Learning <a href="https://www.techlearningevents.com/regionalsummits/awards" target="_blank"><u><strong>Innovative Leader Award</strong></u></a> for Best Implementation of Data Privacy during the Denver Regional Leadership Summit, discusses the ways she has upgraded data safety practices in her school and how educators can keep student and teacher data safe from outside threats.</p><h2 id="data-threats-are-not-new">Data Threats Are Not New</h2><p>When it comes to protecting students’ data in and out of school, the threats they are exposed to are not a new occurrence. Breaches in security have been happening for years. </p><p>“Our district, back in 2016-2017, had a ransomware attack. That was shortly after I joined the district and it was not a pretty sight,” says Jones. “It was a moment where we realized that our security had been set up for physical events very well. We had offsite [areas] where our records were being kept. There were multiple locations in anticipation of fire, earthquakes, and that kind of thing. But we hadn’t done an excellent job of thinking about a digital attack or event.”</p><p>On the heels of this event, Jones and the district made a concerted effort to improve cybersecurity efforts.</p><h2 id="the-influx-of-apps-and-the-need-for-data-privacy-agreements">The Influx of Apps and the Need for Data Privacy Agreements</h2><p>Previously, computer security was a simple addition of one or two programs to thwart outside interference. Many programs that were used on computers were known to be safe. However, with the ever-growing influx of programs, data is increasingly at risk.</p><p>“The risk is higher because everything is installed digitally or comes from the internet, and you’re loading everything up into the cloud,” Jones says. “The bigger issue started happening when a lot of these apps started requiring accounts. You had to have an account to participate or to play. It took a little time to understand what was happening, how that data was being transferred to the application and how it might be used. And that’s when I started carefully reading their policies and their agreements and wondering [what’s happening with our data?]”</p><p>Many people tend to sign up for a service or give our information without a second thought. This kind of behavior can put their data at serious risk. But there are some regulations in place meant to safeguard that information.</p><p>“In California, we became aware of the NDPA, the National Data Privacy Agreement, and so we started to take a closer look at that and at the same time CITE, California IT and Education, started to lead the charge for how carefully we look at the programs we’re adopting,” says Jones. </p><p>As a result, Jones has developed a curated list of “Approved” resources that can be found on the district website that helps to guide staff to digital resources that have been reviewed and have been deemed “high quality.” To receive this designation the resources must have current data privacy agreements (DPAs) in place with the district, have appropriate fully ad-free content for students, and are not connected to social media, blogs, or any other type of social sharing.</p><p>The list is updated monthly as DPAs are updated. New resources may be added and current resources may be removed if any fail to adhere to district guidelines. </p><h2 id="implementing-security-measures-at-the-cost-of-convenience">Implementing Security Measures at the Cost of Convenience</h2><p></p><p>Keeping student information safe is critical, and to do so means making access to devices more challenging. </p><p>“We just implemented multifactor authentication this past school year, and we did get some pushback,” says Jones. “So we gave them multiple ways to authenticate. One was through YubiKey. The positives with this method is that you’re the only person with access to the USB device. The negative was that the physical device could be left at home or misplaced. Using MFA, teachers could authenticate with their devices. I’d say that 90% of our staff choose to do it through their phone or their iPad because they found it simpler.”</p><p>Even though it might take a little while longer to log into an account or access some sensitive information, having MFA implemented can be the difference between keeping your data safe, and leaving your data wide open for a breach. <br></p><h2 id="tools-jones-uses">Tools Jones Uses</h2><ul><li>Classlink</li><li>YubiKey</li></ul><ul><li><a href="https://www.techlearning.com/tag/innovative-leader-awards" target="_blank"><strong>Innovative Leader Awards</strong></a></li><li><a href="https://www.techlearning.com/news/gamifying-cybersecurity-training" target="_blank"><strong>Gamifying Cybersecurity Training</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gamifying Cybersecurity Training ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/gamifying-cybersecurity-training</link>
                                                                            <description>
                            <![CDATA[ INNOVATIVE LEADER AWARD WINNER - By gamifying cybersecurity training, you can increase engagement and the retention of best practices, ultimately increasing your district’s safety. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">49jrE4YTWN6GyVkYYtvbJU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mr53kJUyi9ooqMGxNXfTJP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 15 Jul 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 27 Jul 2026 17:35:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sascha Zuger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gHQk3x9WMA66CvfWv6PdTH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mr53kJUyi9ooqMGxNXfTJP-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gamifying cybersecurity training by making it an engaging learning experience]]></media:description>                                                            <media:text><![CDATA[Gamifying cybersecurity training by making it an engaging learning experience]]></media:text>
                                <media:title type="plain"><![CDATA[Gamifying cybersecurity training by making it an engaging learning experience]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mr53kJUyi9ooqMGxNXfTJP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity is no game, unless you visit the district of Tech & Learning Innovative Leadership Award winner Eva Mendoza. </p><p>Chief Information Technology Officer at San Antonio ISD, serving 45,000 students in 70 schools, Mendoza is known for creative attempts to teach cybersecurity, such as her popular “Phish Market” poster and PSA-video contest with winner’s artwork appearing as the lock screen on the district’s chromebooks and school monitors. She also offers a PD version of a popular television game show.</p><p>“It’s standard ‘Family Feud’ with a cybersecurity theme,” says Mendoza, who was honored for her efforts during a Tech & Learning <a href="https://www.techlearningevents.com/RegionalSummits" target="_blank"><u><strong>regional leadership summit</strong></u></a>. “We follow the basic rules of the game, where a hundred people are surveyed and participant teams guess the most common responses. We just happen to have a hundred people on our IT staff, so it worked out great.”</p><p>Surveys are created with simple Google docs or Microsoft forms, free options that any district budget can handle. </p><p>“We send out a survey, asking questions such as, ‘What is the most commonly used password?’” Mendoza says. “Then we take the game around to different targeted departments because of the data they handle, and get some volunteers to make up two teams. We usually try to gamify anything within HR and finance. It’s just really engaging when you add in competition.”</p><p>Mendoza finds this style of engagement helps important info sink in, both for participating game contestants and the audience.  </p><p>“So we might say, ‘We asked one hundred people, what are the most commonly used passwords? And the responses come — ‘1234’ or ‘pet’s name,’ ‘year of birth,’ all of these things that people do, but are super easy to guess or find,” she says. “There will be some funny responses and then <em>‘Survey says</em>— ‘ and the results can be eye-opening. We want to hit them with that real-world shock. ‘Oh, wow — we all do that or know someone who does.’”</p><p>Some of the answers are entertaining, such as during the real show, which keeps the audience attentive rather than the dynamic of zoning out, too often seen in PD sessions. Mendoza then has the principal or a tech director give a short one liner of actual information, enough to drive home the lesson without ruining the fun and engagement of the activity. </p><p>“We created it within PowerPoint, using the graphics and theme song. It took a little bit of tweaking, but now that it's established, we can take it around to our different departments to take part in the game,” she says. “I personally think cybersecurity's super cool and fun, but you know, not all my colleagues across the district may feel that way. Sometimes people think it's a little intimidating or they think ‘It isn’t part of my work.’ Cyber safety is a shared responsibility. We all play a part in it and we want them to learn and understand the important role they play in cybersecurity.”</p><h2 id="gamification-isn-t-just-for-students">Gamification Isn’t Just For Students  </h2><p>Most school districts in Texas are required to have cybersecurity training approved by the state. </p><p>“These were often formal, traditional, sometimes boring videos that we were required to watch,” says Mendoza. “If you can reach beyond that traditional training, however, you can make a serious impact.”</p><p>It doesn’t matter how secure and advanced your system is if it is made vulnerable by those using it. This can be a real problem when human error leads to leaks of sensitive student data such as social security numbers, grades, health matters, personal phone numbers and addresses, and other family information. </p><p>“With cybersecurity, the No. 1 way people hack into systems is to hack the person, not the technology,” says Mendoza. “They go after those without cyber awareness, capitalizing on human error and carelessness. We need to ensure educators and staff realize the threats that are out there and that they are one of the most important parts of the strategy to keep our environment safe for our students.”</p><p>This sort of fun exploration of cybersecurity can even be a unique way to engage students in assemblies, cheering on teacher teams while learning.  </p><p>“Hackers don't care if a target is a six-year-old, it is just an account to get in,” says Mendoza. “Kids need to learn just as much as our staff. Our students are growing up in a digital age from day one. Even if you're itty bitty, you have a digital footprint, and you need to learn to stay safe and how to protect your data. We did a little lesson with all K through 12. Some of the feedback we got from the teachers were stories of ‘My Roblox account was hacked and they took all my points.’ They are in their own world, but that could be so much bigger if they're not taught early and are ready for the future.”</p><h2 id="tips-when-creating-your-own-cybersecurity-training-games">Tips When Creating Your Own Cybersecurity Training Games  </h2><p><strong>Create real-life activities.</strong> Mendoza says, “We did a tabletop exercise to take staff through a full-day scenario of what it’s like when you go through a ransomware attack. For example, 9:13 a.m., teachers complaining ‘I can’t log in or get to my email.’ How are you going to get through the day without no system? What happens if somebody picks up their kid early, what happens at dismissal? Now extrapolate that into a system down for three to five days. It was meant to be an exercise for staff, but it turned into a great resource for us to document and make a plan of everything schools would need from us and the central office to get by. Suddenly, it comes full circle and we have staff saying, ‘I couldn't make that connection, that my clicking a phishing link could lead to the whole district being down for five days.’ We were able to make it real for them. </p><p><strong>Share the why.</strong> “A lot of the time we have processes for the vetting process on technology or digital tools,” says Mendoza. “Sometimes applications or softwares are denied. Educators see something on social media, a blog or a seemingly helpful app, and don't really understand why— ‘It’s free! I don't see why!’ It comes down to data privacy and protection. We have to read all the terms and conditions. At the end of the day, the ‘No’ is for the students and for our staff so we can be into a good digital environment. </p><p><strong>Focus on the people.</strong> “Having the people part of your strategy is so important,” says Mendoza. “You have your processes, you have your technology, all your cybersecurity systems and solutions. But you need that people piece to make sure that your cybersecurity posture is strong.” </p><ul><li><a href="https://www.techlearning.com/tag/innovative-leader-awards" target="_blank"><strong>Innovative Leader Awards</strong></a></li><li><a href="https://www.techlearning.com/news/how-gamifying-education-brings-out-the-best-in-students" target="_blank"><strong>How Gamifying Education Brings Out the Best In Students</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5 Cybersecurity Tips For Schools From CISA’s Deputy Assistant Director ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/5-cybersecurity-for-schools-from-cisas-deputy-assistant-director</link>
                                                                            <description>
                            <![CDATA[ Making quick cost-effective changes to cybersecurity systems can make a big difference for school safety, says CISA Deputy Assistant Director Trent Frazier. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ENFNhBFfD7rfZFf2Dnou6A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hW4BcLWsoRyyPueUaoJo2C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Jun 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 19:18:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp; Learning contributor. A journalist, &lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology can make that more effective. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hW4BcLWsoRyyPueUaoJo2C-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Pete Linforth from Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A shield with curved lines behind it.]]></media:description>                                                            <media:text><![CDATA[A shield with curved lines behind it.]]></media:text>
                                <media:title type="plain"><![CDATA[A shield with curved lines behind it.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hW4BcLWsoRyyPueUaoJo2C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity attacks on schools across the U.S. are increasing in frequency. </p><p>“They are a target-rich but resource-poor environment that really houses incredibly sensitive information about some of our most vulnerable populations,” says Trent Frazier, Deputy Assistant Director of The Cybersecurity and Infrastructure Security Agency (CISA), a component of the U.S. Department of Homeland Security. </p><p>When these attacks are successful and <a href="https://www.techlearning.com/news/hackers-are-after-student-data-heres-why" target="_blank"><u><strong>student data becomes compromised</strong></u></a>, it can be held for ransom but is also doubly valuable to cyber criminals because students generally have pristine credit records and are not worried about identity theft. </p><p>Cybersecurity is now the <a href="https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert" target="_blank"><u><strong>No. 1 concern among school leaders</strong></u></a>. However, the good news is that there are simple and inexpensive steps that can be taken that will have a huge positive impact on cybersecurity, Frazier says. He offers the following cybersecurity tips.  </p><h2 id="1-don-t-get-overwhelmed">1. Don’t Get Overwhelmed  </h2><p>When they hear about the rising number of cyber attacks, those untrained in cybersecurity can get the mistaken sense that there’s nothing to be done. </p><p>“They view this as an almost insurmountable challenge, that to take on cyber security means getting a second degree and becoming a cybersecurity professional,” Frazier says. </p><p>In reality, the most effective forms of cyber protection are generally simple, common sense, good cybersecurity best practices with which most of us are already familiar. He notes that while there are more complex attacks occurring, the majority are still simple efforts that involve basic tasks, such as cracking a weak password. </p><p>By removing the low-hanging fruit in cybersecurity systems, schools can really beef up their protections. “If we're taking steps to address those things, we're making it harder for our adversaries and forcing them to go to the much more challenging, and frankly much more expensive, types of attacks across all of our infrastructure communities,” he says.  </p><h2 id="2-do-the-little-things">2. Do The Little Things </h2><p>Keeping with the idea that small steps can have a big impact on cybersecurity, Frazier points to <a href="https://www.cisa.gov/secure-our-world" target="_blank"><u><strong>Secure Our World,</strong></u></a> a recent PSA developed by CISA aimed at schools and other organizations that offers four easy-to-implement tips:</p><ul><li>Recognize and report phishing</li><li>Use strong passwords</li><li>Turn on multifactor authentication</li><li>Update software</li></ul><h2 id="3-utilize-cisa-resources">3. Utilize CISA Resources  </h2><p>District technology leaders should be aware that there are many CISA resources for schools. </p><p>“We have regional staff throughout the country that can assist you in assessing vulnerabilities within your system,” Frazier says. </p><p>These staff members can help school leaders prioritize and plan how to best invest in and build more robust cybersecurity systems. “We've developed what we call our <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" target="_blank"><u><strong>Cybersecurity Performance Goals</strong></u></a>, which is really a tool that's essential in helping to prioritize where you want to make investments, and then ultimately start to make those investments, and grow over time,” Frazier says. </p><p>Additionally, CISA has its <a href="https://www.cisa.gov/K12Cybersecurity" target="_blank"><u><strong>Cybersecurity for K-12 Education</strong></u></a> resource, which offers a variety of tips for schools. “Applying those two resources and engaging with our folks is going be a really important tool to help you identify what the long-term sustainable approach to the program that you need to design ultimately will look like," Frazier says. </p><h2 id="4-consider-adding-a-full-time-cybersecurity-resource">4. Consider Adding a Full-Time Cybersecurity Resource </h2><p>A recent <a href="https://www.cosn.org/cosn-news/cybersecurity-remains-k-12-edtech-leaders-no-1-priority-in-2023/" target="_blank"><strong>CoSN report</strong></a> found that 66% of K-12 districts do not have a full-time cybersecurity resource. </p><p>Adding this type of full-time staff member is a step districts should consider, but it’s not always about hiring someone new. Often, existing IT staff members can be trained in the fundamentals of good cybersecurity. </p><p>“Once you do that, those individuals can oftentimes make a lot of progress in helping you build the basics of your cybersecurity program,” Frazier says. “Once you've reached a certain posture, then it becomes meaningful to start to look for the more highly credentialed cybersecurity professionals who are going to be able to in implement even more advanced mitigation measures within your program.” </p><p>But, once again, schools don't have to undertake this process alone. “I highly encourage both schools and school districts to think about where they can partner with local government and state government agencies who may be able to also provide them with capabilities," Frazier says. </p><h2 id="5-cybersecurity-is-a-team-sport">5. Cybersecurity Is A Team Sport</h2><p>Frazier says it's also important for school leaders to realize cybersecurity is everyone’s responsibility, and that includes students, staff, teachers, and parents. </p><p>“Oftentimes someone will say, ‘Well, that's the IT Department's problem,' or, 'That's the state's problem or the Federal Government's problem,' or, 'It's the service provider's problem.' It's really critical that schools understand cybersecurity is entirely a team sport,” Frazier says. “No one is capable of adequately defending [alone] from all of the various threats that we see today. It has to be integrated and we all have our part to play.” </p><ul><li><a href="https://www.techlearning.com/news/hackers-are-after-student-data-heres-why" target="_blank"><strong>Hackers Are After Student Data. Here’s Why</strong></a></li><li><a href="https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert" target="_blank"><strong>5 Cybersecurity Tips from CoSN’s CEO and a Digital Security Expert</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 3 Modern Challenges Facing District IT Leaders ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/3-modern-challenges-facing-district-it-leaders</link>
                                                                            <description>
                            <![CDATA[ During this recent webinar sponsored by Linewize, the focus was on how to handle critical IT issues that school districts are facing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bSs8BNUSy5fvGagCaUc8nN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FUeo7LdfKtFhL5qmM7ynyF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 May 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 12 Nov 2024 16:18:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ray Bendici ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FUeo7LdfKtFhL5qmM7ynyF-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Linewize webinar]]></media:description>                                                            <media:text><![CDATA[Linewize webinar]]></media:text>
                                <media:title type="plain"><![CDATA[Linewize webinar]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FUeo7LdfKtFhL5qmM7ynyF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the rise of innovations such as generative AI, IT leaders face increasingly complex challenges in the effort to protect student safety and digital wellbeing. </p><p>During a recent webinar presentation sponsored by Linewize, Logan Joiner, Network Analyst for Richland School District in Washington, and Terrisa Reeves, Territory Directory for Linewize, discussed exploring practical solutions and empowering IT teams for success in the evolving world of edtech.</p><p>The discussion delved into how IT leaders can address challenges including the need for granularity in filtering, parental concerns and support, and the impact of generative AI tools to student safety.</p><p><a href="https://webinars.smartbrief.com/on-demand/2093/3-modern-challenges-facing-district-it-leaders/" target="_blank" rel="nofollow"><u><strong>Watch the webinar on demand</strong></u></a></p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/hgBAAIcYBLg" allowfullscreen></iframe></div></div><h2 id="key-takeaways-2">Key Takeaways</h2><p>Currently, K-12 IT leaders everywhere are being asked to meet a host of increasingly complex challenges in the effort to protect student safety and digital wellbeing. </p><p>“One challenge we all face today is the capacity of our technology to address these growing needs,” said Reeves.</p><p>In particular, Reeves said that three challenges IT leaders are facing include:</p><p><strong>1. Granularity and flexibility in filtering</strong> - In this area of challenge, Reeves cited new sites popping up everyday, VPNs and proxies, legacy URL filtering, and filtering distractors as a few key pain points. </p><p>“It’s like Whack-a-mole to keep up with students who are using VPNs and proxies to get around filters,” said Reeves. </p><p>Joiner discussed how much of his day is spent monitoring Linewize for these situations, and then using the tools at his disposal to handle any issues.</p><p>“We’re allowing parents to be involved, but we’re enabling districts to manage the process,” said Reeves.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1713px;"><p class="vanilla-image-block" style="padding-top:45.53%;"><img id="FzRg97BupTTPCxEdHVe5TX" name="" alt="linewize webinar" src="https://cdn.mos.cms.futurecdn.net/FzRg97BupTTPCxEdHVe5TX.jpg" mos="" align="middle" fullscreen="" width="1713" height="780" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p><strong>2. Parental engagement & partnership </strong>- “Our parents are seeking to be more active and have more control over what their children are accessing online,” said Reeves. “We want to put safeguards in place.” </p><p>Reeves noted that within this area, the focus is on involving parents/guardians in keeping students safe online, parents actively wanting support from schools, and how schools are seeking better ways to communicate with parents.</p><p>“It’s as simple as parents want to know,” said Joiner, who added that he and his team worked with Linewize to build a great communication plan for connecting with families. </p><p><strong>3. The rise of generative AI</strong> - “Districts across the country are taking different stances on how they’re managing generative AI,” said Reeves, noting that the main challenges are striking a balance with AI, understanding that not all AI tools are the same, and exploring the need for AI strategy.</p><p>Logan discussed how his district only allows AI at the high school level, noting that teachers can use Linewize tools to block AI as they see fit. “Our district goal is to build good digital citizenship with students and teach them how to use tools the right way,” he said.</p><p>Reeves and Joiner then discussed the full Linewize ecosystem of digital school safety tools.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:826px;"><p class="vanilla-image-block" style="padding-top:53.51%;"><img id="xaYjY8cWjYnAXms9CiMThg" name="" alt="The Linewize ecosystem" src="https://cdn.mos.cms.futurecdn.net/xaYjY8cWjYnAXms9CiMThg.jpg" mos="" align="middle" fullscreen="" width="826" height="442" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Linewize)</span></figcaption></figure><p>For more information, visit <a href="https://www.linewize.com/" target="_blank" rel="nofollow"><u><strong>Linewize</strong></u></a><strong>.</strong></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI, Absenteeism, Cybersecurity, and More at the Tech & Learning Regional Leadership Summit in New England ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/ai-absenteeism-cybersecurity-and-more-at-the-tech-and-learning-regional-leadership-summit-in-new-england</link>
                                                                            <description>
                            <![CDATA[ Forward-thinking educators collaborated during a day of information sharing, fact finding, and a bit of entertainment at the Tech & Learning Summit in Boston. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x4CSYbKoH6Ka98NdcHRwFb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y3tmuhCbWGcPQAWVv5DQHe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 May 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Sat, 19 Oct 2024 15:10:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Millington ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/X8Ab6Hyhv3eKDWCduzWcvU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Michael Millington is a senior staff writer for Tech &amp;amp; Learning. A writer and editor with over a decade of experience, his focus on bringing actionable information to those in need is the driving force behind his work. When not researching new advancements in technology, Michael likes to practice his Italian and train his dog Cyril.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y3tmuhCbWGcPQAWVv5DQHe-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Educators, experts, and professionals from across the country gathered at the Tech &amp; Learning Summit in New England]]></media:description>                                                            <media:text><![CDATA[Educators, experts, and professionals from across the country gathered at the Tech &amp; Learning Summit in New England]]></media:text>
                                <media:title type="plain"><![CDATA[Educators, experts, and professionals from across the country gathered at the Tech &amp; Learning Summit in New England]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y3tmuhCbWGcPQAWVv5DQHe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Tech & Learning Regional Leadership Summit is a unique opportunity for educators from various backgrounds to come together for a collective purpose: to find uncommon solutions to common challenges. Educational leaders not only have the chance to network as well as innovate and create solutions, they also are given a voice to share strategies they have tried in their schools or districts. </p><p>The Connors Center in Dover, Massachusetts, provided a beautifully lush backdrop of trees and grass that held fast against the ongoing conversation between educators, edtech partners, and other attendees about the advent of technology in schools. As part of a professional learning experience, those in attendance were tasked with creating an action plan based on the various activities they would take part in throughout the day.</p><h2 id="getting-our-feet-wet">Getting Our Feet Wet </h2><p>Throughout the summit, there was a concentrated focus on AI, which was bolstered by a fearless and entertaining introduction made by Carl Hooker, the emcee for the event. After being split into teams, attendees were tasked with coming up with a two-minute presentation that encapsulated one action plan to be incorporated in the next school year. </p><p>Throughout the day, while some attendees made time for one-on-one meetings with vendor partners, others participated in roundtable discussions based on common educational challenges that were facilitated by experts in multiple fields. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3024px;"><p class="vanilla-image-block" style="padding-top:54.99%;"><img id="6Ds4EhCf7oozzynz3tCUkU" name="" alt="The Summit was hosted by the irrepressible Carl Hooker" src="https://cdn.mos.cms.futurecdn.net/6Ds4EhCf7oozzynz3tCUkU.jpg" mos="" align="middle" fullscreen="" width="3024" height="1663" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">The Summit was hosted by the irrepressible Carl Hooker </span><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>The roundtable talks covered subjects that impacted educators, students, and parents, and included:</p><ul><li>AI Media and Literacy</li><li>Personalized Learning Coaching</li><li>Creating a Personal Wellness Plan</li><li>Integrating Technology into the MTSS Structure</li><li>PD In the Age of AI</li><li>Addressing Chronic Absenteeism</li><li>Data Privacy and Cybersecurity</li></ul><h2 id="chronic-absenteeism-prevention">Chronic Absenteeism Prevention </h2><p>An in-depth conversation about chronic absenteeism was led by Michael Hale, Director of College, Career, and Citizenship at Casco Bay High School in Portland, ME. Hale divulged the alarming rate at which high school students who miss school regularly are prone to miss graduation: 30%! Hale also elaborated on other potential detrimental effects of chronic absenteeism, such as diminished health and low future employment prospects.</p><p>In order to address the issue of chronic absenteeism, Hale discussed how his district employs  a multi-tiered support system designed to help and incentivize regular attendance for students. The system involves support, prevention, and intervention if necessary, designed to help eliminate obstacles keeping students from attending school.</p><h2 id="implementing-ai-across-a-district">Implementing AI Across a District</h2><p>Kerry Gallagher, Assistant Principal of Teaching and Learning for St. John's Prep in Danvers, MA, and Kelley Papa, Instructional Coach at St. John’s Prep, discussed how their district prepared a comprehensive plan to integrate artificial intelligence in a way that helps foster an accepting culture among students, teachers, and parents. The process acts as a cycle that will constantly gauge the opinions of all participants to know what direction to take with AI. </p><p>Gallagher presented an action plan that worked with existing school policy. The plan is designed to evolve as the needs of the students and educators evolve. The main idea behind the process is not only to educate students, teachers, and parents on the potential of AI, but also to demystify AI from the established reputation it garnered through early media coverage. Approaching AI with understanding makes its use more palatable, and Gallagher and Papa have paved the way for a roadmap for the ever-changing landscape AI in education.</p><h2 id="gamifying-schools-looking-forward-to-what-s-cool">Gamifying Schools, Looking Forward to What’s Cool </h2><p>Dan Ryder, Director of Design and Innovation for Community Regional Charter School, presented a game-based and human-centered problem-solving model to help reimagine how to tackle educational challenges. The presentation was accompanied by a brief activity in which participants divided groups of two, learned about game-play styles, and ultimately, each created a game that their partner would enjoy playing.</p><p>After the presentation, attendees were given the opportunity to get an advanced look at cutting-edge technology companies. This provided some quality time with industry innovators to get a glimpse of what the future of educational technology could look like.</p><h2 id="artificial-amateurs-are-absolutely-amazing">Artificial Amateurs are Absolutely Amazing </h2><p>Once the day reached its final moments, the original teams organized at the beginning of the summit reconvened and, equipped with the knowledge gained throughout the day, created endearing proposals for introducing AI to a school. Some groups had used AI tools to craft and sing  unique songs about the benefits of students and teachers using AI. Other groups used AI to create artworks to emphasize the helpfulness of artificial intelligence. </p><h2 id="innovative-and-celebrated">Innovative and Celebrated </h2><p>After the team presentations, Tech & Learning recognized the innovative leaders in attendance for their achievements. The <a href="https://www.techlearningevents.com/regionalsummits/awards" target="_blank"><strong>Innovative Leader Award</strong></a> winners were:</p><p>Innovative District Instructional Tech Specialist: <strong>Russell Levendusky</strong></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3024px;"><p class="vanilla-image-block" style="padding-top:82.94%;"><img id="abqnvtVEzkz4WoP3GDziTB" name="" alt="Russell Levendusky" src="https://cdn.mos.cms.futurecdn.net/abqnvtVEzkz4WoP3GDziTB.jpg" mos="" align="middle" fullscreen="" width="3024" height="2508" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Innovative Director of Design and Innovation: <strong>Dan Ryder</strong></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3024px;"><p class="vanilla-image-block" style="padding-top:79.30%;"><img id="yRhneFMSUvHodiMBYEAKWo" name="" alt="Dan Ryder" src="https://cdn.mos.cms.futurecdn.net/yRhneFMSUvHodiMBYEAKWo.jpg" mos="" align="middle" fullscreen="" width="3024" height="2398" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Innovative Assistant Principal: <strong>Kerry Gallagher </strong></p><p> Best Example of Virtual Learning: <strong>Jacqueline Gardy </strong></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3024px;"><p class="vanilla-image-block" style="padding-top:58.93%;"><img id="9fqpn2D3Fzhm3AFmNbwAPh" name="" alt="Jacqueline Gardy" src="https://cdn.mos.cms.futurecdn.net/9fqpn2D3Fzhm3AFmNbwAPh.jpg" mos="" align="middle" fullscreen="" width="3024" height="1782" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Tech & Learning <a href="https://www.techlearningevents.com/RegionalSummits" target="_blank"><strong>Regional Leadership Summits</strong></a> offer a wonderful opportunity to collaborate with passionate educators from across the nation. Whether organizing unique solutions to complex and ongoing challenges, or being on the cutting edge of the edtech space, the connections made and time spent here become indispensable in helping to further educational endeavors for students, teachers, and parents. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How Schools Should Reassess Cybersecurity Due to AI ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/how-schools-should-reassess-cybersecurity-due-to-ai</link>
                                                                            <description>
                            <![CDATA[ As AI grows in the educational space, more adaptive security measures are needed to protect students and teachers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a4AnqkAku6kGgAKE7n7mGj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9ZWAHoVYdFaqjACVC6km7f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 May 2024 09:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 13 May 2024 23:58:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Millington ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/X8Ab6Hyhv3eKDWCduzWcvU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Michael Millington is a senior staff writer for Tech &amp;amp; Learning. A writer and editor with over a decade of experience, his focus on bringing actionable information to those in need is the driving force behind his work. When not researching new advancements in technology, Michael likes to practice his Italian and train his dog Cyril.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9ZWAHoVYdFaqjACVC6km7f-1280-80.jpg">
                                                            <media:credit><![CDATA[Pexels.com]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity]]></media:description>                                                            <media:text><![CDATA[Cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9ZWAHoVYdFaqjACVC6km7f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It is no secret that artificial intelligence is slowly permeating all aspects of society. Education is no outlier, with both students and teachers finding ways to implement AI into the classroom. Students have been using it to help spur their creativity in many subjects, while teachers are finding new ways to have AI supplement and even write lesson plans. </p><p>With the push to integrate AI in schools, questions may arise about how safe it is to use AI platforms, especially with children involved. While it is scary to think about potential threats that may crop up due to AI, there are also ways to help mitigate the impact or prevent it altogether.</p><h2 id="how-vulnerable-are-students-and-teachers">How Vulnerable Are Students and Teachers?</h2><p>More connected devices are being used in schools, and that can create multiple entry points for cyber attacks. AI platforms make those entry points harder to lock down.</p><p>Shad McGaha, Chief Technology Officer for Belton ISD in Texas, believes that cyber criminals are inevitably growing alongside AI.</p><p>“Cybercriminals are themselves utilizing AI to create advanced malware, highly targeted phishing campaigns, and social engineering tactics that are harder to spot,” McGaha says. “These AI-augmented attacks require a more robust defense.”</p><p>Schools are veritable treasure troves of information for students and teachers, and McGaha states that cyber criminals are evolving with their technology while average individuals don’t know enough about how to protect themselves from cyber attacks.</p><h2 id="why-cybersecurity-is-important-in-education">Why Cybersecurity is Important in Education</h2><p>With the increasing amount of ways AI can be used in education, keeping sensitive information protected is of equal importance. Personal information is valued highly by businesses and individuals, and AI can create pathways to this information in ways that we have yet to consider. However, implementing AI to help combat cybersecurity threats can help keep such information safe, such as an evolving antivirus program set to discover and deal with new threats.</p><p>Schools may soon consider hiring AI specialists to help mold the infrastructure of the institution to better serve students and teachers. Having a professional who is dedicated to teaching an AI platform to look for, identify, and eliminate virtual threats, can help save schools money and time.</p><p>On a smaller scale, AI may also be used to monitor student interaction and behavior. More students are connected with social media than ever before, and this can lead to unwanted forms of communication such as cyberbullying. AI programs may be able to help students understand how to navigate these situations by providing them with examples of what to do when faced with bullying. </p><h2 id="how-to-improve-cybersecurity-in-schools-in-regards-to-ai">How to Improve Cybersecurity in Schools in Regards to AI </h2><p>McGaha suggests that there are various ways we can focus on cybersecurity in our schools, and AI can be a partner in that.</p><p>“AI can surpass traditional rule-based security systems by analyzing huge volumes of network and user data for anomalies that could signal a breach attempt,” he says. “It learns to detect even new types of attacks with more speed and accuracy.”</p><p>AI can also react faster than a human to an attack. “AI-driven systems don't just detect threats, they can automatically take actions to contain them,” says McGaha. “This could mean isolating infected devices, quarantining suspicious files, or alerting IT staff in real time. Speed is key in preventing a minor incident from escalating into a full-blown security crisis.”</p><p>Another point of focus is to improve threat response when incidents happen.</p><p>“Consider how AI can enhance detection speed and automated response actions,” MdGaha says. “Define clear incident escalation procedures that include both IT staff and AI tools. Data backup, offline storage. … Ensure essential data has secure backups that are isolated from the main network should a compromise occur.”</p><p>Protecting our students from cyber breaches and other digital threats is <a href="https://www.k12dive.com/news/student-data-privacy-bills-house-hearing/713582/?utm_source=Sailthru&utm_medium=email&utm_campaign=Issue:%202024-04-18%20K-12%20Dive%20%5Bissue:61234%5D&utm_term=K-12%20Dive" target="_blank"><u><strong>more important than ever</strong></u></a>. Now, with an ever growing amount of tech in our schools, having a cybersecurity specialist that can navigate AI will be critical to protect teachers and students while keeping the focus on education.</p><ul><li><a href="https://www.techlearning.com/news/creating-a-comprehensive-cybersecurity-plan-for-schools" target="_blank"><strong>Creating A Comprehensive Cybersecurity Plan For Schools</strong></a></li><li><a href="https://www.techlearning.com/how-to/cybersecurity-in-the-classroom-what-teachers-can-do" target="_blank"><strong>Cybersecurity in the Classroom: What Teachers Can Do</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers Are After Student Data. Here’s Why  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/hackers-are-after-student-data-heres-why</link>
                                                                            <description>
                            <![CDATA[ Students generally have pristine credit records, which makes student data an appealing target for criminals. The good news is, there are ways they can help keep student data safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eqF6nzqZkpZvQoxnNadSwJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9z4beus3uc2atDZdpg6dwi-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 May 2024 09:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp;amp; Learning&#039;s senior staff writer. A journalist,&amp;nbsp;&lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and educator, his work has appeared in the Washington Post, The Atlantic, and Associated Press. He currently teaches at&amp;nbsp;Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology&amp;nbsp;can make that more effective.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/9z4beus3uc2atDZdpg6dwi-1280-80.png">
                                                            <media:credit><![CDATA[Image by Mohamed Hassan from Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An illustration of a computer hooked by a phishing line indicating someone has fallen victim to a phishing cyberattack.]]></media:description>                                                            <media:text><![CDATA[An illustration of a computer hooked by a phishing line indicating someone has fallen victim to a phishing cyberattack.]]></media:text>
                                <media:title type="plain"><![CDATA[An illustration of a computer hooked by a phishing line indicating someone has fallen victim to a phishing cyberattack.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9z4beus3uc2atDZdpg6dwi-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When people think about student data at K-12 schools being compromised, they tend to envision things such as test scores and grades being shared publicly. </p><p>While that type of information getting out is unfortunate, it’s minor compared to other problems a data breach can cause students. </p><p>“What has surprised people is that students themselves can be valuable targets for financial reasons,” says Doug Levin, co-founder and national director of the K12 Security Information eXchange, a nonprofit dedicated to protecting K-12 schools from emerging cybersecurity threats. </p><p>“Students, particularly younger students, have pristine credit and tax records,” he says, which make an enticing target. </p><p>This also makes students especially vulnerable to identity theft crimes that can occur after a school becomes the victim of a successful cyberattack. The value of student personal data is part of the reason school cyberattacks are increasingly common. In one 2023 survey of school IT leaders, <a href="https://assets.sophos.com/X24WTUEQ/at/j74v496cfwh4qsvgqhs4pmw/sophos-state-of-ransomware-education-2023-wp.pdf" target="_blank"><u><strong>80% said their school was hit by ransomware attacks in the past year</strong></u></a>. </p><p>School IT leaders have devoted greater resources and efforts to preventing these attacks with staff training and more stringent security requirements, such as two-factor authentication. But the dangers an attack poses to students, and the role students need to play in order to help protect school networks, still isn’t always fully appreciated, Levin says. </p><h2 id="why-cyber-criminals-target-student-data">Why Cyber Criminals Target Student Data  </h2><p>In addition to pristine credit records, students are at greater risk when their identities are stolen because nobody checks their spending activity. </p><p>“They don't have anyone watching their credit records, and as a result, they can end up being abused for years until a student maybe applies for a college loan or tries to rent an apartment or buy a car,” Levin says. “Unfortunately, we have seen instances with students as young as first grade being subject to identity theft arising directly from a school cyber security incident.” </p><h2 id="multiple-ways-for-student-data-to-be-compromised">Multiple Ways For Student Data to Be Compromised  </h2><p>Just because a school network requires two-factor authentication for staff, it doesn’t mean that its network is safe from hackers. Even though student accounts don’t have the same rights and privileges as teacher and staff login accounts, there have been instances in which educators have unintentionally shared sensitive student data in environments that students can access, which can poise major risks, Levin says. </p><p>“If a threat actor was able to guess or somehow get the login information for a student account, they are able to then get to sensitive data and exfiltrate it, and either abuse that information or try to extort the school district to keep it from being abused,” he says. </p><p>Another way student data can become compromised is through scams that target students directly. </p><p>“One of the more frequent ones we've seen has been fake employment offers,” Levin says. These often take the form of a great job offer that is contingent on the student providing various forms of personal information for processing purposes. When students fall for this, their personal data can be compromised.  </p><h2 id="how-students-can-help-protect-their-own-data">How Students Can Help Protect Their Own Data </h2><p>“People have started to realize that educating staff about phishing scams and raising their cybersecurity awareness is important because the way so many of these attacks against school systems are successful is via phishing employees,” Levin says. “But students themselves are potentially a vector for these sorts of attacks against school districts and they're also at risk themselves, and this highlights that they need to be an audience for these trainings themselves.” He adds this training should happen at a young age for students as children are getting online earlier and earlier. </p><p>Levin also makes it clear that he doesn’t believe protecting student data should be up to schools alone. Edtech companies should provide more data protection for all student-facing products out of the box, he says, “so we don’t need more expensive licenses to get core security features that we need to protect our school communities.”  </p><p>In general, education also needs more funding to address cybersecurity and student data privacy concerns. </p><p>“Schools do need more resources and support and help from state and also the federal government,” Levin says. “It's important that folks understand this isn't an individual school system issue. This is a sector-wide issue, and we really need more support and help from the government.” </p><ul><li><a href="https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert" target="_blank"><strong>5 Cybersecurity Tips from CoSN’s CEO and a Digital Security Expert</strong></a></li><li><a href="https://www.techlearning.com/news/school-cyberattacks-how-the-fbi-works-to-protect-school-districts" target="_blank"><strong>School Cyberattacks: How the FBI Works to Protect School Districts</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Creating A Comprehensive Cybersecurity Plan For Schools ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/creating-a-comprehensive-cybersecurity-plan-for-schools</link>
                                                                            <description>
                            <![CDATA[ How Belton ISD in Texas created a comprehensive cybersecurity plan under CTO Shad McGaha ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AbmisdYSGQv8mVy6iQp6zM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5XfxmAk6D2funZGbJARGtA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Mar 2024 09:00:55 +0000</pubDate>                                                                                                                                <updated>Mon, 15 Jul 2024 18:01:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp;amp; Learning contributor. A journalist,&amp;nbsp;&lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at&amp;nbsp;Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology&amp;nbsp;can make that more effective.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5XfxmAk6D2funZGbJARGtA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity plan]]></media:description>                                                            <media:text><![CDATA[Cybersecurity plan]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity plan]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5XfxmAk6D2funZGbJARGtA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Shad McGaha, Chief Technology Office for Belton ISD in Texas, has a simple principle that guides the work that he and his technology staff do in the district. </p><p>“Anything affecting education in our classrooms takes top priority,” he says. This mantra served as McGaha’s north star as he implemented a district-wide cybersecurity plan that includes regular staff training and more secure storage solutions. For this and other efforts, McGaha was recently honored with an Innovative CTO Award as part of Tech & Learning’s <a href="https://www.techlearningevents.com/innovativeleaderawards/home?ref=CW" target="_blank"><u><strong>Innovative Leader Awards</strong></u></a> during the <a href="https://www.techlearningevents.com/RegionalSummits" target="_blank"><strong>Regional Leadership Summit</strong></a> in Baltimore.</p><p>McGaha was drawn to education due to a longtime love of working with kids. “From my early days as a camp counselor to volunteering at Sunday school, I found joy in helping young minds grow,” he says. “During college, I landed a job at the afterschool program in my local YMCA, where I continued to learn and contribute. While I knew teaching wasn’t my calling, I discovered another passion: technology. Computers, networks, and electronics fascinated me. So, I pursued a degree in Business Computer Information Systems. After graduating, my first role was as a desktop technician at a local school. Over time, I climbed the ladder.” </p><p>He adds, “What brings me the greatest fulfillment is knowing that our daily work directly impacts the teachers and students in our district.” </p><p>Below McGaha shares the strategies that have made Belton ISD’s district-wide cybersecurity plan so successful. </p><h2 id="building-a-comprehensive-cybersecurity-plan-for-schools-phishing-awareness-campaigns-and-staff-training">Building a Comprehensive Cybersecurity Plan for Schools: Phishing Awareness Campaigns and Staff Training </h2><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1915px;"><p class="vanilla-image-block" style="padding-top:130.55%;"><img id="cMuKShru8BH2KsvYXc3N3Y" name="Shad McGaha Headshot 23 (2).jpg" alt="A headshot of Shad McGaha he is wearing a dress shirt and tie." src="https://cdn.mos.cms.futurecdn.net/cMuKShru8BH2KsvYXc3N3Y.jpg" mos="" align="right" fullscreen="" width="1915" height="2500" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shad McGaha)</span></figcaption></figure><p>One of McGaha's first initiatives focused on threat identification. “We implemented regular phishing awareness campaigns to educate all staff members about recognizing and avoiding phishing attempts,” McGaha says. “Additionally, comprehensive training sessions were conducted to enhance their cybersecurity awareness.” </p><p>Rather than being one and done, these efforts are ongoing. “We prioritize continuous education and training by conducting workshops, webinars, and awareness campaigns for staff, students, and parents,” he says. “Robust password policies encourage strong, unique passwords and multifactor authentication. Regularly applying security patches keeps our systems up-to-date.” </p><h2 id="staffing-study-incident-response-plan-and-more">Staffing Study, Incident Response Plan, and More </h2><p>Early in the process, McGaha conducted a thorough staffing study to assess the adequacy of the current network staff. “This analysis helped identify any gaps or areas for improvement in our cybersecurity team,” he says. </p><p>He then collaborated with that team to develop a detailed incident response plan that outlines clear procedures for handling security incidents promptly and effectively. He also looked beyond the district for additional support.</p><p>“We engaged a consultant who worked closely with us to create a comprehensive cybersecurity plan. This plan addresses risk management, threat mitigation, and proactive measures,” McGaha says. </p><h2 id="secure-data-storage">Secure Data Storage</h2><p>McGaha and his team recognized the need to replace outdated backup hardware and software. “As part of our upgrade, we invested in Dell hardware, known for its reliability and performance,” he says. “Our choice for backup software fell on Rubrik, a robust solution that offers efficient data protection and management. Rubrik not only streamlines backups but also provides seamless integration with cloud storage.”</p><p>This integrated approach adds an extra layer of protection. “By combining these upgrades, we’ve significantly bolstered our storage system’s security, ensuring data integrity and availability,” he says. </p><h2 id="data-privacy-agreement-standardization">Data Privacy Agreement Standardization </h2><p>Data privacy is increasingly important given how many learning apps are used. McGaha’s cybersecurity plan recognizes this. </p><p>“We established a standard data privacy agreement for all software used within our district. This ensures that privacy and data protection are prioritized consistently across applications and platforms,” he says. </p><p>In addition, the district established a software vetting committee responsible for examining any new software proposed for use within the district. “This process ensures that only secure and reliable tools are adopted,” McGaha says. </p><h2 id="more-on-this-vetting-process-for-new-tools">More On This Vetting Process for New Tools </h2><p>The process of vetting new technology is comprehensive. “First, we conduct a needs assessment to understand specific educational goals and challenges,” McGaha says. “Next, we meticulously research and evaluate potential solutions, considering factors like functionality, ease of use, and support. Security and data privacy are top priorities, ensuring compliance with relevant regulations.” </p><p>Once a tool passes through this phase, the district pilots the technology with features, gathering feedback on usability and impact. “Finally, we carefully weigh the costs and benefits, assessing the technology’s long-term viability,” McGaha says. “Establishing a feedback loop ensures continuous improvement, enhancing teaching and learning experiences.” </p><ul><li><a href="https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert" target="_blank"><strong>5 Cybersecurity Tips from CoSN’s CEO and a Digital Security Expert</strong></a></li><li><a href="https://www.techlearning.com/news/school-cyberattacks-how-the-fbi-works-to-protect-school-districts" target="_blank"><strong>School Cyberattacks: How the FBI Works to Protect School Districts</strong></a></li><li><a href="https://www.techlearning.com/how-to/4-cybersecurity-tips-for-schools" target="_blank"><strong>4 Cybersecurity Tips for Schools</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5 Quick Tips for Backing Up Your School Data ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/5-quick-tips-for-backing-up-your-school-data</link>
                                                                            <description>
                            <![CDATA[ Practical advice for backing up to protect your data from cyber attacks or technical mishaps ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o46MqBN436dzD4CmKgkKU8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oEfhMgeZ84EhEhas9HDAo4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Feb 2024 10:00:30 +0000</pubDate>                                                                                                                                <updated>Wed, 21 Feb 2024 16:08:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Baule ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Steve Baule served as a technology director, high school principal, and superintendent for 20+ years in K-12 education. He is currently the director of Winona State University’s online educational doctorate program in Minnesota.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oEfhMgeZ84EhEhas9HDAo4-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[backing up data]]></media:description>                                                            <media:text><![CDATA[backing up data]]></media:text>
                                <media:title type="plain"><![CDATA[backing up data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oEfhMgeZ84EhEhas9HDAo4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the upswing in hacking and ransomware attacks on schools and other educational institutions, it is essential for educators to ensure their data is secure. As some school districts have seen significant data loss due to such activities, such preparation minimizes risks that no one can afford. </p><p>Problems with ransomware attacks and corrupted cloud accounts have also seen several of my colleagues lose data. It’s distressing and often can be costly to recover.</p><p>Educators should consider the following for backing up their data:</p><h2 id="5-quick-tips-for-backing-up-your-school-data">5 Quick Tips for Backing Up Your School Data</h2><ol><li><strong>Follow the 3-2-1 rule for data backup</strong>. Have at least three backups of your data, using at least two different media with one offsite. Those backups should be stored in at least two physical locations. For instance, one copy at home and another at the office. Or maybe on external hard drives. A third might be stored on the cloud, either a personal or an institutional account, although remember that cloud accounts are not 100% reliable and should not be your only backup. Backups should also be on at least two different types of media. External hard drives, flash drives, and optical disks are all potential options along with cloud backups. </li><li><strong>If possible, automate the backup process so you don’t have to remember to manually start it</strong>. At the end of each semester or term, it is a wise idea to create a complete backup. Label that backup and set it aside as an archival record for that semester. </li><li><strong>Make sure you invest in high-quality external hard drives for your archival backups</strong>. Many systems include password protection or encryption on the hard drives. Encrypting your data provides an additional layer of protection. If you have large amounts of data, you might want to consider a cloud-based backup service. </li><li><strong>Test your backups</strong>. Make sure each backup is complete and successful by recovering at least a couple of files from each backup. Backups are of no value if one is unable to recover the data. </li><li><strong>Take extra care with any data that includes personally identifiable information (PII)</strong>. One might consider adding password protection to documents including any PII, especially regarding students. </li></ol><p>Implementing a thorough and effective data backup plan is crucial to safeguard your data against loss due to hardware failure, cyberattacks, or accidental deletion. By combining local and off-site backup solutions, automating the backup process, and regularly verifying the integrity of backups, individuals can ensure their data remains secure and recoverable. </p><p>It’s important to evaluate your specific needs and resources to select the most appropriate backup methods and tools. Remember, the goal of a backup strategy is not just to preserve data but to enable efficient recovery when needed, ensuring minimal disruptions to one’s work and personal life.</p><ul><li><a href="https://www.techlearning.com/how-to/6-steps-to-remove-social-security-numbers-from-student-data" target="_blank"><strong>6 Steps to Remove Social Security Numbers from Student Data</strong></a></li><li><a href="https://www.techlearning.com/how-to/how-to-implement-a-systemic-approach-to-student-data-security-and-privacy" target="_blank"><strong>How to Implement a Systemic Approach to Student Data Security and Privacy</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The FTC Is Proposing Updates to COPPA. Here’s What You Need To Know ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/the-ftc-is-proposing-updates-to-coppa-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ COPPA is more than 20 years old and long overdue for an update to better protect students and their data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bGrsxcpL2yWcqkuiyVBUvn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5E7GvbDW7buKLfojt2YQS8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jan 2024 10:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Susan Gentz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/Sb6HUyWq2mCN3HaepFj7VA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5E7GvbDW7buKLfojt2YQS8-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[COPPA]]></media:description>                                                            <media:text><![CDATA[COPPA]]></media:text>
                                <media:title type="plain"><![CDATA[COPPA]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5E7GvbDW7buKLfojt2YQS8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Federal Trade Commission recently announced that it is updating COPPA (Children’s Online Privacy Protection Act). Many of the proposed changes are aimed at better protecting student data by requiring technology providers to take a bigger role in that effort, as well as limiting the ability to monetize student information.</p><p>Data privacy rules are generally outdated. COPPA became law in 2000 and hasn’t been updated since. When enacted, COPPA made it illegal for websites and online services to collect personal information from children under 13 without parents’ verifiable consent.</p><p>This isn’t to say that there are no student data privacy laws on the books since then. In 2016, California passed the <a href="https://fpf.org/wp-content/uploads/2016/03/FPF-Boot-Camp-SOPIPA-Presentation.pdf" target="_blank"><u><strong>Student Online Personal Information Protection Act (SOPIPA)</strong></u></a>, which started an avalanche of student data privacy legislation across the country. Only a year after it took effect, 22 states had adopted all or parts of the law. </p><p>All this to say that student data privacy has played out on a national scale as a big game of chicken. The federal government hasn’t acted, wondering what states will do, and states are looking for guidance from the feds. It’s set up a very interesting landscape for this issue, especially as technology in schools -- especially emerging ones such as AR, VR, and AI – have grown in the classroom. </p><p>Be it state or federal, all laws are outdated for the current edtech landscape in which students and educators operate. This also means it is long past due for an update.</p><h2 id="key-proposed-coppa-updates-xa0">Key Proposed COPPA Updates </h2><p>After the FTC announced it was considering revisions to COPPA, it received more than 175,000 comments in response. Stakeholders included parents, educators, industry members, researchers, and others.</p><p>According to the FTC, here is a recap of the key <a href="https://www.ftc.gov/business-guidance/blog/2023/12/ftc-proposes-enhanced-protections-kids-online-where-do-you-stand" target="_blank"><u><strong>proposed changes</strong></u></a> and what each means: </p><ul><li><strong>Requiring separate opt-in consent for third-party disclosures</strong>. This means that the default settings for edtech platforms and products would automatically be set to “no sharing” for students, and parents would have to specifically opt in to share or allow data to be shared with third-party advertisers. </li><li><strong>Limiting the “support for internal operations” exception</strong>. Currently, edtech companies can collect information if it’s for internal business operations. The FTC wants to limit this going forward, as well as have companies post detailed disclosures on how any collected data is used or shared any with advertisers.</li><li><strong>Limiting companies’ nudging of kids to stay online</strong>. This is pretty straightforward–companies wouldn’t be allowed to use certain COPPA exceptions to send push notifications to encourage kids to keep using edtech products or platforms. This would also include getting parental consent to even send push notifications.  </li><li><strong>Limiting data retention</strong>. The FTC proposal would limit how long edtech companies could retain student data to essentially the time the student is actively using the product or platform, and not do anything with the data afterward. Also data retention policies would have to be clearly disclosed and publicly available. </li><li><strong>Codifying edtech guidance</strong>. As the edtech industry has grown exponentially since COPPA was first enacted, this would formalize FTC guidance and safeguards, such as in cases when schools and districts allow edtech companies to collect student data for school-authorized purposes and not resale to advertisers. </li><li><strong>Increasing accountability for Safe Harbor programs</strong>. This would increase transparency and accountability of COPPA’s Safe Harbor programs, including public disclosure of membership lists. </li><li><strong>Strengthening data security requirements</strong>. This would focus on generally creating more stringent rules and safeguards that edtech companies have to follow when dealing with student data. </li><li><strong>A change to the definition of “personal information” to include biometric identifiers</strong>. This would include protecting students’ biometric information collected by edtech companies, such as thumbprints, facial recognition patterns, retinal scans, etc. </li></ul><p>These proposals all have major implications for districts and providers. For example, codifying edtech guidance is very vague, and how this rule is interpreted and applied could change how schools operate in very big ways. </p><p>These proposed rules are nowhere near finished. In fact, the FTC published the <a href="https://www.federalregister.gov/documents/2024/01/11/2023-28569/childrens-online-privacy-protection-rule" target="_blank"><strong>Notice of Proposed Rulemaking</strong></a>, which incorporates much of the feedback from the initial review process. </p><p>If you are interested in commenting on the proposed rules, file it at  <a href="https://www.regulations.gov/" target="_blank"><strong>https://www.regulations.gov</strong></a> by following the instructions on the web-based form. Write “COPPA Rule Review, Project No. P195404” on any comment. Public comment on the proposed changes must be received by March 11, 2024. </p><h2 id="why-is-the-ftc-leading-proposed-changes-xa0">Why is the FTC Leading Proposed Changes? </h2><p>It is interesting to see the updates to COPPA coming through an agency rather than legislatively. Although not uncommon, it certainly shows a doubt in legislation making it through both Congressional chambers and receiving the President’s signature. Rulemaking is one way to try and update what can be agreed upon while sorting out the more controversial challenges. </p><p>Upon the announcement of FTC changes, Senators Bill Cassidy (R-LA) and Edward Markey (D-MA) released a <a href="https://www.cassidy.senate.gov/newsroom/press-releases/cassidy-markey-release-joint-statement-applauding-proposed-rule-to-update-childrens-privacy-rules/" target="_blank"><u><strong>joint statement</strong></u></a> that applauded the FTC’s proposed updates but also stated that this effort should not be considered a replacement for congressional action. </p><p>The Senators also noted that they wish to quickly pass the Children and Teens’ Online Privacy Protection Act (COPPA 2.0) “to prioritize the well-being of our children,” adding, “Inaction is not an option.” </p><p>The Senate has expressed more interest in student privacy bills, yet none have passed the full Senate or been introduced in the House. The FTC taking this step will likely lead to at least some modernization of privacy rules before Congress can act.</p><ul><li><a href="https://www.techlearning.com/how-to/best-student-data-privacy-practices-for-schools" target="_blank"><strong>Best Student Data Privacy Practices for Schools</strong></a></li><li><a href="https://www.techlearning.com/how-to/5-tips-for-creating-a-data-privacy-day-in-your-school" target="_blank"><strong>5 Tips for Creating a Data Privacy Day in Your School</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Incident Response Plans vs. Disaster Recovery Plans — Are You Prepared? ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/incident-response-plans-vs-disaster-recovery-plans-are-you-prepared</link>
                                                                            <description>
                            <![CDATA[ Having both an incident response plan and a disaster recovery plan is critical for school districts to be prepared for cyber attacks and natural disasters ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qstZRvivewScHJb7PcYAHS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tWymLjf57gw45qEcuc9pvG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Sep 2023 09:00:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sascha Zuger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/gHQk3x9WMA66CvfWv6PdTH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tWymLjf57gw45qEcuc9pvG-1280-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[disaster recovery plan]]></media:description>                                                            <media:text><![CDATA[disaster recovery plan]]></media:text>
                                <media:title type="plain"><![CDATA[disaster recovery plan]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tWymLjf57gw45qEcuc9pvG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>How prepared is your school for the unexpected? A recent high-profile event at the <a href="https://www.techlearning.com/news/white-house-hosts-school-districts-large-and-small-at-event-unveiling-new-k-12-cybersecurity-initiative" target="_blank"><u><strong>White House with K-12 administrators and cybersecurity professionals</strong></u></a> highlighted the importance of protecting schools against ransomware and other hacks. </p><p>Sandra Paul, Director of Information Technology and Operations for the Township of Union Public Schools in New Jersey, discusses incident response plans versus disaster recovery plans and how both can keep students, educators, and their personal information safe while also helping schools to recover from cybersecurity breaches and quickly return to the important business of learning.</p><h2 id="incident-response-plans-vs-disaster-recovery-plans-prepare-for-the-unexpected-xa0">Incident Response Plans vs. Disaster Recovery Plans: Prepare for the Unexpected </h2><p>Cyber threats and attacks on educational institutions are making the news daily. For example, the University of Michigan, which serves 50,000 students, recently faced the challenge of kicking off the fall semester sans internet for several days after having to cut connections following a significant cybersecurity incident. Access to services such as financial aid, research materials, courses, and other resources necessary for a smooth start created a tough environment for everyone. </p><p>These types of cyber attacks are hardly confined to the university level, with more than 120 school districts already suffering ransomware attacks this year, which provoke concerns over private information and put the identities of minors at risk. Private details such as grades, medical records, behavioral information, documented home issues, and financial information are typically compromised. </p><p>Having plans to prepare for and overcome potential risks is key.</p><p>“The primary focus of an incident response plan is a collection of the processes and procedures that a school district follows if there is a cybersecurity breach/incident,” says Paul. “This type of plan is a response to an incident that caused a disruption of business and educational services leading to a disaster. In a disaster recovery plan, the primary focus is business continuity for the school district if there is an interruption of business and education services. This plan is implemented when there is a stoppage or halting of services.”</p><p>This two-pronged approach can reduce risk and give administrators a clear path to finding their way through an incident without wasting precious time formulating a response.</p><p>“Districts need both plans to systematically resolve or prevent technological issues that can be caused by outside and/or inside incidents, including natural disasters,” says Paul.</p><h2 id="disaster-recovery-plan-3-best-practices-xa0">Disaster Recovery Plan: 3 Best Practices </h2><ol><li><strong>Have major stakeholders involved in the development of plans. </strong>By doing so, it creates support and buy-in for the district, and can also prevent any delays when time is of essence. In addition, it ensures communication is clear and understood, as any potential areas of confusion will be hammered out during the plan’s creation. </li><li><strong>Avoid complacency.</strong> Those involved need to keep updated and practice the plan. Coordinated response exercises via simulated scenarios with key personnel in the form of tabletop assessments can offer an opportunity for a walkthrough to see if the plan works and makes sense in real-world conditions. </li><li><strong>Communication is crucial, as is detailed documentation</strong>. Keeping records of results of tabletop assessments can help tweak a plan to be even more effective and usable. Post-incident, clear and specific documentation can help solve issues in the present and prevent future repeat situations. </li></ol><h2 id="pull-together-a-community-and-a-plan-xa0">Pull Together a Community and a Plan </h2><p>Clearly, a response plan for these sort of emergencies requires a specific skill set and background knowledge. CIO/tech directors are trained and keep abreast of the latest development regarding the tools and strategies to keep schools and their students and educators safe. However, the implementation of these plans are not–and should not be–a solo effort. </p><p>“These plans should be developed by CIO/tech directors because there are several resources that will be called upon if any of these plans are to be implemented,” says Paul. “This includes technology service companies, cybersecurity insurance carriers, district security and safety personnel, community emergency management office, district IT, business and administrative personnel, school legal advisors, school board members, etc.” </p><p>As anyone involved in education knows, support for plans not only involves a united front in deciding how emergency scenarios will be handled, but how developing plans and the various aspects within those plans will fit into an often tight budget.</p><p>“These plans require financial and IT equipment resources that will have to be approved by the school board and community members,” notes Paul. </p><p>Smoothing the pathway throughout the process by including all stakeholders can avoid political hiccups that could lead to delays or leave schools vulnerable while points of any plan are debated.</p><h2 id="5-phases-of-the-nist-cybersecurity-framework-xa0">5 Phases of the NIST Cybersecurity Framework </h2><p>The <a href="https://www.nist.gov/" target="_blank"><u><strong>National Institute of Standards and Technology</strong></u></a> has created a framework which can help create an Incident Recovery Plan. </p><ol><li><strong>Identify</strong> — Determine your district’s critical functions and what cybersecurity risks could disrupt those functions. </li><li><strong>Protect </strong>— Define safeguards needed to prioritize the elements necessary to deliver a school’s critical infrastructure services. </li><li><strong>Detect </strong>— Monitor in a continuous manner to quickly discover unusual activities which could be tied to a potential threat. </li><li><strong>Respond </strong>— Once detected, implement measures to accommodate and adjust to the threat or incident without hindering the daily business of learning.</li><li><strong>Recover </strong>— Create a strategic plan to restore systems that might have been compromised or damaged. Consider lessons learned and tweak existing plans to help better protect from future threats.  </li></ol><ul><li><a href="https://www.techlearning.com/news/white-house-hosts-school-districts-large-and-small-at-event-unveiling-new-k-12-cybersecurity-initiative" target="_blank"><strong>White House Hosts School Districts Large and Small at Event Unveiling New K-12 Cybersecurity Initiative</strong></a></li><li><a href="https://www.techlearning.com/news/an-hour-by-hour-account-of-one-districts-cyber-attack-nightmare" target="_blank"><strong>An Hour-By-Hour Account of One District’s Cyber Attack Nightmare</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ White House Hosts School Districts Large and Small at Event Unveiling New K-12 Cybersecurity Initiative ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/white-house-hosts-school-districts-large-and-small-at-event-unveiling-new-k-12-cybersecurity-initiative</link>
                                                                            <description>
                            <![CDATA[ The new White House initiative aims to bolster cybersecurity in the nation’s schools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EfNChrsWrx6Xqrp7cAqEXE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LAUvAHerbEstGiLDHgKMKb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Aug 2023 09:00:50 +0000</pubDate>                                                                                                                                <updated>Mon, 28 Aug 2023 12:15:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon McGoran ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jon McGoran is an author, magazine writer, and freelance editor. He lives outside Philadelphia.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LAUvAHerbEstGiLDHgKMKb-1280-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LAUvAHerbEstGiLDHgKMKb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>First Lady Jill Biden, Secretary of Education Miguel Cardona, and Secretary of Homeland Security Alejandro Mayorkas recently hosted a White House event to highlight a new initiative to bolster cybersecurity in the nation’s schools. They were joined by representatives of government agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), FCC, and the FBI, as well as tech companies, national organizations such as the State Educational Technology Directors Association (SETDA), and school districts large and small. </p><p>Among those in attendance was Frank Pileiro, tech director for the Public Schools of Linwood, New Jersey, a smaller district with roughly 830 students pre-K through eighth grade. "I was really honored. I received a &apos;save the date&apos; email from Erin Mote of Project Unicorn and InnovateEDU. The official invitation from the First Lady came a few days later. I was surprised to be invited -- I’m sure they wanted to have representation from different sized districts,” says Pileiro. “In total, there were about 200 people in the East Room. Including myself, there were only 15 tech directors and CIOs from around the country.”</p><h2 id="coordinating-cybersecurity-efforts-xa0">Coordinating Cybersecurity Efforts </h2><p>The administration’s new cybersecurity initiative includes a proposed three-year pilot program providing up to $200 million to strengthen cyber defenses in K-12 schools and libraries, and the establishment by the U.S. Department of Education of a Government Coordinating Council (GCC) that will coordinate cybersecurity activities, policy, and communications among a broad array of federal, state, local, tribal, and territorial education leaders. <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2023/08/07/biden-harris-administration-launches-new-efforts-to-strengthen-americas-k-12-schools-cybersecurity/" target="_blank"><u><strong>According to a White House statement</strong></u></a>, the GCC aims to foster formal, ongoing collaboration between all levels of government and the education sector in “preparing for, responding to, and recovering from cybersecurity attacks.”   </p><p>Pileiro welcomes this coordinating initiative, citing the many government agencies and departments that can come into play in response to cyber security threats. “There&apos;s just so many layers,” he says. “They need something to coordinate all that, to help them with intelligence and getting information out to us, which they&apos;re really good about. CISA sends out bulletins. They will even go so far that if they see a trend happening, they will pick up the phone and call you, which I think is terrific.”</p><p>Working with the Department of Education, CISA has also released <a href="https://www.cisa.gov/news-events/news/cisa-and-secret-service-release-toolkit-k-12-schools-strengthen-school-safety-reporting-programs" target="_blank"><u><strong>the second in a series of guidance documents to assist educational leaders</strong></u></a> in building and sustaining core digital infrastructure for learning. </p><h2 id="cybersecurity-threats-exist-for-every-school-district-no-matter-the-size-xa0">Cybersecurity Threats Exist For Every School District, No Matter the Size </h2><p>Other activities were held in conjunction with the White House event. </p><p>“Edtech companies convened there the day before the event,” says Pileiro. “And many of them took a pledge called Secure by Design, which is a cybersecurity pledge that encourages the solution-providers to prioritize cyber security in their products and their practices to reduce the burden on the K to 12 districts.”</p><p>The event also included breakout panels, during which attendees could share information and gain insights from peers. </p><p>“Being in the room was just great, being able to meet people from everywhere. It makes me proud to just be part of the conversation and to be able to take what I&apos;ve learned back to my school district and share it with my colleagues,” says Pileiro. “I think collaboration and what they&apos;re saying at the federal level is very encouraging because they want to collaborate, they want to see what&apos;s happening and they want to provide help.”</p><p>Other concrete takeaways from the event that Pileiro cites include the availability of free training from edtech companies, guidebooks and best practices from Google and others, and $20 million in grants from Amazon Web Services for K-to-12 cyber security.</p><p>“So the one thing that I took away, especially, is we all have the same problems, just at different scales,” says Pileiro. “And I was really happy to see that the federal government is taking some action, because [the threat] is ever present and it&apos;s growing.”</p><ul><li><a href="https://www.techlearning.com/how-to/4-cybersecurity-tips-for-schools" target="_blank"><strong>4 Cybersecurity Tips for Schools</strong></a></li><li><a href="https://www.techlearning.com/how-to/cybersecurity-in-the-classroom-what-teachers-can-do" target="_blank"><strong>Cybersecurity in the Classroom: What Teachers Can Do</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ An Hour-By-Hour Account of One District’s Cyber Attack Nightmare  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/an-hour-by-hour-account-of-one-districts-cyber-attack-nightmare</link>
                                                                            <description>
                            <![CDATA[ How one K-12 school district survived a ransomware attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">T9wCQDShpBy4LDggbC63qk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QhHBtfWBhjcXSUJpctTBF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jul 2023 09:00:19 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jul 2023 09:48:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp;amp; Learning&#039;s senior staff writer. A journalist,&amp;nbsp;&lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and educator, his work has appeared in the Washington Post, The Atlantic, and Associated Press. He currently teaches at&amp;nbsp;Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology&amp;nbsp;can make that more effective.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QhHBtfWBhjcXSUJpctTBF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ransomware attack]]></media:description>                                                            <media:text><![CDATA[ransomware attack]]></media:text>
                                <media:title type="plain"><![CDATA[ransomware attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QhHBtfWBhjcXSUJpctTBF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The first sign something was wrong came courtesy of an alert that Joel Handler received notifying him that his district’s Student Information System (SIS) was offline. It was 8:35 p.m. on April 11, 2021, and Hillsborough Township Public Schools’ spring break was coming to an end.</p><p>After receiving the alert, Handler, the district’s director of technology, and one of his staff members started trying to determine what was wrong with VPN access from their home computers. </p><p>At 9:15 p.m. the SIS came online and it was instantly clear that the district had a bigger problem than a web outage on its hands. Instead of the normal homesite, there was a message from hackers. The word “Ryuk,” the name of ransomware software inspired by a character in a popular manga series, was in the center of the screen, and in the bottom right corner of the screen were the cryptic words, “balance of a shadow universe.” </p><p>What followed was a whirlwind 24+ hour period during which Handler and his staff tried to work with law enforcement and school leaders to protect student information, minimize disruptions to teaching, and learn how to better prepare for the future. </p><p>Ever since this harrowing experience, Handler has shared the story in the hopes it will help other districts better prepare for the increasing risk of cyberattacks. </p><p>Here is an hour-by-hour look at how one district survived a cyberattack. </p><h2 id="before-the-cyber-attack-xa0">Before The Cyber Attack </h2><p>Hillsborough Township Public Schools’ is a Central New Jersey suburban district with 7,350 students and 1,000 staff members spread across nine schools. At the time of the attack, Handler’s IT staff consisted of two systems engineers, one systems integrator, and one SIS database manager, as well as five field repair technicians. On the education side, the district had one technology integration coordinator and nine tech coaches. </p><h2 id="during-the-attack">During The Attack</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1483px;"><p class="vanilla-image-block" style="padding-top:44.10%;"><img id="nCSmXc7fUox4CeovseHuvf" name="Screenshot 2023-07-20 141643.png" alt="The cryptic sign with the word "ryuk" that replaced Hillsborough district's homepage." src="https://cdn.mos.cms.futurecdn.net/nCSmXc7fUox4CeovseHuvf.png" mos="" align="middle" fullscreen="" width="1483" height="654" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">This cryptic message replaced the district's SIS page. </span><span class="credit" itemprop="copyrightHolder">(Image credit: Hillsborough Board of Education)</span></figcaption></figure><p><strong>9:15 p.m., April 11: Panic Mode! </strong></p><p>Googling “Ryuk,” Handler learns it is ransomware software. “We start panicking,” Handler says. They start to try and assess the damage, but no school server is working and they worry that engaging any through VPN with their home computers will infect their home computers as well. </p><p><strong>9:43 p.m., April 11: Sounding The Alarm</strong></p><p>A little more than a half-hour into the crisis, Handler gets on the phone with the district’s business administrator and superintendent to bring them up to speed. The extent of the hack is still unclear at this point. </p><p><strong>10-11 p.m., April 11: Pleas for Help and Damage Control</strong></p><p>“We’re basically reaching out for help,” Handler says. “We don’t really know what to do to stop this.” Handler starts calling law enforcement agencies, including the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), the Multi-State Information Sharing Analysis Center (MS-ISAC), and the FBI, but since it is Sunday night, no one is answering. The state police do pick up and give him numbers for cybersecurity divisions and experts to call but when he does he still only gets voicemails. “Nobody’s there,” he says. </p><p>Meanwhile, the superintendent has started contacting Board of Education representatives, union leadership, and preparing community communications. The Business Administrator also calls the district’s cyber insurance policy holder and makes sure all the district’s bank accounts are frozen in case the hackers have gained access. </p><p>Team members begin to worry that the digitized HVAC systems at the schools might be compromised. “No one really thinks about this,” he says. “But all of our facilities, they&apos;re all interconnected. So are they attacking our schools with the intent to do physical damage?” </p><p>(Thankfully, this fear would turn out to be unfounded.) </p><p><strong>12:15 a.m., April 12: Shut it Down</strong></p><p>After a series of meetings with school officials, Handler hears from MS-ISAC and they advise him to shut down everything he can. “We went into the school, myself and one of my operations guys who lives in town, and we physically shut down our server, and that was one of the most eerie sounds I&apos;ve ever heard.” </p><p><strong>12:48 a.m., April 12: No School </strong></p><p>School for April 12 is canceled and because all the digital tools the district uses are potentially compromised, thus virtual school is not an option. </p><p><strong>1 a.m., April 12: Final Meeting of the Night/Early Morning</strong></p><p>The district’s operations team holds its final meeting of the night and makes plans to further assess and address the damage for the following day. </p><p><strong>6 a.m., April 12: Operations Team Meeting </strong></p><p>A message from the hackers on the server has been found saying they will be in touch shortly. </p><p><strong>6 a.m. to 11 p.m., April 12: Starting to Figure Out What Happened </strong></p><p>Throughout the day, Handler and other school employees begin to start the recovery process. It’s determined that the hackers have not accessed personal devices connected to the school’s servers, but district-wide password resets are initiated. The district decides that the next day of school will be a virtual day, and Handler and his team are figuring out things as they go. </p><p><strong>April 13-April 16: Virtual School and Analysis </strong></p><p>The operations team focuses on an attack analysis and restore process. Restoration is a slow process that takes place server-by-server, and each server is hardened from a cybersecurity standpoint as it is reconnected. </p><p><strong>April 19: In-Person School Resumes and Return to Normalcy</strong></p><p>In-person school resumes and most services are fully restored. Handler and his team had determined early on, within the first 24 hours, that they had a stable full backup, so there was no need to consider paying the ransom to recover school data. </p><h2 id="after-the-attack">After The Attack</h2><p><strong>Lessons Learned </strong></p><p>The process was long, difficult, and more multifaceted than could be summarized in this story but as operations returned to normalcy, Handler says they learned a number of important lessons – including ones you’d expect and others that are more surprising. </p><p>“As a tech director, I was in the middle of three different entities,” Handlers says. Law enforcement agencies were looking at the attack as a crime scene and didn’t want him to erase any data that could be helpful in tracking the origins of the attack. </p><p>Next, “My superintendent, the board of ed, they were like, ‘Let’s get the kids back in school,’” he says. “Finally, you had your business administrator and cyber insurance firm and they’re all like, ‘Get us back up and running without spending any money.’” </p><p>Educators who have the misfortune of finding themselves in this situation should, “Expect the unexpected,” Handler says. He adds it is vital to have a point person in charge of updating staff and the community, to let the IT team focus on fixing the problem. </p><p><strong>Cause of The Outbreak And Changes Going Forward </strong></p><p>“A student account was compromised on a gaming site or something out there,” Handler says. The student used their school login and username for that site and when it got compromised, the hackers used that information to log into the student’s school account. From there, they were able to infiltrate the system. </p><p>Since the attack, Hillsborough Township Public Schools has implemented a number of new updates to its cybersecurity procedures, including multifactor authentication requirements for all staff, implementation of endpoint detection and response, more phishing training efforts, and many other new interventions. </p><p>However, Handler also knows it’s important to have a plan for if these efforts fail, as no cybersecurity system is foolproof. Having set procedures in place ahead of time for when a district is the victim of a successful cyberattack can lessen the fog of war Handler and his district experienced.  </p><p>“There&apos;s a lot of good stuff out there that talks about how to prevent ransomware attacks,” Handler says. “There’s no good playbooks out there for as the attack is happening.” </p><p>And as Handler knows from experience, you don’t want to be searching for those playbooks after hackers have successfully stormed the gates and are inside your network. </p><p><em>To share your feedback and ideas on this article, consider joining our Tech & Learning online community </em><a href="https://k12leaders.com/tech-learning/tech-learning-public-invitation/" target="_blank"><em>here</em></a>.</p><ul><li><a href="https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert" target="_blank"><strong>5 Cybersecurity Tips from CoSN’s CEO and a Digital Security Expert</strong></a></li><li><a href="https://www.techlearning.com/how-to/4-cybersecurity-tips-for-schools" target="_blank"><strong>4 Cybersecurity Tips for Schools</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity in the Classroom: What Teachers Can Do ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/cybersecurity-in-the-classroom-what-teachers-can-do</link>
                                                                            <description>
                            <![CDATA[ Teachers can boost classroom cybersecurity with these resources, best practices, and more ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FbB5wj3h6Bv6q28PEfos2A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rpkRaaGruHbmrr3SydjPoZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Jul 2023 09:02:35 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Jul 2023 11:57:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Laurie Guyon ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Laurie Guyon is the Coordinator for Model Schools at WSWHE BOCES in Saratoga Springs, New York, and a trainer with NYSCATE.&amp;nbsp;She is also an author, the Capital Region Director for NYSCATE, and an adjunct professor for SUNY Plattsburgh.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rpkRaaGruHbmrr3SydjPoZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[classroom cybersecurity]]></media:description>                                                            <media:text><![CDATA[classroom cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[classroom cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rpkRaaGruHbmrr3SydjPoZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the ever-increasing presence of technology in our classrooms and our daily lives, it is more important than ever for teachers to be aware of the risks associated with using technology with students. We need to understand the potential perils as well as the safeguards and what to do if there is a security breach. </p><p>These essential topics can open opportunities to support critical thinkers and problem solvers. Fortunately, there are tremendous resources available to you online.</p><p>One of the best sites for educators is <a href="https://www.commonsense.org/education" target="_blank"><u><strong>Common Sense Education</strong></u></a>, which offers many free resources to support us as teachers, students, and the community. Before diving into any other site, it would be worth reviewing their <a href="https://www.commonsensemedia.org/research" target="_blank"><u><strong>research</strong></u></a>, <a href="https://www.commonsense.org/education/digital-citizenship/curriculum"><u><strong>lessons</strong></u></a>, and <a href="https://www.commonsense.org/education/articles" target="_blank"><u><strong>other resources</strong></u></a>. </p><p>Many aspects of cybersecurity need to be considered, however, there are three significant areas worth focusing on for your classroom.</p><h2 id="classroom-cybersecurity-password-protection-xa0">Classroom Cybersecurity: Password Protection </h2><p>One of the most important things you can do to protect yourself from cybersecurity threats is to create strong passwords that are at least 12 characters long and include a mix of upper and lowercase letters, numbers, and symbols. In addition, you should create unique passwords for each account you have. To keep your passwords safe, you can use a password manager or write them down in a safe place. </p><p>There are excellent resources to support teaching about password safety:</p><ul><li><a href="https://sphero.com/pages/cybersecurity" target="_blank"><u><strong>Sphero lessons</strong></u></a> teach the fundamentals of password creation while using the Sphero BOLT. Minimal coding knowledge is needed to create robust opportunities for students to explore password safety and other aspects of cybersecurity. </li><li><a href="https://cyber.org/find-curricula/test-strength-your-passwords" target="_blank"><u><strong>Cyber.Org</strong></u></a> has ways to test our password strength and many lessons to enrich our understanding of cybersecurity. </li><li><a href="https://nearpod.com/t/search?q=password&s=3&i=3" target="_blank"><u><strong>Nearpod's 21st Century Skills Program</strong></u></a> has additional content that a district can purchase to highlight all aspects of digital literacy, including password protection. </li></ul><h2 id="think-before-you-click-xa0">Think Before You Click </h2><p>Phishing scams are a common way for hackers to steal personal information. Phishing emails often look as if they are from legitimate companies. Still, these are designed to trick you into clicking on a malicious link or downloading a virus. A simple pause and examination before we click can help keep us safe. </p><p>There are so many fun ways to help our students practice these skills, including:</p><ul><li><a href="https://beinternetawesome.withgoogle.com/en_us/" target="_blank"><u><strong>Be Internet Awesome</strong></u></a> offers excellent activities, slide decks, and games for your upper elementary students. The games are fun and engaging enough that students will be excited to share what they learn with one another. </li><li><a href="https://everfi.com/courses/k-12/digital-literacy-wellness-safety/" target="_blank"><u><strong>EverFi</strong></u></a> has an entire unit on digital wellness that will take your students through every aspect of their digital wellness. Lesson 4 explores identifying threats and helps them learn more about passwords. </li><li><a href="https://cias.utsa.edu/k-12/" target="_blank"><u><strong>CIAS</strong></u></a> uses CyBear characters and card games to teach all about cybersecurity. Request your free classroom pack of cards and print these tremendous offline activities to teach about cyber attacks and safety. </li></ul><h2 id="using-technology-for-good-xa0">Using Technology for Good </h2><p>Students need strong support when engaging online with others. As we teach character education, SEL, and DEI, we must support students&apos; social media use. </p><p>Students need to know essential terms such as bystander, upstander, and ally. While much teaching in the past has focused on what not to do online, we have the opportunity to help students see the potential that our online presence can do to bring social good. </p><p>Exploring our online world in the classroom can seem daunting, but there are so many incredible resources available, including:</p><ul><li><a href="https://www.stopbullying.gov/cyberbullying/tips-for-teachers" target="_blank"><u><strong>StopBullying.gov</strong></u></a> is a great place to help us understand the warning signs and give us a toolkit to share with students to help protect them. </li><li><a href="https://digcitinstitute.com/digcitsummit-global-student-showcase/" target="_blank"><u><strong>DigCit Institute</strong></u></a> offers month-long celebrations during which students and teachers share all the great ways they use technology for good. Check out their month-long #GlobalStudentShowcase recordings from April 2023 and follow them on social media for more opportunities to learn and participate. </li><li><a href="https://buttersfinalmeal.com/" target="_blank"><u><strong>Butter</strong></u></a> is a movie that your students will be on the edge of their seats while watching. It tackles mental health, suicide, and bullying in an engaging film. Then, check out the free <a href="https://buttersfinalmeal.com/school_curriculum/" target="_blank"><u><strong>curriculum</strong></u></a> created by <a href="https://twitter.com/lhighfill?lang=en" target="_blank"><u><strong>Lisa Highfill</strong></u></a>, one of the <a href="https://hyperdocs.co/" target="_blank"><u><strong>Hyperdocs</strong></u></a> creators, to engage your students on these complex topics. </li></ul><p><em>To share your feedback and ideas on this article, consider joining our Tech & Learning online community </em><a href="https://k12leaders.com/tech-learning/tech-learning-public-invitation/" target="_blank"><em>here</em></a>.</p><ul><li><a href="https://www.techlearning.com/news/best-cybersecurity-lessons-and-activities-for-k-12-education" target="_blank"><strong>Best Cybersecurity Lessons and Activities for K-12 Education</strong></a></li><li><a href="https://www.techlearning.com/how-to/4-cybersecurity-tips-for-schools" target="_blank"><strong>4 Cybersecurity Tips for Schools</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5 Cybersecurity Tips from CoSN’s CEO and a Digital Security Expert ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/cybersecurity-tips-from-cosns-ceo-and-a-digital-security-expert</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity was the No. 1 concern of edtech leaders, a CoSN survey reveals. These easy-to-implement tips can help any school district quickly address cybersecurity weaknesses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oPJmRHa9RzLwG2j8TTrTHG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/485cQxmuwz9wmtoyxLPvqD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Jul 2023 09:05:12 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Jul 2023 11:10:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp;amp; Learning&#039;s senior staff writer. A journalist,&amp;nbsp;&lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and educator, his work has appeared in the Washington Post, The Atlantic, and Associated Press. He currently teaches at&amp;nbsp;Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology&amp;nbsp;can make that more effective.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/485cQxmuwz9wmtoyxLPvqD-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Katie White from Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[school cybersecurity tips]]></media:description>                                                            <media:text><![CDATA[school cybersecurity tips]]></media:text>
                                <media:title type="plain"><![CDATA[school cybersecurity tips]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/485cQxmuwz9wmtoyxLPvqD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>“For the last five years, cybersecurity has been the No. 1 concern, and it’s increasing in anxiety each year,” says Keith Krueger, CEO of the Consortium for School Networking (CoSN). “School districts are the No. 1 target for ransomware.” </p><p>Drawing on CoSN’s recent 2023 <a href="https://t.e2ma.net/webview/99mbg8/703ba5ca0dd20d6e2fd00e05194dc6a8" target="_blank"><u><strong>State of EdTech Leadership</strong></u></a><strong> </strong>survey, and in conjunction with Amy McLaughlin, CoSN’s cybersecurity subject matter expert, Krueger recently shared tips for school leaders around cybersecurity. </p><p>Fortunately, there is plenty of cybersecurity help for school districts in the form of resources, potential collaboration, and little changes that can have a big impact. </p><h2 id="1-school-cybersecurity-tips-backup-information-offline-and-offsite">1. School Cybersecurity Tips: Backup Information Offline and Offsite</h2><p>The 2023 State of EdTech Leadership survey found 65 percent of school districts are backing up all their data on an offsite location that is not connected to the internet. </p><p>Krueger believes this is a good start but he also sees "the cup is almost half empty" side of that stat. “[It] means that a third of school districts aren&apos;t doing that most essential kind of a backup,” he says.  </p><h2 id="2-xa0-patch-everything-xa0">2.  Patch Everything  </h2><p>The first step McLaughlin says every district should take is to patch everything in a timely manner. “I can&apos;t believe I&apos;ve been doing this for 20 years and I have to say this, people still don&apos;t patch their stuff timely,” she says. “This is one of the simplest things to do. Patch every month, every device on time, and don&apos;t forget the stuff that you&apos;re not working with, every minute. Things like routers, switches, and firewalls also need patches and firmware upgrades.” </p><h2 id="3-utilize-two-factor-authentication-xa0">3. Utilize Two-Factor Authentication  </h2><p>McLaughlin’s next piece of advice for a security measure that can pay immediate cybersecurity dividends is to install two-factor authentication. </p><p>“It is not the silver bullet, but it is a significant increase in security,” she says. “It makes it so much harder for somebody to compromise your account when they phish credentials on it.” </p><p>Sixty-one percent of respondents to the CoSN survey said they require two-factor authentication. While McLaughlin would like to see that number rise, the trend is moving in the right direction. Last year only 40 percent of respondents required two-factor authentication. </p><h2 id="4-xa0-don-apos-t-reinvent-the-wheel">4.  Don&apos;t Reinvent The Wheel</h2><p>State education departments have resources available and Homeland Security tracks and publishes information about cybersecurity attacks on schools. <a href="https://www.cosn.org/cosn-news/k12-cybersecurity-primer-released-by-cosn/" target="_blank"><u><strong>CoSN also offers a primer</strong></u></a> for schools looking to ensure they are following cybersecurity best practices. </p><p>“It&apos;s probably the kind of thing that most school districts will read it and say, ‘Yeah, we&apos;re doing almost all those things,’ but it reminds you of what to do if you&apos;re not doing all those things,” says McLaughlin.  </p><h2 id="5-xa0-change-the-culture-xa0">5.  Change the Culture  </h2><p>“The tendency is to think that well, cybersecurity is only the responsibility of the people who have technology in their title, and that&apos;s not the case,” Krueger says. </p><p>The culture around cybersecurity needs to change so that all school leaders are thinking about it and it becomes a priority for superintendents and school boards. </p><p>“They have to understand that cybersecurity isn&apos;t a technical problem that you dump on the IT department. It&apos;s an organizational challenge for the whole organization, and it needs funding,” McLaughlin says.  “Implementing multifactor authentication isn&apos;t difficult, technically. None of this is horribly difficult, technically. But the hard part is getting the organizational culture to not just accept but to embrace that this is an important element for taking care of the organization.”</p><ul><li><a href="https://www.techlearning.com/news/school-cyberattacks-how-the-fbi-works-to-protect-school-districts" target="_blank"><strong>School Cyberattacks: How the FBI Works to Protect School Districts</strong></a></li><li><a href="https://www.techlearning.com/how-to/4-cybersecurity-tips-for-schools" target="_blank"><strong>4 Cybersecurity Tips for Schools</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5 Tips for Creating a Data Privacy Day in Your School ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/5-tips-for-creating-a-data-privacy-day-in-your-school</link>
                                                                            <description>
                            <![CDATA[ INNOVATIVE LEADER AWARD WINNER - A data privacy day in your school can help raise awareness regarding the importance of protecting students’ online presence ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ue7WQ9ABDfdYKZMBEvUCcd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pgxdZUwL7cGwPfbseU5TQi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 May 2023 09:04:17 +0000</pubDate>                                                                                                                                <updated>Mon, 15 Jul 2024 18:11:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sascha Zuger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gHQk3x9WMA66CvfWv6PdTH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pgxdZUwL7cGwPfbseU5TQi-1280-80.jpg">
                                                            <media:credit><![CDATA[Union School District]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[On Data Privacy Day, Lisa DeLapo works with students in Union School District to understand the need to protect themselves online]]></media:description>                                                            <media:text><![CDATA[data privacy day]]></media:text>
                                <media:title type="plain"><![CDATA[data privacy day]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pgxdZUwL7cGwPfbseU5TQi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity continues to be a concern for all, with everyone from small businesses to major corporations and even governments on high alert, fighting the good fight to keep what’s private, private. </p><p>On the surface, it might seem that a young learner would be the last one to need to worry about securing their tech — not a lot of hacking of fridge-destined finger paint masterpieces or “my cat sat on a mat” stylings of literary work and intellectual property. </p><p>What isn’t such a cute concept is the amount of personal and sensitive information kept within a district’s system. Holding a data privacy day to bring awareness to this important topic is a great way to encourage safe use of tech.</p><p>Union School District in San Jose has a data privacy day, organized by Lisa DeLapo, Director of Information & Instructional Technology, to help students, staff, and families better protect their online presence.</p><h2 id="start-digital-and-data-privacy-ed-early">Start Digital and Data Privacy Ed Early </h2><p>As with most subjects, early intervention ensures students build good habits from the beginning. When started early, self-awareness of data safety can become as second nature as putting a bike helmet on before hitting the pedals.</p><p>“As soon as students are using technology, they should learn about digital privacy,” says DeLapo, who was recently honored as Innovative Technology Director during Tech & Learning’s Northern California <a href="https://www.techlearningevents.com/RegionalSummits" target="_blank"><u><strong>Regional Leadership Summit</strong></u></a>. “Kids are clean slates when it comes to their personal information, which also makes them a target by cyber criminals. COPPA protects kids under 13 years old, but learners have to know how to make sure their information does not get into the wrong hands.”</p><p>DeLapo, known as “the digital privacy lady” in the halls of Union, loves when lessons learned stick.</p><p>“When I teach in classes, they will make comments about private versus public information— such as when they build a website, they don't put their names or other personally identifiable info on it,” DeLapo says. “It's like music to my ears!”</p><h2 id="invest-a-little-save-a-lot">Invest a Little, Save a Lot </h2><p>Unlike adults, identity security isn’t something most parents and guardians would think to keep tabs on for children. As such, typically obvious red flags might fly under the radar and not be caught until the damage is already done. Keeping students safe and secure, whether tucked in their desks, in the lunchroom, or in their digital future, is paramount. </p><p>“While many public school districts are under-funded, digital privacy still must be protected,” says DeLapo. “The cost of that data being released to the public—or worse— to criminals who may use it for their monetary gain, is far more costly. School districts can always use CITE's privacy services to ensure their schools and teachers are using applications and services that are legally bound to protect student data. It has to be part of the app-vetting process to ensure student information is not sold to other parties.”</p><h2 id="5-tips-for-creating-a-data-privacy-day-in-your-school">5 Tips for Creating a Data Privacy Day in Your School </h2><ul><li><strong>Keep it simple.</strong> Kids need to understand what digital privacy is in general, so they know what they are protecting.</li><li><strong>Get students to participate in the creation of the day</strong> so they are involved in making it an engaging topic for their peers.</li><li><strong>Keep it short</strong>. Don't bore your audience with too much information.</li><li><strong>Stickers for participation!</strong> “We created our own sticker for students to show off on the case of their school-issued devices,” says DeLapo. “This raises excitement and helps to spread the word.”</li><li><strong>Ask parents and other adults in your community for help</strong>. "You never know who can help with good ideas and info," says DeLapo.</li></ul><ul><li><a href="https://www.techlearning.com/how-to/4-cybersecurity-tips-for-schools" target="_blank"><strong>4 Cybersecurity Tips for Schools</strong></a></li><li><a href="https://www.techlearning.com/news/best-cybersecurity-lessons-and-activities-for-k-12-education" target="_blank"><strong>Best Cybersecurity Lessons & Activities for K-12 Education</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 4 Cybersecurity Tips for Schools ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/4-cybersecurity-tips-for-schools</link>
                                                                            <description>
                            <![CDATA[ INNOVATIVE LEADER AWARD WINNER - Cybersecurity tips for securing your school or district's website from award-winning technology director Emmanuel Ajanma ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wkfYofhWu5oNrwGCZyPsaj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tt9KL8zENXwk74xxns7p7V-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Apr 2023 09:01:25 +0000</pubDate>                                                                                                                                <updated>Mon, 15 Jul 2024 18:13:11 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp;amp; Learning contributor. A journalist,&amp;nbsp;&lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at&amp;nbsp;Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology&amp;nbsp;can make that more effective.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/tt9KL8zENXwk74xxns7p7V-1280-80.png">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity tips for schools]]></media:description>                                                            <media:text><![CDATA[cybersecurity tips for schools]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity tips for schools]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tt9KL8zENXwk74xxns7p7V-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As technology director of Barre USD in Vermont, Emmanuel Ajanma has led the movement to revamp the district's cybersecurity. These efforts earned him the award for Best Implementation of Data Privacy & Security at a recent Tech & Learning <a href="https://www.techlearningevents.com/innovativeleaderawards/home?ref=CW" target="_blank"><strong>Regional Leadership Summit</strong></a> in Maryland.  </p><p>A former Catholic priest, Ajanma began his career in education teaching in parochial schools and found that he wanted to teach full-time. “If we are to secure our future, we do it through educating the young ones because they are the leaders of tomorrow,” he says.  </p><p>Ajanma, a native of Nigeria, was drawn to technology in particular because he saw years ago that it would become increasingly intertwined with learning. “Everything we do in the classroom and everything we ask, we are relying more and more on technology,” he says. </p><p>That’s part of the reason cybersecurity is so important because when there is a breach in a school district these days, learning can grind to a halt. Ajanma shares some of his advice for securing school networks. </p><h2 id="1-cybersecurity-tips-for-schools-add-segmentation">1. Cybersecurity Tips for Schools: Add Segmentation </h2><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1272px;"><p class="vanilla-image-block" style="padding-top:77.44%;"><img id="5obBWvMrUWUeVpRMPhQDUf" name="Headshot.png" alt="A headshot of Emmanuel Ajanma" src="https://cdn.mos.cms.futurecdn.net/5obBWvMrUWUeVpRMPhQDUf.png" mos="" align="right" fullscreen="" width="1272" height="985" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">As technology director of the Barre USD in Vermont, Emmanuel Ajanma has led the movement to revamp the districts cybersecurity. </span><span class="credit" itemprop="copyrightHolder">(Image credit: Emmanuel Ajanma)</span></figcaption></figure><p>One initial cybersecurity step everyone should take is to implement segmentation, says Ajanma. “That is the very first project that I did as a technology director,” he says. </p><p>This divides a network into semi-independent segments protected by firewalls, which can limit the damage in the event of a security breach in one of the segments. “It wouldn’t spread if something happens at the high school or the middle school, or at the central office or wherever it is. It will be limited to a particular segment of our network,” he says. </p><p>This is such an important step that Ajanma’s advice is, “Do it yesterday.”</p><h2 id="2-make-school-stakeholders-aware-cybersecurity-is-everyone-s-responsibility">2. Make School Stakeholders Aware Cybersecurity is Everyone’s Responsibility </h2><p>Another key in a successful school cybersecurity program is getting buy-in from teachers, students, administrators, parents, and anyone and everyone who interacts with school devices or the school network.  </p><p>“Cybersecurity is not only a technology department issue, it's all hands on deck,” Ajanma says. To get help from all stakeholders, Ajanma works with the school board to create cybersecurity policies based on best practices. </p><p>However, having good policies is only the first part of the equation. “You need folks to actually know what the policies are and practice those policies,” he says. </p><p>To ensure that, Ajanma has launched online cybersecurity training modules for all staff, which helps ensure they not only know the policies but help the technology department stay vigilant in regard to cybersecurity. </p><h2 id="3-implement-multifactor-authentication">3. Implement Multifactor Authentication </h2><p>Another step Ajanma recommends is multifactor authentication, a two-step or greater login process that requires the user to do more than just enter a password. </p><p>While multifactor authentication has been Cybersecurity 101 for years now, many school districts still do not require it, and technology directors often face pushback when they try to launch the programs. Ajanma’s department was able to avoid this by sharing stories about cybersecurity breaches, including one that happened in a neighboring district, which highlighted the risk for educators at Barre USD. </p><p>“This is not something that is only happening in New York City or in California, it can happen here in Vermont, it can happen in every district,” he says. Ajanma is also intentional about linking news of hacks to information on prevention solutions and strategies. </p><h2 id="4-be-proactive-rather-than-reactive">4.  Be Proactive Rather Than Reactive  </h2><p>Ajanma uses tools to monitor the school network for any anomalies or strange behavior, plus he holds regular tabletop exercises with his staff and tries to get school leaders involved in drills. </p><p>In addition, Ajanma tries to be forward-thinking in recognizing new threats and advises others to do the same. For instance, he is starting to look at the ways ChatGPT and other AI language models with the capability to generate code might create malicious software. </p><p>“I don't want to wait until it's happened,” he says. “I'm trying to be proactive.” </p><ul><li><a href="https://www.techlearning.com/how-to/building-pathways-between-schools-and-local-businesses" target="_blank"><strong>Building CTE Pathways Between Schools and Local Businesses</strong></a></li><li><a href="https://www.techlearning.com/news/school-cyberattacks-how-the-fbi-works-to-protect-school-districts" target="_blank"><strong>School Cyberattacks: How the FBI Works to Protect School Districts</strong></a></li></ul><p><em>To share your feedback and ideas on this article, consider joining our Tech & Learning online community </em><a href="https://k12leaders.com/tech-learning/tech-learning-public-invitation/" target="_blank"><em><strong>here</strong></em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ K-12 Cybersecurity in 2023: Ransomware, AI, and Increased Threats ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/k-12-cybersecurity-in-2023-ransomware-ai-and-increased-threats</link>
                                                                            <description>
                            <![CDATA[ The current trends in K-12 cybersecurity that education leaders need to be aware of ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EaShPnQcnixGjbRnRmNWLU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZAmSfi9mhnz4Bnrj6Moc3P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Mar 2023 09:10:50 +0000</pubDate>                                                                                                                                <updated>Fri, 24 Mar 2023 15:13:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Eileen Belastock ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZAmSfi9mhnz4Bnrj6Moc3P-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZAmSfi9mhnz4Bnrj6Moc3P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Well into 2023, it is disheartening to know that K-12 institutions continue to be one of the primary targets of cybersecurity attacks. Cyberattacks such as DDoS, phishing, data breaches, password attacks, man-in-middle attack, and malware on school districts have resulted in monetary losses, the need for additional recovery resources, and loss of instruction time.</p><p>While all types of cyberattacks are increasing in districts, for the first time, ransomware incidents were the most frequently disclosed incident type in 2022, with percentages rising from 12% in 2020 to 62% in 2022, according to the <a href="https://www.emsisoft.com/en/blog/43258/the-state-of-ransomware-in-the-us-report-and-statistics-2022/" target="_blank"><u><strong>Emsisoft 2022 report</strong></u></a>. School districts hit by ransomware in 2022 represented 1,981 schools, almost double the number of K-12 schools potentially compromised in 2021. In addition, ransomware groups successfully exfiltrated data from U.S. schools at a rate of two-thirds in 2022, up from half that number in 2021. </p><p>“We must ensure that our K-12 schools are better prepared to confront a complex threat environment,” says Jen Easterly, Director of <a href="https://www.cisa.gov/sites/default/files/2023-01/K-12report_FINAL_V2_508c_0.pdf" target="_blank"><u><strong>CISA</strong></u></a>, the U.S. Cybersecurity and Infrastructure Security Agency, which is partnering with K-12 to bolster security. “As K-12 institutions employ technology to make education more accessible and effective, malicious cyber actors are working to exploit vulnerabilities in these systems, threatening our nation’s ability to educate our children.” </p><h2 id="ransomware-attacks-on-the-rise-xa0">Ransomware Attacks on the Rise </h2><p>Ransomware has the potential to access and exploit the sensitive data in K-12 institutions, including student records and other personally identifiable information, financial aid and transaction data, and healthcare information. As such, districts are continually at high risk. For example, <a href="https://www.reuters.com/world/us/ransomware-gang-leaked-los-angeles-student-health-records-online-2023-02-23/" target="_blank"><u><strong>bad actors recently released health records for about 2,000 current and former LAUSD students</strong></u></a>, publishing it on the dark web. </p><p>With the increase in classroom technology and personal digital data, district leaders and IT professionals need to acknowledge that ransomware will continue to be an evolving cybersecurity threat. It is typically seen as easy big money for many bad actors, as they understand that districts are more willing to pay a ransom than undertake a long recovery process with educational and administrative consequences. </p><p>Currently, many districts don’t have significant resources or budgets focused on cybersecurity, with an estimated less than 2% of operating budget allocated for staffing, training, and software. The <a href="https://www.cosn.org/edtech-topics/state-of-edtech-leadership/" target="_blank"><u><strong>State of EdTech District Leadership 2022</strong></u></a> highlights that more than half of the IT professionals (52%) said their schools lack adequate staffing to support and protect teachers, while 77% of districts reported not having a full-time employee dedicated to network security. </p><p>In addition, often unintentional, and non-malicious human errors are the top reason for school cyber attacks. Focusing on daily operations, staff and teachers are too quick to respond to phishing attempts, suspicious links, and unsecured access networks. With easily hacked passwords, unsecured devices, and software available with one click, accessing user data is an easy lift for hackers.</p><h2 id="cybersecurity-help-and-resources-xa0">Cybersecurity Help and Resources </h2><p>Cybersecurity will keep edtech leaders up at night; however, many resources and organizations support the work done in school districts through educational programs, policies and initiatives, and training. Two organizations committed to cybersecurity and education are <a href="https://www.cosn.org/" target="_blank"><u><strong>CoSN</strong></u></a> and the <a href="https://cryptologicfoundation.org/" target="_blank"><u><strong>National Cryptologic Foundation</strong></u></a>. </p><p>As a premier membership organization designed to meet the needs of K-12 education technology leaders, CoSN supports cybersecurity initiatives in many school districts. At the federal level, they are campaigning along with other organizations for FCC to expand E-rate eligibility for basic firewalls to include all current firewalls and related features without requiring cost allocations. </p><p>CoSN recently released the <a href="https://www.cosn.org/edtech-topics/cybersecurity/" target="_blank"><u><strong>Blaschke Report</strong></u></a>, a cybersecurity primer for any K-12 school district. This report identifies five actions a school system IT staff might take to defend IT infrastructure better, including: </p><ul><li>Training</li><li>Technical expertise </li><li>Network security </li><li>Sustainability plans </li><li>Leadership buy-in and funding </li></ul><p>Keith Krueger, CEO of CoSN, recommends that along with the actions in the report, K-12 organizations take a district-wide approach to cybersecurity by focusing on user education, increasing internal human capacity, and understanding what is at risk regarding cyberattacks. </p><p>The National Cryptologic Foundation focuses on a community approach to reach youth with vital cybersecurity concepts and tools. They provide the education community various resources including cybersecurity curriculum guidelines and the Outsmart Cybersecurity Collection, which guides students to build their foundation of data care principles and practices. Also available are interactive cybersecurity games and podcasts that provide expert advice. They also partner with <a href="https://teachcyber.org/" target="_blank"><u><strong>Teach Cyber</strong></u></a> to offer pathways for students to explore careers in cybersecurity. </p><p>“You don’t have to have a background in cybersecurity to teach our youth and provide future opportunities in the cybersecurity space,” says Dr. Alisha Jordan, Director of Education for the National Cryptologic Foundation. She recommends that any educator interested in learning more should sign up for an account and newsletter <a href="https://cryptologicfoundation.org/" target="_blank">on their website</a>.</p><h2 id="what-x2019-s-ahead-in-cybersecurity-xa0">What’s Ahead in Cybersecurity </h2><p>With the avenues of attack growing, districts cannot rely on outdated methods to stay secure. The 2022 <a href="https://www.cisa.gov/news-events/news/cisa-releases-report-k-12-schools-help-address-evolving-cybersecurity-threats" target="_blank"><u><strong>CiSA report</strong></u></a> recommends that districts explore several strategies to  meet the increased demands of the cyber risk landscape, including: </p><ul><li>Making all employees part of the district’s security defense</li><li>Keeping patches up-to-date  </li><li>Restricting unnecessary access </li><li>Implementing multi-factor authentication </li><li>Following industry best practices </li></ul><p>Educators also need to stay abreast of cybersecurity trends. For example, cybercriminal gangs and sophisticated advanced persistent threat <a href="https://www.crowdstrike.com/cybersecurity-101/advanced-persistent-threat-apt/" target="_blank"><u><strong>(APT) groups</strong></u></a> are actively recruiting AI and ML specialists who design malware that can evade current-generation threat-detection systems. While developing these AI capabilities is a lengthy process,  they already can facilitate easy and undetectable network access with malware-free intrusions and valid credentials.</p><p>In addition, cyber criminals have tapped into the highly popular ChatGPT AI to refine malware, personalize phishing emails, and finely tune computations to steal highly sought access credentials.</p><p>On the plus side, we are seeing some noteworthy cybersecurity developments. Leading cybersecurity vendors such as AWS, Google, and Microsoft are prioritizing investment in AI and ML research and development in response to increasingly complex threats. </p><p>AI may also be a game changer for districts against cyber attacks, with its potential to help build automated security systems, support natural language processing, refine face detection, and be a part of predictive threat- detection systems. </p><p>While not a substitute for committed experienced IT personnel, robust infrastructures, and knowledgeable users, AI technology will soon be able to help districts fight the good fight in regard to cybersecurity.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Confidentiality, Integrity & Availability: 4 Ways Schools Can Securely Build A CIA Triad ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/confidentiality-integrity-and-availability-4-ways-schools-can-securely-build-a-cia-triad</link>
                                                                            <description>
                            <![CDATA[ When building confidentiality, integrity, and availability (the CIA Triad), districts can’t overlook security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">v3QcewWZdC8MLusXLfX4xB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VXgDYFBpqoawBVL7RVLtN8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Dec 2022 10:15:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Smith and Rod Russeau ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;&lt;em&gt;Rod Russeau is the director of technology &amp;amp; information services, District 99 (IL) and Chairperson, CoSN Cybersecurity Initiative. Steve Smith is the PIO at Cambridge Public Schools (MA) and Founder of the Student Data Privacy Consortium.&lt;/em&gt;&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VXgDYFBpqoawBVL7RVLtN8-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CIA Triad]]></media:description>                                                            <media:text><![CDATA[CIA Triad]]></media:text>
                                <media:title type="plain"><![CDATA[CIA Triad]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VXgDYFBpqoawBVL7RVLtN8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The focus on student privacy has grown in recent years and for good reason. As consumers, we want to know that the banks, retailers and other organizations that we do business with aren’t misusing or reselling our data. The same goes for schools, which have always gathered, stored and shared student data. Unlike paper, which can be locked in a file, digital data is generally more prone to misuse by “bad actors” that may steal it and use it illegally. </p><p>But where the banking industry has built up a level of confidence for consumers who log into their accounts online or via an app and know that those institutions won’t misuse their data, school districts are still working to establish this level of trust and confidence. Most understand the responsibility that they have to keep their students’ data secure, but they don’t always recognize that security must also ensure privacy. For example, a district may have an extremely secure system, but it could be unknowingly misusing and/or sharing data inappropriately (e.g., with outside vendors or partners). </p><p>It’s also important that districts distinguish between information security and cybersecurity. The former is focused on high-level, overall protection of information and ensures that information systems aren’t used in an unauthorized manner. It includes the policies and procedures related to security. </p><p>Cybersecurity, on the other hand, relates to the technical, hands-on aspect of protecting and preventing damage to electronic resources. Where cybersecurity is certainly part of information security, the latter also includes application security and protection of the infrastructure itself. </p><h2 id="confidentiality-integrity-amp-availability-cia-triad-4-good-starting-points-xa0">Confidentiality, Integrity & Availability (CIA Triad): 4 Good Starting Points </h2><p>When creating what we refer to as the “confidentiality, integrity and availability” (CIA) triad, districts must factor in the myriad different aspects of security. Here are four ways to get started down the right path: </p><ol><li><strong>Reduce the number of applications in use on campus.</strong> Rather than letting teachers and administrators find and use applications on their own, develop a process for “approving” applications for use within the district. This will help reduce the number of disparate solutions that are being used and give IT and other stakeholders more control over what kind of data is being shared and who has access to it. Give users access to a list of approved applications and make it easy for them to find, implement and begin using those solutions. </li><li><strong>Work with vendors that understand the value of privacy and security.</strong> They say you’re only as strong as your weakest link, and this definitely holds true in the technology space. Your technology partners should share your vigilance for protecting the privacy of your students’ data. If they don’t, then find another partner. For example, as a fully unified school-home communications platform, ParentSquare is only accessible with a username and password. The platform stores and protects account information on a secured server behind a firewall and uses encryption/security software to safeguard the confidentiality of any personal information that it collects.</li><li><strong>Make it real for teachers, students, and parents. </strong>People will take both security and privacy to heart when they can relate to the potential threats and the damage that they can inflict. For example, when we’re trying to impress upon our staff the significance of password clarity, using different passwords for different sites, and using multifactor authentication wherever possible, we’ll use an example like a retail credit card breach to support our points. We’re all consumers and know that using the same login and password across dozens of sites is a bad idea. We try to explain it to them in ways that make the situation more personal; that helps bridge that gap a bit.  </li><li><strong>Get your leadership involved.</strong> Make sure your leadership understands that it’s ultimately accountable for everything that happens within its school district—security and privacy included. If there's a major incident of any kind in a school district, it's the superintendent who will be on the news trying to address and explain it. Also, leadership can play a key role in establishing the risk tolerance for their districts and helping everyone better understand that privacy, security, and data aren’t just “techie things.” </li></ol><h2 id="start-small-and-continue-to-build-xa0">Start Small and Continue to Build </h2><p>As much as everyone has been talking about privacy and security in recent years, there’s still a large percentage of small districts around the country that aren’t thinking about it because they’ve yet to experience a data breach, no one in their community has expressed concern, or they live in a state without a state law mandating they take proactive measures. </p><p>We talk to a lot of districts that don’t realize how much data is being shared with vendors and outside parties. Other schools feel like they just don&apos;t have the capacity or the resources to handle the issue properly, so security and privacy get tabled for another day. It’s important to keep in mind that all districts house information which is highly valuable to bad actors. No district is immune from attack. For all school districts, no matter their size, location, technological skills, or budget, it&apos;s a matter of <em>when </em>a security incident or data breach occurs, not<em> if</em>. </p><p>For districts that don&apos;t know where to start, reach out to your peers and other organizations. <a href="https://www.cosn.org/" target="_blank"><u><strong>CoSN</strong></u></a>, with resources such as the Trusted Learning Environment, along with the <a href="https://privacy.a4l.org/" target="_blank"><u><strong>Student Data Privacy Consortium</strong></u></a> (SDPC) are good starting points. </p><p>Using these resources, you can start with just one or two initiatives and gradually begin building the framework for a privacy program in your district.</p><ul><li><a href="https://www.techlearning.com/news/are-school-social-media-accounts-putting-student-privacy-at-risk" target="_blank"><strong>How School Social Media Accounts Put Student Privacy at Risk</strong></a></li><li><a href="https://www.techlearning.com/how-to/school-ransomware-attacks-5-tips-to-prevent-and-survive" target="_blank"><strong>School Ransomware Attacks: 5 Tips to Prevent & Survive</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How School Social Media Accounts Put Student Privacy at Risk  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/are-school-social-media-accounts-putting-student-privacy-at-risk</link>
                                                                            <description>
                            <![CDATA[ New student privacy research shows that school social media accounts have posted millions of photos of students and other identifiable information, which might be dangerous ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8Uwh4mCuysT7Hw95Ne25Lf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kLsiER7jMMWyx9ychwJyXd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Nov 2022 10:17:29 +0000</pubDate>                                                                                                                                <updated>Wed, 30 Nov 2022 19:16:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp;amp; Learning&#039;s senior staff writer. A journalist,&amp;nbsp;&lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and educator, his work has appeared in the Washington Post, The Atlantic, and Associated Press. He currently teaches at&amp;nbsp;Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology&amp;nbsp;can make that more effective.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kLsiER7jMMWyx9ychwJyXd-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Gerd Altmann from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[student privacy]]></media:description>                                                            <media:text><![CDATA[student privacy]]></media:text>
                                <media:title type="plain"><![CDATA[student privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kLsiER7jMMWyx9ychwJyXd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>U.S. schools and districts routinely share student photos and names on public school social media accounts, new research from the American Educational Research Association reveals. </p><p>The study’s authors estimate that more than 4.9 million posts have included identifiable images of students on public Facebook pages, and about 726,000 of those posts are thought to identify one or more students by their first and last names. </p><p>The common media release forms many parents sign at the beginning of the year often don’t explicitly include social media. In addition, many educators and parents are unaware of the potentially harmful ways in which student images and names from social media posts can be used, says a co-author of the <a href="https://www.aera.net/Newsroom/Posts-About-Students-on-Facebook-A-Data-Ethics-Perspective" target="_blank"><u><strong>study</strong></u></a><u>,</u> Joshua M. Rosenberg.</p><p>“This study, we hope, is a constructive warning,” says Rosenberg, an assistant professor of STEM education at the University of Tennessee, Knoxville. “This is not meant to say all educational social media use is bad or dangerous, or that there&apos;s any high degree of risk associated with a single post. It&apos;s more saying that in aggregate, and over time, there&apos;s some potentially serious downsides that come from sharing this much personally identifiable information in a publicly accessible way.” </p><h2 id="student-privacy-serious-downsides-to-public-posts-xa0">Student Privacy: Serious Downsides to Public Posts </h2><p>The dangers of schools posting student names and pictures on social media fall broadly under three categories, Rosenberg says. </p><p><strong>1) Companies and governments accessing the data</strong></p><p>“We know that foreign and domestic governments access public social media data,” Rosenberg says. “What do they use that for? We don&apos;t really know. But in many cases, it&apos;s for things that we know adults don&apos;t like, and they wouldn&apos;t like for their children to be wrapped up in.” </p><p>For example, there are companies that collect public social media posts and other public internet data and compile it into a database that law enforcement agencies can use to probabilistically identify suspects for crimes. “This is an example where it&apos;s probably not illegal, but it&apos;s the kind of thing that parents and kids probably wouldn&apos;t like if a photo that was shared on a school or district page ended up in a database used by one of these policing companies to identify possible suspects in a crime,” says Rosenberg. </p><p><strong>2) People seeking images of children </strong></p><p>“There&apos;s data from Australia that suggests that around half of the images shared on child pedophilia websites came from public sources,” Rosenberg says. “These photos could end up being collected and presented in such a way that they look very different, and they are used for very creepy, and potentially really damaging purposes.” </p><p><strong>3) Individual risk</strong></p><p>“We&apos;ve heard many anecdotal stories of kids in custody disputes, in which one parent looks on the social media pages of their child&apos;s school or district to try to find out where they are, so that they can try to find that child and possibly do things that run counter to some custody agreement or some protection order,” Rosenberg says. “There&apos;s also the risk of stalking of individual kids. We have anecdotes of this.” </p><h2 id="how-schools-and-parents-can-be-safer-with-social-media-use-xa0">How Schools and Parents Can Be Safer with Social Media Use </h2><p>The first step to better protect student privacy is for school leaders and parents to start thinking more about potential risks, Rosenberg says. Unlike personal social media accounts, school accounts are always public and often have many more followers than an individual user would. School accounts can also place students in specific geographic areas in ways even public personal social media accounts don’t. </p><p>Rosenberg advises school leaders to make their school and district accounts private, though he acknowledges this has downsides, including less visibility for posts and more administrative work approving followers to the account. “That single step alone would prevent the large-scale collection of these data for purposes that are hard to anticipate at this point,” he says. “Another change we suggest making is to not post photos that readily identify students&apos; faces.”</p><p>He also suggests never posting students’ full names, and instead posting only their first name or only their first name and last initial.  </p><p>Finally, Rosenberg advises school leaders to review their media release policy and make sure it is current. “From a study that is ongoing, we found that less than 20% of [school media release policies] mention social media explicitly,” he says. “So a lot of these media release policies were written for a different era when social media use wasn&apos;t ubiquitous.” </p><p>Parents should also read these types of releases carefully and talk with their children’s educators. “I would encourage parents and students to ask questions about how schools and districts are sharing this kind of content,” he says. </p><p>The goal of the research is to spark broader conversations around this issue and serve as a warning. “It is definitely not a criticism of educational leaders,” Rosenberg says. “Myself and my colleagues have all shared information about ourselves, and family members on social media. And so we see this more as a constructive dialogue that we hope to start where we can slowly nudge ourselves and others into using social media in a way that doesn&apos;t have as many potential downsides for student privacy.” </p><ul><li><a href="https://www.techlearning.com/news/what-is-digital-wellness-how-one-school-implements-it" target="_blank"><strong>What is Digital Wellness? How One School Implements It</strong></a></li><li><a href="https://www.techlearning.com/news/4-ways-to-prevent-cyberbullying" target="_blank"><strong>4 Ways To Prevent Cyberbullying</strong></a></li><li><a href="https://www.techlearning.com/how-to/6-tips-for-protecting-student-data-privacy" target="_blank"><strong>6 Tips for Protecting Student Data Privacy</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Some Schools Use 2,000 Apps. Here’s How One District Protects Data Privacy  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/some-schools-use-2000-apps-heres-how-one-district-protects-data-privacy</link>
                                                                            <description>
                            <![CDATA[ Data privacy is a priority at Fayette County Schools. Jim Farmer, the chief technology officer, discusses how the district made that happen. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wCiMTZ9EfBbUuyeBi86JM5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DKkQZJHvdFP2w5hxDYc7ej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Nov 2022 09:00:43 +0000</pubDate>                                                                                                                                <updated>Mon, 14 Nov 2022 16:38:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp;amp; Learning&#039;s senior staff writer. A journalist,&amp;nbsp;&lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and educator, his work has appeared in the Washington Post, The Atlantic, and Associated Press. He currently teaches at&amp;nbsp;Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology&amp;nbsp;can make that more effective.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DKkQZJHvdFP2w5hxDYc7ej-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Dan Nelson from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[data privacy]]></media:description>                                                            <media:text><![CDATA[data privacy]]></media:text>
                                <media:title type="plain"><![CDATA[data privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DKkQZJHvdFP2w5hxDYc7ej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Educators today have a dizzying array of learning apps from which to choose. </p><p>A recent <a href="https://s3.amazonaws.com/files.lightspeedsystems.com/collateral/Ebook/2022+Edtech+App+Report+-+Lightspeed+Analytics_F.pdf" target="_blank"><u><strong>report</strong></u></a> from Lightspeed Systems finds that most school districts have more than 2,000 apps in use, but 300 apps account for 99 percent of school usage. </p><p>The sheer number of apps used in schools can present a challenge to chief technology officers and school IT teams tasked with protecting school data and student data privacy. </p><p>However, technology can also help protect student privacy. Jim Farmer, chief technology officer at Fayette County Schools in Georgia, says he and colleagues including Sarah MacDonald, information systems and data manager, Matt Jackson, coordinator of digital and media services, and Matt Smithson, network analyst, were able to protect student privacy in their district with smart use of privacy technology and good old-fashioned district education and outreach. </p><h2 id="vet-apps-for-data-privacy-and-rigor-xa0">Vet Apps For Data Privacy and Rigor  </h2><p>The technology and curriculum departments at Fayette County Schools worked closely together to establish how technology would be vetted. </p><p>“There&apos;s been this conversation for quite a few years now about trying to help people understand the importance of our students&apos; information, and where it&apos;s going, and how it&apos;s being used,” Farmer says. That conversation extended beyond privacy to quality. “From a curriculum standpoint, obviously we want to make sure our kids are getting the proper rigor, and [apps are] standards-based and vetted by our coordinators, and by our teachers, appropriately.” </p><p>Each app now goes through a standardized digital resource approval process. "Teachers work within their school and with their leadership to submit a request for a digital resource," Farmer says. "Once the principal or designee approves the request it then moves forward in the process to the district office. The district team is made up of the curriculum and technology department personnel. A rubric is used to evaluate the resource from multiple perspectives by the technology team safety, security, data policies, sharing, advertising, etc."</p><h2 id="understand-the-tech-being-used-in-your-district-xa0">Understand The Tech Being Used in Your District  </h2><p>The next step was assessing what tech was being used in the district. To do this, the Fayette IT team deployed Lightspeed Systems tools that provided analytics on technology use by students and teachers. “There were some obvious concerns,” Farmer says. “We found a lot of apps that we didn&apos;t pay for, [and] that the curriculum department didn&apos;t pay for.” </p><p>The district quickly established plans to shore up the security involved with this technology use. Going forward, student information has only been shared in apps that have been vetted and approved from a privacy and curriculum perspective. </p><h2 id="establish-tech-request-procedures-and-focus-on-rostered-technology-xa0">Establish Tech Request Procedures and Focus On Rostered Technology  </h2><p>The district has established standardized policies for educators to request permission to use new tech tools. Any app or platform that requires students to provide their names or other identifying information is not permitted. </p><p>“As long as it&apos;s not using a student name and email, and the teacher is getting good use out of it because it&apos;s engaging and interactive, then that&apos;s more of a curriculum piece,” Farmer says. “We don&apos;t really have a problem with that, but if they&apos;re signing in, and they&apos;re being rostered in any way, then that&apos;s where the bar has to be met for us.” </p><h2 id="communicate-the-importance-of-data-privacy-initiatives-xa0">Communicate the Importance of Data Privacy Initiatives  </h2><p>Four or five years ago educators may have been able to incorporate whatever technology they wanted into classes but school privacy breaches have become far more common and awareness of safety issues has risen. Consequently, school leaders have had to be more restrictive in the types of edtech tools they permit. </p><p>To build educator support, it’s very important to make the reasons for this change clear. “If we just start saying, ‘Nope, we&apos;re not using that,’ we&apos;re gonna get a lot of pushback,” Farmer says. “So we&apos;ve been doing a lot of communication and leadership meetings, we&apos;ve been doing a lot of communication with principals, and then they re-communicate that out to their staff at staff meetings.” </p><p>He adds, “If you think you&apos;re doing enough communication, do it 10 times more and you still won&apos;t be doing enough.” </p><ul><li><a href="https://www.techlearning.com/how-to/6-tips-for-protecting-student-data-privacy" target="_blank"><strong>6 Tips for Protecting Student Data Privacy</strong></a></li><li><a href="https://www.techlearning.com/how-to/school-ransomware-attacks-5-tips-to-prevent-and-survive" target="_blank"><strong>School Ransomware Attacks: 5 Tips to Prevent & Survive</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ School Ransomware Attacks: 5 Tips to Prevent & Survive  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/school-ransomware-attacks-5-tips-to-prevent-and-survive</link>
                                                                            <description>
                            <![CDATA[ Lessons learned after a district fell victim to a ransomware attack, from Brad Stewart the chief technology officer at Lufkin ISD ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jtH8jKyvjZEmkjkQGDcCDg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UAYqQAHkzBKET22NpLP7US-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Oct 2022 09:17:15 +0000</pubDate>                                                                                                                                <updated>Tue, 29 Nov 2022 20:26:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp;amp; Learning&#039;s senior staff writer. A journalist,&amp;nbsp;&lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and educator, his work has appeared in the Washington Post, The Atlantic, and Associated Press. He currently teaches at&amp;nbsp;Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology&amp;nbsp;can make that more effective.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/UAYqQAHkzBKET22NpLP7US-1280-80.png">
                                                            <media:credit><![CDATA[Mohamed Hassan from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ransomware attack]]></media:description>                                                            <media:text><![CDATA[ransomware attack]]></media:text>
                                <media:title type="plain"><![CDATA[ransomware attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UAYqQAHkzBKET22NpLP7US-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>At about 6:30 in the morning on a Monday last year, Brad Stewart got a text informing him that a principal of one of Lufkin ISD’s schools couldn’t log into the system. </p><p>After Stewart, the chief technology officer of the Texas district, got to his office, he learned the problem was much more extensive than that one principal’s inability to log in. </p><p>On the previous Friday evening hackers based in the Netherlands had gained control of four of the district’s security camera servers, and with that access, moved and encrypted district data all weekend. By Monday morning all the district’s virtual servers had been encrypted, essentially shutting down everything that relied on technology. The hackers were asking for $1.5 million dollars in bitcoin to restore the stolen data. </p><p>“When you take an entire network down, you lose things like time clocks, you lose things like air conditioning, you lose a way to check students in and out, you lose grades,” Stewart says. “Everything was down. It really left us paralyzed.” </p><p>Stewart and his team were able to restore basic services within a couple of weeks and worked tirelessly over the next six months to get most everything back online and to ensure the district would be less vulnerable in the future. For these efforts, Stewart was given an award for Best Implementation of Data Privacy at the Tech & Learning <a href="https://www.techlearningevents.com/innovativeleaderawards/home?ref=CW" target="_blank"><u><strong>Innovative Leader Awards</strong></u></a> in Texas.  </p><p>Ever since his district’s ransomware attack experience, Stewart, who is the Texas Computer Education Association Area 7 director, has been sharing the story so other districts can avoid going through what his district experienced. </p><h2 id="1-school-ransomware-attack-get-24-hour-protection-xa0">1. School Ransomware Attack: Get 24-Hour Protection  </h2><p>Many districts don’t have the funding to have a staff member monitor servers 24 hours per day to prevent a ransomware attack. Hackers know this, which is why they tend to target schools on weekends and holidays, Stewart says. </p><p>To stop such attacks, Stewart recommends hiring a 24/7 monitoring service so someone can always spot strange activity. “If I had known they were starting to make changes that Friday night, which would have shown up with 24/7 monitoring, we could have pulled the plug and prevented everything,” Stewart says. “I&apos;ve actually given the people that run that service the ability that if we see a ripple, anything, pull the plug, let&apos;s figure it out in the morning.” </p><h2 id="2-make-sure-you-have-strong-backups-xa0">2. Make Sure You Have Strong Backups </h2><p>Once you have 24-hour protection, the next step to preventing and overcoming a ransomware attack is backing up data.  “Make sure you have good backups, whether that&apos;s in the cloud or off-site, or if it&apos;s a second site,” Stewart says. </p><p>In addition to having quality system backups in place, Stewart recommends regular testing to ensure those systems are secure, working, and up to date. </p><h2 id="3-harden-your-network-apos-s-defenses">3. Harden Your Network&apos;s Defenses</h2><p> “Strengthen passwords, make sure that you have a good firewall in place,” Stewart says. Moving to two-factor authentication for all with access to the network is another way to provide extra protection, and something Lufkin ISD had not done prior to becoming a ransomware attack victim. </p><p>Staff members might push back against some of these changes, but the educators in Stewart’s district learned the hard way why such precautions are necessary. “You let people go with no internet for two months, and they&apos;ll do just about anything you tell them to do after that,” he says. </p><h2 id="4-be-aware-of-what-x2019-s-stored-on-your-network-xa0">4. Be Aware of What’s Stored on Your Network </h2><p>Prior to the ransomware attack some departments at Lufkin ISD had been storing data digitally without proper encryption. “Accounting had stuff that shouldn&apos;t have been on their desktop,” Stewart says. “HR was keeping people&apos;s information that had social security numbers and stuff in it.” </p><p>Stewart advises having conversations with department heads about the types of information that is being stored and then figuring out how to keep that information safe. Doing this before a ransomware attack can ultimately save time and money. “We ended up having to give a credit monitoring service to every employee in our district due to the fact that someone had left those files on there,” he says. </p><h2 id="5-have-a-hardcopy-of-a-ransomware-response-plan-xa0">5. Have a Hardcopy of a Ransomware Response Plan  </h2><p>“You need to have a disaster recovery plan for anything--it could be for fire, flood, hurricane, and a ransomware attack,” Stewart says. The recovery plan for a ransomware attack should include contacts at your insurance company, the name of a cybersecurity lawyer who is picked out in advance, and a plan to notify the appropriate law enforcement agencies. This document should make clear the district’s priorities and who should be called first, Stewart says. </p><p>It’s also vital for ransomware preparation that you go old school and print this plan. “It needs to be paper,” Stewart says. “It&apos;s stupid to have a digital one because you&apos;re not gonna be able to get to it.”  </p><ul><li><a href="https://www.techlearning.com/news/5-takeaways-from-ibm-study-on-school-cybersecurity" target="_blank"><strong>5 Ways to Boost School Cybersecurity</strong></a></li><li><a href="https://www.techlearning.com/news/campus-cybersecurity-tips-and-resources" target="_blank"><strong>Campus Cybersecurity Tips & Resources</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vetting Tech Tools ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/vetting-tech-tools</link>
                                                                            <description>
                            <![CDATA[ Creating clear systems for tech tool approval in your district is important, says Kimberly Ramos, instructional coach at the North Kingstown School Department in Rhode Island. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3wpQLMzu4hYAKgLA5KKXWU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uVDDmsEDMsDuWHRVAXoTx5-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jun 2022 09:00:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/uVDDmsEDMsDuWHRVAXoTx5-1280-80.png">
                                                            <media:credit><![CDATA[by Darwin Laganzon from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cartoon laptop against a blue backdrop with a red warning signal on its screen.]]></media:description>                                                            <media:text><![CDATA[A cartoon laptop against a blue backdrop with a red warning signal on its screen.]]></media:text>
                                <media:title type="plain"><![CDATA[A cartoon laptop against a blue backdrop with a red warning signal on its screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uVDDmsEDMsDuWHRVAXoTx5-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The early days of the pandemic ushered in a Wild West era for student digital privacy. Scores of online platforms started offering products for free and it was not always clear how student data would be handled. </p><p>Kimberly Ramos, a technology instructional coach at the North Kingstown School Department in Rhode Island, realized early on this could be a problem. Working with the district’s IT director and systems administration, she helped form a student data privacy plan to establish effective systems for vetting new tech tools and fielding requests from educators to use others. </p><p>For these efforts and others, Ramos was recognized with an Innovative Leader Award for Best Implementation of Data Privacy during Tech & Learning’s recent <a href="https://www.techlearning.com/news/digital-wellness-data-privacy-and-innovation-explored-at-the-tech-and-learning-leadership-summit-in-boston" target="_blank"><u><strong>Northeast Regional Leadership Summit</strong></u></a>.</p><p>From her experiences, Ramos has developed tips and best practices for vetting digital tools. </p><h2 id="standardizing-the-process-xa0">Standardizing the Process  </h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:75.05%;"><img id="K23MoxbHuxmzrt5bhjFk2C" name="Kim ramos.png" alt="Kim Ramos gives a presentation in front of a  screen with a slideshow projected on it." src="https://cdn.mos.cms.futurecdn.net/K23MoxbHuxmzrt5bhjFk2C.png" mos="" align="middle" fullscreen="" width="970" height="728" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>To protect student data, Ramos and colleagues implemented a vetting process that asks several key questions about each new tech tool, including whether the tool is of high instructional quality, whether it is in compliance with state and federal data laws, and if there is an approved budget to pay for it. The district also partners with other districts on a standard student data privacy agreement that many tech companies have already signed. </p><p>“We also have an approval process that we created for teachers who really want to stick with something that they were using before, or something that they found,” Ramos says. (See workflow graphic the district uses below</p><p>Educators can request a new tool through a Google form and then Ramos or a member of her team will work with them on answering questions about the new technology, including whether there is a privacy agreement with the company on file and how the tool will be utilized. For example, teachers will be asked, “Are other people in your grade, or your content area, going to use it, or are you the only one?” Ramos says, adding equity is also a point of emphasis. “If you&apos;re in fifth grade in one school, and then you go to fifth grade in another school, they should be using the same tools and platforms, so that everybody has a similar experience.” </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:651px;"><p class="vanilla-image-block" style="padding-top:85.71%;"><img id="EjfJB9svDRY8SoTDqnbDQH" name="Data privacy work flow.png" alt="A workflow graphic that helps teachers make decisions about technology." src="https://cdn.mos.cms.futurecdn.net/EjfJB9svDRY8SoTDqnbDQH.png" mos="" align="middle" fullscreen="" width="651" height="558" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Kim Ramos)</span></figcaption></figure><h2 id="the-vetting-process-should-be-ongoing-xa0">The Vetting Process Should be Ongoing  </h2><p>School leaders should also understand that the vetting process for tech tools is ongoing and the usage of these tools should constantly be evaluated for educational efficacy. During summer break Ramos analyzes the data surrounding each app the district uses. “For example, ‘Alright well, we had licenses for 4,000 kids, how many are actually using it this year?’ So the data will tell us if it&apos;s worth purchasing again,” she says. </p><p>The data can also help answer questions about which groups of students should get licenses. “Is it just a middle school and high school thing? Or is it just an elementary school thing?” she says. </p><h2 id="getting-teacher-buy-in-xa0">Getting Teacher Buy-In  </h2><p>When rolling out new vetting tools for digital technology it’s important to get teachers to understand the need for such vetting. “Don&apos;t be heavy-handed about it,” Ramos advises. “You need to give the ‘why’ as well as the ‘what.’” </p><p>Taking a personal approach can also help. “Rather than just sending an email, setting a deadline, and saying, ‘Okay, this is what&apos;s happening,’ I like to go to faculty meetings in every building,” Ramos says. </p><p>She’ll work with teachers during planning time and offer to help as much as she can. In addition to sending instructions, she’ll offer one-on-one meetings with teachers or to come to classrooms to work with them and their students. “I think being approachable and being flexible are the keys to that, and just making sure that people know that there&apos;s a bigger reason behind this,” Ramos says. “We&apos;re not doing this to be difficult, we&apos;re doing this because we need to protect our students.” </p><ul><li><a href="https://www.techlearning.com/how-to/6-tips-for-protecting-student-data-privacy" target="_blank"><strong>6 Tips for Protecting Student Data Privacy</strong></a></li><li><a href="https://www.techlearning.com/how-to/5-tips-for-it-leadership-from-an-award-winning-director-of-technology" target="_blank"><strong>5 Tips for IT Leadership From an Award-Winning Director of Technology</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ensuring Secure Digital Collaboration ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/ensuring-secure-digital-collaboration</link>
                                                                            <description>
                            <![CDATA[ Teaching educators the basics of cybersecurity and fostering good digital citizenship can help keep your school network secure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zunAyQVjqPJHnYK2LvPAUn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mkQo5eC6fuvjbE7NGVMztK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jun 2022 11:24:47 +0000</pubDate>                                                                                                                                <updated>Wed, 08 Jun 2022 11:27:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mkQo5eC6fuvjbE7NGVMztK-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Gerd Altmann from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand points to a digital display of various online icons.]]></media:description>                                                            <media:text><![CDATA[A hand points to a digital display of various online icons.]]></media:text>
                                <media:title type="plain"><![CDATA[A hand points to a digital display of various online icons.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mkQo5eC6fuvjbE7NGVMztK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Digital literacy and ease of use for teachers and students are important components of creating secure digital collaboration, say Drew Lane and Mary Schlegelmilch. </p><p>Lane, executive director of ICT at Shawnee Mission School District in Kansas, and Schlegelmilch, business development manager at Cisco, spoke with Dr. Kecia Ray during a recent Tech & Learning webinar sponsored by Cisco. </p><p>Watch the on-demand version <a href="https://www.techlearningevents.com/roundtable_Cisco?utm_campaign=socialflow&utm_source=twitter.com&utm_medium=social&utm_content=tech-learning&i=Rg4DIWov2EizkSUZqVcmkuI6FdSkFHI6"><u><strong>here</strong></u></a>. </p><h2 id="key-takeaways-xa0">Key Takeaways  </h2><p><strong>Plan on Planning </strong></p><p>When developing secure collaboration systems in a district, having a planning process that prioritizes flexibility is important. </p><p>“The act of planning itself is probably as important as the plan itself,” Lane said. “No matter what plan you develop, it will change as soon as you put it in place. As soon as it is tested, it will change and you will need to respond to that change.” </p><p>He added, “No plan survives first contact with the enemy. Who would have ever thought supply chain issues would be such a factor in the execution of your plans? So that&apos;s required creative thinking.” </p><p>Keeping this in mind, Lane’s district now plans five years out rather than seven, which allows for more flexibility. </p><p><strong>Use The Right Tech Tools </strong></p><p>Finding the correct use of your technology tools is as important as the quality of the tools themselves. </p><p>“Technology is a tool and like all tools you need to use it for the right thing,” Lane said. “If you use a hammer to fix a windshield, you don&apos;t get a repaired windshield.” </p><p>For example, the forced remote learning of 2020 and parts of 2021 were more challenging than many expected, Lane said. However, schools learned from the experience and know better how to use available edtech tools for both in-person and virtual learning going forward. “If we&apos;re ever in a position where we have to do a version 2.0, it will be better than version 1.0 was because we will take the lessons learned,” Lane said. </p><p><strong>Give Teachers The Support They Need to Focus on Teaching </strong></p><p>Schlegelmilch has spent time over the past two-plus years working with teachers on developing good tech pedagogy. “What I learned is that teachers really want to do what they do best, which is teach, but they also want to communicate,” she said. </p><p>To support both these goals, teachers need access to a secure network and the right tools for communication and collaboration such as easy-to-use video chat options. When technology is difficult to use for students or teachers, utilization tends to be low. “I always say, ‘Make it easy for teachers. Make it even easier for students,’” Schlegelmilch said</p><p><strong>Realize That Secure Collaboration is Linked to Digital Citizenship </strong></p><p>The Shawnee Mission School District was able to navigate remote learning and incorporate more technology without putting its students or teachers at risk from data breaches. Even though the district has avoided being hacked, school leaders learned during the pandemic that they need to do more work around digital literacy education for all school stakeholders. “Secure collaboration leads to greater digital literacy,” Lane said. “It is symbiotic. In that sense. You have to have one living with the other to get the full benefit. People didn&apos;t necessarily realize until they were using secure collaboration that insecure collaboration and cybersecurity was a threat to them at an individual level.” </p><p>District leaders are now devoting resources to ensure educators understand cybersecurity basics and its role in protecting their district’s network or networks. “We do have a responsibility if we intend to remain masters of technology and not the other way around to be digitally literate enough to understand the limitations of things like identity access management controls,” Lane said. “You have to understand how a bad actor could get into my space against my wishes, and what actions are available for me to take as a teacher to prevent that. I think that there is some water there for us to carry as educators and I think there always will be.”</p><p><strong>Define Security and Innovate </strong></p><p>It can also help to clarify what secure collaboration involves for your district. Lane said that for his district it means if they’re working with a tech platform their IT department understands the way the district’s data is stored. “They know where that data rests,” he said. “They know that that data is encrypted when it&apos;s in transit. And they know that that data is in good hands when it&apos;s decrypted and presented to your internal customer.” </p><p>Schlegelmilch said that secure tech tools that foster collaboration can help teachers continue to use technology to innovate education. “Coming out of this pandemic, I always say this is the time to truly reimagine education,” she said. “This is not the time to go back to the old normal of what we had. This is the time where we start thinking differently.” </p><ul><li><a href="https://www.techlearning.com/tag/webinars" target="_blank"><strong>Tech & Learning Webinars</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Securing & Future-Proofing Your School IT ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/securing-and-future-proofing-your-school-it</link>
                                                                            <description>
                            <![CDATA[ Experienced education IT professionals share tips on safe and equitable technology use for students and staff. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hGH5KV3rGky7RSUrdVoDx7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2aHKTew28xMoHjvSmrFaRT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Mar 2022 10:00:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2aHKTew28xMoHjvSmrFaRT-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[data]]></media:description>                                                            <media:text><![CDATA[data]]></media:text>
                                <media:title type="plain"><![CDATA[data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2aHKTew28xMoHjvSmrFaRT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>How can schools create the infrastructure that supports the equitable and safe use of technology in schools today -- and in the future? </p><p>During a recent Tech & Learning roundtable, Sandra Paul, director of IT for Township of Union Public Schools in New Jersey, and Rob Dickson, CIO for Wichita Public Schools in Kansas, discussed best practices on how school districts could implement the tools and systems to ensure IT is safe, accessible, and easy to manage. The webinar was hosted by Dr. Kecia Ray and sponsored by Microsoft. </p><p>View the on-demand version of the talk <a href="https://www.techlearningevents.com/microsoft-roundtable/1638979?i=FcTj58GtZXYNtmvVkWmmh9wIJ24ObtRD" target="_blank"><u><strong>here</strong></u></a>. </p><h2 id="access-anywhere-and-everywhere-xa0">Access Anywhere and Everywhere  </h2><p>Providing students equitable and safe access to technology goes well beyond the classroom today. “We&apos;ve accepted as a society that our kids are going to be multi-medium connectors,” Dickson said. “Before, when we thought about learning, we kept it in the confines of that classroom, or we kept it in the confines of that district.” </p><p>Paul agreed. “When it comes to equity, the biggest thing is we&apos;ve changed the whole concept of instruction and learning,” she said. “It&apos;s no longer boxed into a school district or in the four walls of the classroom. It&apos;s gone out into the community and beyond.” </p><p>Education technology leaders now need to think about the tech that is available in each student and teacher’s home and what kind of support the district can provide for effective and secure use of that technology. </p><h2 id="limits-on-use-xa0">Limits On Use </h2><p>In her district, Paul said she provided student access to educational materials but not to everything on the internet. “My whole idea was to make sure that the students get what they need, but also make sure that whatever device they&apos;re using has the filtering, or has the ability to give them what they need on an instructional site,” she said. For instance, parents were not able to check their personal emails on a school device. “We had to do workshops for parents that explained a Chromebook is not a laptop, or an iPad, or cell phone,” Paul said. </p><p>Dickson also employs filters on school-issued devices to help keep students and the school’s network secure. However, he will loosen certain restrictions with students and staff members who he knows are knowledgeable about how they are using a given device. “If I&apos;ve trained a student or a staff member on something, I’ll allow them to go a little bit further than I typically would the standard user,” he said. </p><h2 id="privacy-concerns-xa0">Privacy Concerns </h2><p>Dickson discussed how there is more awareness of data privacy in Europe and more restrictions on the way data can be gathered and used. However, more U.S. states are beginning to focus on data and the need to protect data that can be used to identify students – even if it’s not explicitly sharing a student’s name. </p><p>Paul said that leaving student security and safety up to technology directors alone is a mistake and that laws surrounding student privacy and safety need to be updated. Not only do directors have to try and protect student data but they have to help students steer a safe course while using devices that are increasingly controlled by algorithms that might prey on their insecurities by doing things such as reinforcing worries about weight or appearance. “Everybody was in a rush to give out these devices, not realizing that there is a side of it that we need to definitely step back and take a look at because the laws have not caught up,” she said. </p><h2 id="guarding-against-cyber-attacks-xa0">Guarding Against Cyber Attacks </h2><p>School IT infrastructures continue to increasingly be targets of attacks from hackers. </p><p>“It&apos;s a matter of when not if it&apos;s going to happen,” Paul said of cyberattacks. “We, as directors, try to be preventative. We try to educate and inform everyone that&apos;s a part of the entire instructional and learning process.” </p><p>In addition to providing advice on how to protect school information, IT directors also try to inform educators about protecting their own personal information. Dickson’s district has moved all staff to two-factor authentication. “That’s non-negotiable,” he said. </p><h2 id="other-steps-districts-can-take-to-protect-themselves-xa0">Other Steps Districts Can Take to Protect Themselves </h2><p>Paul advised those who are new technology leaders to connect with others in the field. “Reach out to your colleagues in the next district, your next state,” she said. “Reach out and join some national organizations. COSN has been amazing.” </p><p>Dickson is working with other tech directors in Kansas to share best practices and knowledge. “We&apos;re going to start creating peer groups where we review one another&apos;s processes and procedures,” he said. “There are some things that are very inexpensive that you can put in place to help.” </p><p>In addition, Dickson said that his district is working with Microsoft to help protect student data by providing secure platforms and help the district respond if an incident were to occur. “If something were to happen, let&apos;s say a data breach or data leak, I can contact Microsoft and have one of the largest entities in technology in the world helping me to remediate that,” he said. </p><ul><li><a href="https://www.techlearning.com/tag/webinars" target="_blank"><strong>Recent Tech & Learning Webinars</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 4 Ways To Prevent Cyberbullying  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/4-ways-to-prevent-cyberbullying</link>
                                                                            <description>
                            <![CDATA[ Chad A. Rose, the director of Mizzou Ed Bully Prevention Lab, shares tips for preventing cyberbullying. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oGM3KqsMFFq6QBcucXWqg7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EaH6cqrz8VdjHF742an4K3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Feb 2022 10:00:39 +0000</pubDate>                                                                                                                                <updated>Fri, 18 Feb 2022 13:07:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EaH6cqrz8VdjHF742an4K3-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cyberbullying]]></media:description>                                                            <media:text><![CDATA[cyberbullying]]></media:text>
                                <media:title type="plain"><![CDATA[cyberbullying]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EaH6cqrz8VdjHF742an4K3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Preventing cyberbullying is increasingly critical for education as students spend more and more time online. </p><p>“We live in a world now where bullying doesn’t begin and end with school bells,” says Chad A. Rose, director of <a href="https://www.mizzoubullypreventionlab.com/" target="_blank"><strong>Mizzou Ed Bully Prevention Lab </strong></a>at the University of Missouri. “It encompasses a kid’s entire life.”</p><p>Rose shared the following suggestions for educators who want to help prevent cyberbullying at their schools. </p><h2 id="1-preventing-cyberbullying-recognize-that-it-x2019-s-a-school-problem-even-if-it-happens-outside-of-school-xa0">1. Preventing Cyberbullying: Recognize That It’s a School Problem Even if It happens Outside of School  </h2><p>Bullying, of any kind, is defined as an imbalance of physical or emotional power, intent to cause physical or emotional harm, and behavior that is repeated or likely to be repeated, Rose says. Unlike traditional in-person bullying, cyberbullying does not necessarily occur on school grounds or even during school hours. As a result, it can be seen as an issue that is outside of school, even though cyberbullying has the potential to impact every aspect of a child’s life and education. </p><p>“I think it’s always a school issue,” Rose says. If educators acknowledge this, they can do more to prevent it and support and protect their students in their digital interactions. </p><h2 id="2-preventing-cyberbullying-teach-digital-citizenship-xa0">2. Preventing Cyberbullying: Teach Digital Citizenship </h2><p>A key to protecting students from cyberbullying is to <a href="https://www.techlearning.com/how-to/how-to-teach-digital-citizenship"><u><strong>teach digital citizenship</strong></u></a> in elementary school, Rose says. These lessons should focus on the following:  </p><ul><li><strong>Safety </strong>- Students should learn the basics of online safety, including not giving out personal information such as their name or address</li><li><strong>Choice </strong>- Students should be reminded that posting something online is a choice and that stopping and thinking before posting or sharing can often prevent an unfortunate incident</li><li><strong>Permanence -</strong> Students need to learn that things that you post online are permanent, Rose says, as even apps that claim to delete data often keep that data stored </li></ul><p>While school digital citizenship programs often do a good job with teaching online safety, Rose says more needs to be done to teach students about the other two key aspects, particularly that items posted online can be there forever. “I don’t think kids quite understand permanence,” he says.  </p><h2 id="3-preventing-cyberbullying-working-with-cyberbullies-on-sel-and-empathy-xa0">3. Preventing Cyberbullying: Working with Cyberbullies on SEL and Empathy  </h2><p>When educators discover one of their students is a perpetrator of cyberbullying they are limited in how they can respond. “You can’t tell a kid that, ‘Hey, I’m confiscating your phone that your parents paid a thousand dollars for,’” Rose says. However, educators can and should work to form a connection with parents. “Before anything happens, we should have a nice form of communication between parents and schools,” he says. That way parents of both cyberbullies and their victims can be enlisted to help find solutions. </p><p>Students who engage in cyberbullying should be given extra social and emotional learning lessons. One strategy is to build empathy by having the student and a facilitator talk through a story that is similar to the real-life situation that is occurring, and then delve into the student’s thoughts and feelings in relation to that story. If the student says they wouldn’t care if someone did that to them, an educator can teach them about empathy by explaining that other students might care. </p><h2 id="4-preventing-cyberbullying-don-x2019-t-suggest-students-stop-using-technology-xa0">4. Preventing Cyberbullying: Don’t Suggest Students Stop Using Technology  </h2><p>A common piece of advice for the victims of cyberbullying is to stop using the platform on which the bullying is taking place, however, that may not be the best approach. “We used to tell kids if someone is mistreating you, delete the app,” Rose says. “I’ve long said that we can’t just tell them to socially remove themselves.” For example, Rose says you wouldn’t tell a child to stop playing basketball if they were getting bullied on the court. </p><p>Increasingly, online spaces fulfill a similar function in children’s lives, and simply withdrawing from social media isn’t a valid option. Instead, educators need to understand the causes of bullying and work with students to develop online strategies to mitigate the impact. "Digital citizenship should be embedded in the daily curriculum, especially in environments that include high usage of electronic devices," Rose says. "This includes teaching students about the safety, choice, and permanency of interacting online."</p><ul><li><a href="https://www.techlearning.com/news/study-popular-students-are-not-always-well-liked" target="_blank"><strong>Study: Popular Students Are Not Always Well-liked</strong></a></li><li><a href="https://www.techlearning.com/news/former-us-poet-laureate-juan-felipe-herrera-shares-tips-for-teaching-poetry" target="_blank"><strong>Former U.S. Poet Laureate Juan Felipe Herrera: Using Poetry to Support SEL</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Potential E-Rate Changes: Cybersecurity and New Competitive Bidding  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/potential-e-rate-changes-cybersecurity-and-new-competitive-bidding</link>
                                                                            <description>
                            <![CDATA[ John Harrington of Funds For Learning says districts should be permitted to apply E-rate funding to cybersecurity but that proposed changes to the discount’s competitive bidding process are not necessary. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xeACu4iUMwX8zRoEQU3TuL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DUy3NoFxu2PHSeKZfsRssU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Jan 2022 10:00:47 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Jan 2022 14:21:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DUy3NoFxu2PHSeKZfsRssU-1280-80.jpg">
                                                            <media:credit><![CDATA[pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[digital access]]></media:description>                                                            <media:text><![CDATA[digital access]]></media:text>
                                <media:title type="plain"><![CDATA[digital access]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DUy3NoFxu2PHSeKZfsRssU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two major issues are on the minds of E-rate applicants this year, says John Harrington, CEO of Funds For Learning, an E-rate compliance firm. </p><p>First, Funds For Learning’s most recent E-rate Trends Report <a href="https://www.fundsforlearning.com/e-rate-data/trendsreport/" target="_blank"><u><strong>revealed</strong></u></a> that many E-rate applicants would like to see E-rate funding expanded to include cybersecurity. Second, The FCC’s has <a href="https://www.fundsforlearning.com/news/2021/12/fcc-to-consider-changes-to-e-rate-bidding-requirements/" target="_blank"><u><strong>proposed</strong></u></a> changes to the E-rate competitive bidding process in a manner Harrington and others believe could hinder the administration of the program, which provides discounts of between 20 and 90 percent on broadband access cost for schools and libraries.</p><h2 id="e-rate-cybersecurity-xa0">E-rate Cybersecurity  </h2><p>Without proper cybersecurity, school networks are vulnerable to attacks and can be shut down, leading to the loss of learning opportunities. Network breaches can also compromise student data. </p><p>Even so, many of the cybersecurity resources schools need to protect their networks currently are not eligible for E-rate funding. “The mission of the E-rate program has always been to help connect students and library patrons to the internet, and to provide the support for whatever goods and services were necessary to make that happen, and nothing else,” Harrington says. “Just the essential pieces, not just not the software that they use, or any of that, but the essential pieces.” </p><p>However, as time has gone on, Harrington says the regulations around the program have not kept pace with the way technology has evolved. “Now in order to just have a network up and running requires a whole different suite of hardware and software to keep it safe and accessible,” he says. “But the FCC has not kept the E-rate-eligible services list up to date. That is really the frustration point for school leaders today. They are looking at their networks, and it&apos;s not optional for them whether or not they provide security – they have to.” </p><p>The argument against expanding E-rate-eligible services is that there may not be enough funding to cover these additional needs. However, Harrington and others say that since E-rate funding is already capped, district leaders should be able to allocate funding as they see fit. “Provide schools the opportunity to prioritize their needs,” he says, adding that many IT directors would choose to spend money to secure their existing network rather than expand it. </p><h2 id="potential-e-rate-competitive-bidding-change-xa0">Potential E-rate Competitive Bidding Change </h2><p>The FCC has <a href="https://www.fundsforlearning.com/wp-content/uploads/2021/12/FCC-Proposed-Bidding-Portal-for-E-rate.pdf" target="_blank"><u><strong>proposed</strong></u></a> creating a bidding system in which all the E-rate requests would be processed through one centralized document portal managed by the Universal Service Administrative Company. This new system would replace the process by which service providers submit bids directly to applicants for E-Rate-supported equipment and services. </p><p>“There&apos;s a great deal of skepticism around that, because there are about 21,000 applicants that participated in the E-rate program last year, and about 45,000 different contracts that are listed on applications,” Harrington says. “Each one of those applicants has a slightly different set of rules and policies, and there are different laws governing different states, different jurisdictions, and there is not a one-size-fits-all set of rules for procurement.” </p><p>If the plan goes forward, he says, “Either the FCC is going to create a one-size-fits-all system that somehow everyone now has to adjust their bidding processes to, or they&apos;re going to have to make some incredibly complex system that can somehow accommodate all of the different requirements of these different states and different localities.” </p><p>Although the proposed change will not impact the current E-rate cycle, many school leaders are worried. Officials in California have submitted comments saying that such an application process would violate California state law. </p><p>The proposal was made in response to audits in which some E-rate recipients did not keep proper documentation of their bids. While those instances of non-compliance should be addressed, Harrington doesn’t believe a change this dramatic is warranted. “You don&apos;t have to re-engineer the entire system that&apos;s worked out really well for 24 years,” he says. </p><h2 id="what-district-leaders-and-others-can-do-to-have-the-fcc-listen-to-their-concerns-about-e-rate-xa0">What District Leaders and Others Can Do to Have The FCC Listen to Their Concerns About E-rate?  </h2><p>School leaders who want the FCC to expand E-rate funding for cybersecurity and who worry about the change to a centralized bidding system, should make their thoughts known by writing directly to the FCC while public comment is open, Harrington says. </p><p>Additionally, he advises education leaders to reach out to their local congressional representatives who may be unaware of the potential negative impact of the proposed changes. </p><p>“The E-rate program impacts every school district in America,” Harrington says. “They all depend on it. The internet connections that they have all rest on this program. And this action by the FCC could really disrupt that.” </p><ul><li><a href="https://www.techlearning.com/news/overcoming-digital-deserts-the-birth-of-bronx-digital-equity-coalition" target="_blank"><strong>Overcoming Digital Deserts: The Birth of Bronx Digital Equity Coalition</strong></a></li><li><a href="https://www.techlearning.com/news/school-cyberattacks-how-the-fbi-works-to-protect-school-districts" target="_blank"><strong>School Cyberattacks: How the FBI Works to Protect School Districts</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Campus Cybersecurity Tips & Resources  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/campus-cybersecurity-tips-and-resources</link>
                                                                            <description>
                            <![CDATA[ The culture around campus cybersecurity has evolved and so have the risks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5dQ4VDBhwaiEwKWMyC2QiV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QZkVwayF5FX6p8DGfBsE7m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Nov 2021 09:00:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QZkVwayF5FX6p8DGfBsE7m-1280-80.jpg">
                                                            <media:credit><![CDATA[Image by Stefan Coders from Pixabay .]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[information technology]]></media:description>                                                            <media:text><![CDATA[information technology]]></media:text>
                                <media:title type="plain"><![CDATA[information technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QZkVwayF5FX6p8DGfBsE7m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Prior to the start of the pandemic, chief information officers on higher ed campuses across the country developed a reputation for discouraging the use of new tech tools because of security concerns. But that has changed due to the pandemic, says Brian Kelly, director of the Cybersecurity Program at Educause. </p><p>“The cybersecurity officer, the chief information security officer, who used to be the office of ‘No,’ as in, ‘No you can&apos;t do that.’ Or, ‘No, you&apos;re not doing it correctly,’ or ‘Don&apos;t do it,’ has really moved to be the office of K-N-O-W,” Kelly says. “We want you to <em>know</em> how to do it securely.” </p><p>More communication between cybersecurity officers and instructors necessitated by the pandemic has led to a cultural shift in which instructors now see those officers as facilitators rather than gatekeepers, and go to them with questions about how to safely implement new tech tools, Kelly says. </p><p>This increased spirit of collaboration is one of many ways campus cybersecurity has evolved since March 2020. </p><h2 id="more-flexible-threats-and-a-more-flexible-defense-xa0">More Flexible Threats and a More Flexible Defense </h2><p>The pandemic moved college classrooms off campus and even though institutions have since reopened, students, professors, and staff have gotten used to connecting to school networks from wherever they are whenever they want. “Our institutional assets now are all over the place,” Kelly says. </p><p>Keeping these remote-learning and remote-work friendly networks safe has led to increased emphasis on preventative cybersecurity strategies, such as endpoint detection response (EDR), which is the process of monitoring endpoint activity in real time while identifying and halting digital threats. </p><p>With these new threats in mind, Educause offers several resources to help cybersecurity professionals, including the: </p><ul><li><a href="https://library.educause.edu/resources/2020/4/higher-education-community-vendor-assessment-toolkit" target="_blank"><u><strong>Higher Education Community Vendor Assessment Toolkit</strong></u></a><strong> </strong>A questionnaire framework specifically designed for higher ed to measure vendor risk.  </li><li><a href="https://library.educause.edu/topics/cybersecurity/endpoint-detection-and-response-edr" target="_blank"><u><strong>End Detection and Response (EDR)</strong></u></a><strong> </strong>Resources on EDR include a roundup of what you should know about EDR and a research case study conducted at Boston University.  </li></ul><h2 id="what-can-it-professionals-do-to-combat-cyber-threats-xa0">What Can IT Professionals Do to Combat Cyber Threats  </h2><p>For IT professionals, Kelly says it&apos;s important to maintain a dialog with campus stakeholders about IT policies and get feedback, noting that these policies should be formed in a collaborative way. </p><p>Beyond fostering collaboration on campus, cybersecurity professionals should remember that practice makes perfect. </p><p>“If we use the college analogy, most of our sports teams are practicing many times a week before it&apos;s game day,” Kelly says. Similarly, cybersecurity teams should be practicing what to do in the event of a ransomware attack or some other breach. “Going through those steps really helps to show the best practices to maybe point out where there&apos;s gaps in your strategies, and then you make policies and tweak from there.” </p><h2 id="what-can-instructors-do-to-protect-against-cyber-attacks-xa0">What Can Instructors Do to Protect Against Cyber Attacks?  </h2><p>Keeping those lines of communication open isn’t just the responsibility of the information security professionals on campus. Faculty and staff members should also make an effort to connect with and get to know their institution’s cybersecurity experts. For example, if a professor is interested in using a new tech tool, they should ask questions of their IT team and reach out to fellow instructors. </p><p>“We all use Yelp before we go out to a restaurant,” Kelly says. “Not to quote Ted Lasso, but be curious about the applications you’re going to use with your students, be curious about what type of data that application is collecting, how it&apos;s stored. Then ask and seek those professionals on campus for guidance, because they&apos;re there to help.” </p><ul><li><a href="https://www.techlearning.com/news/school-cyberattacks-how-the-fbi-works-to-protect-school-districts" target="_blank"><strong>School Cyberattacks: How the FBI Works to Protect School Districts</strong></a></li><li><a href="https://www.techlearning.com/news/best-cybersecurity-lessons-and-activities-for-k-12-education" target="_blank"><strong>Best Cybersecurity Lessons and Activities for K-12 Education</strong></a></li><li><a href="https://www.techlearning.com/news/5-takeaways-from-ibm-study-on-school-cybersecurity" target="_blank"><strong>5 Ways to Boost School Cybersecurity</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 6 Steps to Remove Social Security Numbers from Student Data ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/6-steps-to-remove-social-security-numbers-from-student-data</link>
                                                                            <description>
                            <![CDATA[ By removing social security numbers from student data, Greeneville City School District has increased security by making itself less of a target ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Mw3N9JvKF4XrP8tsdc98sm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pyhRXw3RZ7JmAapvKWDmUG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Oct 2021 09:30:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Beverly Miller ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pyhRXw3RZ7JmAapvKWDmUG-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[social security numbers]]></media:description>                                                            <media:text><![CDATA[social security numbers]]></media:text>
                                <media:title type="plain"><![CDATA[social security numbers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pyhRXw3RZ7JmAapvKWDmUG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It is no coincidence that K-12 organizations have become one of the most targeted sectors for cybercriminals seeking access to confidential data. Most student information systems (SIS) contain sought-after information when the goal is to illegally assume another person’s identity. Student and employee data sets most always include full, legal names, dates of birth, and far too often, social security numbers. </p><p>While still necessary to maintain employee social security numbers for tax and retirement reporting purposes, I believe it is time for schools and school districts to eradicate student social security numbers from both electronic and paper records, if they have not already done so. </p><p>The task may sound simple. However, the reality of accomplishing that feat is complex and must be strategically planned and executed. </p><p>The Greeneville City School District is located in the heart of the Appalachian Mountains in rural, eastern Tennessee. Digital records are now the norm; however, certain paper documents are still maintained in various locations throughout the district. The one warehouse in the district is not environmentally controlled with temperatures soaring during Tennessee summers and dipping throughout the winter months. To preserve these historical records, the district has a goal to digitize it all and has engaged with a vendor-partner to accomplish that task. </p><p>As the current Assistant Director of Schools for Administration, I have also served as the Chief Technology Officer for the school district for the past 27 years and have certainly observed a rapidly shifting landscape in regard to data security and information management. Never has data management been more critical than it is in today’s environment. </p><p>There are so many aspects of data security, privacy, and information management that need to be addressed. Just focusing on the elimination of student social security numbers, the following steps are the ones taken by our rural district and are recommended for others who might be facing this same challenge.</p><h2 id="6-steps-to-remove-social-security-numbers-from-student-data">6 Steps to Remove Social Security Numbers from Student Data</h2><p><strong>1. Assemble a cross-sectional team of stakeholders who have a broad knowledge base.</strong> We began by brainstorming and prioritizing what could quickly become an overwhelming project. This is the point in the process at which we identified the importance of eliminating student social security information as our top priority. </p><p><strong>2. Identify all sources of student social security information.</strong> While it may be obvious to concentrate on SIS, make sure to account for hard copies of such information that may be inside permanent records or other files. This step in the overall process can be laborious. Allow time for team members to speak with teachers, school leaders, special education experts, school secretaries, and others who will likely have pertinent information to help the project progress.  </p><p><strong>3. Communicate plans across the organization throughout the process. </strong>Like any project management endeavor, this one will not be fully successful without a robust, streamlined communication plan to keep all stakeholders involved and engaged. Parents and guardians need to know about your effort and understand the reasons behind it. Teachers need to be involved as they might be asked to provide student information when rostering as part of a software pilot project or other similar task. District leadership team members need to receive regular updates as the work progresses. School boards and local media outlets need to be involved. Invite them to serve on data security teams and work together to accomplish your goals.  </p><p><strong>4. Develop a strategic plan to address both paper and electronic record scrubbing simultaneously.</strong> It is important to have small teams focusing on specific record types. For example, we solicited the help of a couple of great special education teachers to assist our team in purging socials from historical records, which was a substantial task. Our district utilizes PowerSchool as our SIS. Our local PSUG (PowerSchool Users Group) played a tremendous role in developing a plan to begin using a unique pin number in lieu of social security number. They then tested the plan exhaustively in a sandbox environment before moving to the production server. </p><p><strong>5. Involve your state education department information systems team.</strong> We reached out to the EIS (Education Information System) team at the Tennessee State Department of Education early in our planning stages. The Tennessee EIS platform is critical because all our state education funding is generated based on the student enrollment and attendance data uploaded by local SIS extracts. Our EIS support team were instrumental in helping us map the data fields and prepare for the transition to the unique pin numbers by which students would be uniquely identified and tracked.  </p><p><strong>6. Stay the course.</strong> Any school system with a large amount of data (historical and/or current) must acknowledge that the process of removing student social security numbers will be one that requires focus, endurance, and commitment. Team members may leave. New team members may emerge. It is important to have the process documented and a training plan in place by which information and knowledge transfer can happen quickly and thoroughly. </p><p>The Greeneville City School District is now positioned to enroll and serve students without ever seeing or knowing their social security numbers. As a longtime IT professional, I often worry about the fact that many young adults may find themselves applying for college scholarships, seeking a loan to buy that first new car, or filling out an application for a job only to discover that their identity has been stolen as the result of a data breach during their K-12 school years. It gives me a sense of peace to know that social security numbers are not at risk in the district I serve. </p><ul><li><a href="https://www.techlearning.com/news/5-takeaways-from-ibm-study-on-school-cybersecurity" target="_blank"><strong>5 Ways to Boost School Cybersecurity</strong></a></li><li><a href="https://www.techlearning.com/news/best-cybersecurity-lessons-and-activities-for-k-12-education" target="_blank"><strong>Best Cybersecurity Lessons and Activities for K-12 Education</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ School Cyberattacks: How the FBI Works to Protect School Districts ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/school-cyberattacks-how-the-fbi-works-to-protect-school-districts</link>
                                                                            <description>
                            <![CDATA[ School cyberattacks are increasing, particularly ransomware attacks. The FBI has advice for keeping your school safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Dbyd9M9hAYZEom7s96X4q5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RnMVRTTjEerDszmKGamwsh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Oct 2021 09:00:54 +0000</pubDate>                                                                                                                                <updated>Fri, 22 Oct 2021 11:54:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/RnMVRTTjEerDszmKGamwsh-1280-80.png">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[school cyberattacks]]></media:description>                                                            <media:text><![CDATA[school cyberattacks]]></media:text>
                                <media:title type="plain"><![CDATA[school cyberattacks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RnMVRTTjEerDszmKGamwsh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>School cyberattacks are on the rise. Between August and September of this year, educational organizations <a href="https://gcn.com/articles/2021/09/15/k12-college-cyberattacks.aspx" target="_blank"><u><strong>were the target</strong></u></a> of more than 5.8 million malware attacks, accounting for more than half of all such attacks. Along with retail companies, educational institutions were the most likely to be targeted by ransomware attacks, according to a <a href="https://secure2.sophos.com/en-us/medialibrary/pdfs/whitepaper/sophos-state-of-ransomware-2021-wp.pdf" target="_blank"><u><strong>survey </strong></u></a>conducted by Sophos, an IT security company. </p><p>While a shift to remote learning during the pandemic may have made some attacks easier, cyber crimes have become more common in general over the past decade, says Conor Phoenix, supervisory special agent for the FBI. </p><p>The nature of the attacks has also changed, says Phoenix, who supervises the seven agents who make up the cyber squad of the FBI’s New Haven Field Office. Prior to the pandemic, swatting incidents and denial of service attacks were the most common. “In the last handful of years, ransomware is certainly the number one issue that will get reported to us by school districts,” Phoenix says. </p><p>Phoenix recently spoke to Tech & Learning about how cyber crimes against schools are conducted and shared tips for safeguarding your school against them.</p><h2 id="who-is-responsible-for-school-cyberattacks-xa0">Who is Responsible for School Cyberattacks?  </h2><p>Perpetrators of school cyberattacks range from individuals to international criminal organizations. Sometimes students even launch denial of service attacks against school systems. “It&apos;s something that a student with some computer background could be familiar with,” Phoenix says. Because this kind of attack requires only limited sophistication, students will launch one for reasons as trivial as hoping to postpone a test for which they have not studied. Ransomware attacks, on the other hand, are most commonly launched by criminal organizations outside of the U.S. </p><p>The FBI works hand-in-hand with the U.S. Attorney’s office while investigating cyber crimes, which helps determine the types of cyberattacks on schools they investigate. “For example, a denial of service attack that we were able to determine was [launched by] a student, that is not going to be taken any further by the FBI, or by the U.S. Attorney&apos;s Office,” Phoenix says. “But a ransomware incident absolutely would be.”  </p><p>Phoenix’s cyber squad primarily handles cyberattacks against schools in Connecticut but works closely with other field offices.</p><p>“There are many variants of ransomware that are deployed against victims. Those are controlled by different sets of actors. And so for efficiency, we typically have one or two offices that might focus on any one variant,” Phoenix says. “Here in Connecticut, my office focuses on two separate investigations on two different variants of ransomware and the actors behind those.” </p><p>Another example is investigations into <a href="https://www.jdsupra.com/legalnews/fbi-cisa-nsa-issue-conti-ransomware-9210077/" target="_blank"><u><strong>Conti ransomware</strong></u></a>, which is one of the most common types of ransomware used in attacks nationwide and was launched by Wizard Spider, a hacker group located in Russia. “That&apos;s investigated by two of our offices outside of Connecticut, but if there is someone who&apos;s been victimized by Conti, I know who the case agents are, my agents can talk to them, figure out what type of intelligence we can share with the victim so they can go through their own network and figure out, ‘Have we identified a point of origin for the intrusion?’ Once we&apos;ve remediated this, can we be confident that we&apos;ve removed it out of our system?” </p><p>“Then there&apos;s a law enforcement component where we&apos;re also trying to gather evidence,” Phoenix adds. “Once a victim is able to get past that immediate phase of incident response, we are trying to gather information so that we can continue to pursue those actors and hopefully, ultimately bring them to justice.”</p><h2 id="protecting-your-school-from-cyberattacks-xa0">Protecting Your School From Cyberattacks  </h2><p>Ransomware attacks tend to get into a victim’s network by either gaining access through a vulnerability in remote desktop protocol ports or via phishing emails. Preventing a remote desktop protocol intruder, often comes down to basic network hygiene. “It&apos;s making sure you don&apos;t have any remote open access that you don&apos;t absolutely need,” Phoenix says. “All computer systems will have vulnerabilities. If there&apos;s some appliance or software you&apos;re using that has a vulnerability and has a patch available, make sure that you apply that patch as quickly as possible to enhance your security.” </p><p>As for protecting against phishing emails, that is all about educating your staff. “Make sure that they can recognize a suspicious email when they see it and then know what to do with it,” Phoenix says. “Even in my own organization, we have annual information security training. One component of that has to do with phishing emails.” This is very basic, Phoenix says, but will go a long way to protecting a school district from becoming a victim. </p><p>However, no prevention methods are 100 percent impenetrable. Consequently, schools should develop an incident response plan to prepare for an attack and establish protocols for what to do when it occurs. </p><p>One part of preparing for the worst is having a backup system in place, a practice that is becoming more common as ransomware attacks increase in frequency. “I would often encounter victims who either didn&apos;t have backups, or if they did, which would have been the minority a few years ago, the backups would have been connected to the network, and then also likely encrypted as well,” Phoenix says. “But I am seeing a shift toward having backups that are separate and apart from the main network of the institution or organization. That&apos;s been extremely helpful in allowing victims to not feel compelled to pay a ransom because we&apos;re able to within maybe two or three days get their systems back up and running based on the backups.” </p><p>Getting to know local law enforcement agencies before an attack can also be helpful, as it can help schools plan who to contact when an attack occurs. While different FBI field offices respond to crimes in different regions of the U.S., the bureau has set up <a href="https://www.ic3.gov/" target="_blank"><u><strong>C3.gov</strong></u></a><strong>,</strong> an online clearinghouse for all cybercrimes. </p><p>Even if a school plans on paying a ransom to retrieve its data, the authorities should be contacted. </p><p>“The FBI&apos;s position is, in general, that we do not encourage payment of ransom in these types of situations. That being said, I understand that from a victim perspective, that&apos;s not always feasible,” Phoenix says. “We&apos;ve been dealing with these groups for some time, so we&apos;ll have information, whether it&apos;s information about the tactics of the group, or it might be information on something as simple as, ‘Well listen, if you pay this one particular group, you&apos;re not likely to get a decryption key.’” </p><ul><li><a href="https://www.techlearning.com/news/best-cybersecurity-lessons-and-activities-for-k-12-education" target="_blank"><strong>Best Cybersecurity Lessons and Activities for K-12 Education</strong></a></li><li><a href="https://www.techlearning.com/news/5-takeaways-from-ibm-study-on-school-cybersecurity" target="_blank"><strong>5 Ways to Boost School Cybersecurity</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Balancing Responsibility for Student Data and Online Safety ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/balancing-responsibility-for-student-data-and-online-safety</link>
                                                                            <description>
                            <![CDATA[ School districts face enormous challenges in protecting student data -- and students themselves -- while also fending off hackers and attackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">btGHUy43PTv67fJZ3JZ32S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ogVc7Ck7UxxAfX6srfFDx8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Oct 2021 10:30:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dr. Kecia Ray ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/a85tKi5hGZB3jYP67TBCMS.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ogVc7Ck7UxxAfX6srfFDx8-1280-80.jpg">
                                                            <media:credit><![CDATA[Unsplash: Thomas Park]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[student data]]></media:description>                                                            <media:text><![CDATA[student data]]></media:text>
                                <media:title type="plain"><![CDATA[student data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ogVc7Ck7UxxAfX6srfFDx8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>On October 8, 2021, President Biden signed the K-12 Cybersecurity Act of 2021 into law. The legislation acknowledges that maintaining the security of student data is mission-critical and, therefore, a study will be conducted to determine the best guidance to offer districts. </p><p>While this seems to be a great attempt at protecting our student data, it also represents the federal government slowly crossing the state and local authority line using legislation, policies, and letters to companies to emphasize concerns related to technology in schools, specifically cybersecurity and privacy. However, more than 45 states and Puerto Rico have introduced legislation related to cybersecurity during 2021, according to the <a href="https://www.ncsl.org/research/telecommunications-and-information-technology/cybersecurity-legislation-2021.aspx" target="_blank"><u><strong>National Conference of State Legislators</strong></u></a>. So, it begs the question: what is the purpose behind the federal legislation?  </p><p>The increased use of technology in schools will no doubt increase the risk of attacks on student data. Since 2016, there have been at least 1,062 reported attacks on school districts across the U.S., with 53 school districts being attacked in 2020 and costing more than $7.5 billion, <a href="https://amtrustfinancial.com/blog/small-business/ransomware-attacks-on-school-districts#:~:text=Since%202016%2C%20there%20were%20at,been%20victims%20of%20ransomware%20attacks." target="_blank"><u><strong>according to a recent report from Amtrust Financial</strong></u></a>. Since July, at least 16 school districts have already been victims of ransomware attacks.</p><p>In spite of these numbers, technology is no longer an option for districts. Schools must include technology in their daily practice of operating a school and delivering instruction. They must also use technology to protect student data as well as protect students themselves while they are online. </p><p>An <a href="https://childsafety.losangelescriminallawyer.pro/children-and-grooming-online-predators.html" target="_blank"><u><strong>estimated 500,000 online</strong></u></a> predators are seeking out children while they are accessing the internet. The F.B.I. reports that children aged 12-15 represent more than 50% of the victims of online sexual exploitation. </p><p>In addition to adult predators, students are also attacked by cyberbullies. <a href="https://www.security.org/resources/cyberbullying-facts-statistics/" target="_blank"><u><strong>Cyberbullying</strong></u></a> through digital devices occurs through social media, text, emails, instant messaging, and gaming. <a href="https://www.security.org/digital-safety/cyberbullying-covid/#references" target="_blank"><u><strong>Research</strong></u></a> suggests 21% of children aged 10-18 experience cyberbullying, which can lead to additional mental health issues. And, children living in <a href="https://www.security.org/resources/cyberbullying-facts-statistics/" target="_blank"><u><strong>lower-income households</strong></u></a> are more likely to be bullied online.  </p><h2 id="striking-a-balance">Striking a Balance</h2><p>Data privacy isn’t the only challenge with our students online. We must protect their safety as well, and some companies aid districts in monitoring student safety online. However, during the first week of October 2021, these companies received letters of concern from three U.S. Senators related to violating students’ privacy. </p><p>Where is the balance between protecting student data and protecting students online? Students -- and the data that come with them -- are the most fragile piece of the education system and the entire reason the system exists. No school or district administrator wakes up thinking of putting their students at risk. Districts and the schools they support must be armed with resources to protect their most significant responsibility, the safety of the students they serve. These resources come in the form of funding, technologies to monitor student activity online, technologies to protect student data, and legislation to back it when a predator or hacker is doing harm. </p><p>Although the federal government may have good intentions, it remains the responsibility of the states and local school boards to govern and direct school operations. </p><p>Cybersecurity and student data privacy are certainly huge issues for districts today and support is definitely needed to fend off hackers and attackers, but does the support need to come in the form of guidance or restricting what products and services districts can use? States have already passed legislation on handling student data, and organizations such as <a href="https://www.setda.org/" target="_blank"><u><strong>SEDTA</strong></u></a> and <a href="https://www.cosn.org/" target="_blank"><u><strong>CoSN</strong></u></a> determine effective practices for managing student data and protecting students while online, and <a href="http://www.imsglobal.org/" target="_blank"><u><strong>standards</strong></u></a> have been set to manage this. </p><p>The federal government’s role should be supporting states through funding and legislation that protects constitutional and civil rights when states fail to do so. States and local school boards must do diligence to defend the needs of their schools when it comes to protecting student data and online safety. </p><p>Interested in learning more about cybersecurity in K-12, check out these articles:</p><ul><li><a href="https://www.techlearning.com/news/best-cybersecurity-lessons-and-activities-for-k-12-education" target="_blank"><u><strong>Best Cybersecurity Lessons and Activities for K-12 Education</strong></u></a></li><li><a href="https://www.techlearning.com/how-to/how-to-implement-a-systemic-approach-to-student-data-security-and-privacy" target="_blank"><u><strong>How to Implement a Systemic Approach to Student Data Security and Privacy</strong></u></a></li><li><a href="https://www.techlearning.com/news/5-takeaways-from-ibm-study-on-school-cybersecurity" target="_blank"><u><strong>5 Ways to Boost School Cybersecurity</strong></u></a></li><li><a href="https://www.techlearning.com/how-to/how-to-integrate-student-data-privacy-protection-into-district-data-governance-plans" target="_blank"><u><strong>How to Integrate Student Data Privacy Protection into District Data Governance Plans</strong></u></a>    </li></ul><p>Want to be more informed about protecting students online? Look over these resources: </p><ul><li><a href="https://www.techlearning.com/resources/keeping-students-safe-while-learning-online" target="_blank"><u><strong>Keeping Students Safe While Learning Online</strong></u></a></li><li><a href="https://www.edutopia.org/blog/starting-point-ensuring-student-online-privacy-anne-obrien" target="_blank"><u><strong>A Starting Point for Ensuring Student Online Privacy</strong></u></a></li><li><a href="https://studentprivacymatters.org/top-10-back-to-school-student-privacy-tips-and-resources-for-parents/" target="_blank"><u><strong>10 Back-to-School Tips for Online Tips and Resources for Parents</strong></u></a>   </li></ul><p>Longing to learn more about the role of school boards, states, and federal government in overseeing education? Read over this interesting history of our educational system in these resources: </p><ul><li><a href="https://files.eric.ed.gov/fulltext/ED606970.pdf" target="_blank"><u><strong>History and Evolution of Public Education in the U.S.</strong></u></a></li><li><a href="https://www.publicschoolreview.com/blog/a-relevant-history-of-public-education-in-the-united-states" target="_blank"><u><strong>A Relevant History of Public Education in the U.S.</strong></u></a>  </li></ul><p>Our districts are under so much pressure today, let’s stand united to support their best efforts and intentions, and let’s make sure each entity responsible -- federal, state, and local school boards -- educates our amazing students and does the right thing for the good of the whole. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5 Ways to Boost School Cybersecurity  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/5-takeaways-from-ibm-study-on-school-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ The FBI recently warned that cyber attacks of schools are on the rise but an IBM survey suggests many schools are not taking the threat seriously enough ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NU9EyBk3P8mKZDa23qss8P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/P47DnHBQsfc9C6FfuDijpn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Feb 2021 10:00:18 +0000</pubDate>                                                                                                                                <updated>Fri, 19 Feb 2021 13:14:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Erik Ofgang is Tech &amp; Learning contributor. A journalist, &lt;a href=&quot;https://www.penguinrandomhouse.com/books/557664/the-good-vices-by-dr-harry-ofgang-and-erik-ofgang/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;&lt;strong&gt;author&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; and educator, his work has appeared in The New York Times, The Smithsonian, Washington Post, The Atlantic, and Forbes.com. He currently teaches at Western Connecticut State University’s MFA program. While a staff writer at Connecticut Magazine he won a Society of Professional Journalism Award for his education reporting. He is interested in how humans learn and how technology can make that more effective. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/P47DnHBQsfc9C6FfuDijpn-1280-80.jpg">
                                                            <media:credit><![CDATA[Darwin Laganzon from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ransomware]]></media:description>                                                            <media:text><![CDATA[ransomware]]></media:text>
                                <media:title type="plain"><![CDATA[ransomware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/P47DnHBQsfc9C6FfuDijpn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ransomware attacks on schools are on the rise. </p><p>More than 1,600 schools <a href="https://securityintelligence.com/posts/defend-against-ransomware-in-schools/" target="_blank"><u>were targeted</u></a> by ransomware in 2020. In December, the FBI, along with the Infrastructure Security Agency and the Multi-State Information Sharing and Analysis Center, issued an alert that nearly 60 percent of ransomware incidents between August and September 2020 involved K-12 schools, which was nearly a 30 percent jump from the two months previous. </p><p>Despite this, many schools do not appear ready for the threat. <a href="https://filecache.mediaroom.com/mr5mr_ibmnews/189762/IBM_Embargo%20Feb.%204_6%20AM%20ET_IBM%20Education%20Ransomware%20Study.pdf" target="_blank"><u>A recent study</u></a> by Morning Consult that was sponsored by IBM Security surveyed 1,000 U.S. educators and administrators.<a href="https://securityintelligence.com/posts/defend-against-ransomware-in-schools/"> </a></p><p><a href="https://securityintelligence.com/posts/defend-against-ransomware-in-schools/" target="_blank"><u>Findings include</u></a>: </p><ul><li>Nearly 60% of educators and administrators say they haven’t been given cybersecurity training for remote learning, despite nearly 80% of educators reporting they’re using online learning. </li><li>Despite the FBI’s recent warning to schools, half of educators and administrators still aren’t concerned about impending cyberattacks. </li><li>More than half of administrators and educators say budget is a barrier in securing cybersecurity for their schools. </li><li>60% of educators are using their own personal devices for remote learning, and 34% are doing so without any guidelines to protect those devices. </li></ul><p>IBM is also offering <a href="https://www.ibm.org/initiatives/ibm-service-corps/security"><u>$3 million in grants</u></a> aimed toward improving cybersecurity in schools. The deadline for districts to apply is March 1. </p><p>IBM’s Christopher D. Scott, director of Security Innovation and Remediation, office of the CISO, offers takeaways from this survey and tips for better preparing yourself and your school to ward off potential cyber attacks.</p><h2 id="recognize-the-need-for-conversations-around-security-xa0">Recognize the Need for Conversations Around Security  </h2><p>Since the mass migration to remote and hybrid classes began, Scott says teachers have been rightly focused on getting systems set up to serve the educational needs of their students, but they shouldn’t forget about securing those systems. When classes first went to video, educators realized they had to protect those video sessions against so-called Zoom bombing. Today, Scott says we need to think about the data and how to secure it.</p><p>Sometimes merely raising questions about online school security can get the ball rolling. “I found that starting that conversation is powerful,” Scott says. </p><h2 id="more-collaboration-between-schools-and-with-law-enforcement-xa0">More Collaboration Between Schools and with Law Enforcement  </h2><p>“What I&apos;m hoping that we&apos;ll see in the future is more partnering and collaboration between law enforcement, districts, and subject matter experts in cybersecurity to build out this infrastructure in a way that secures the data better,” Scott says. “You may have something where you&apos;re reporting different concerns from a physical security aspect, but maybe now we say do we have the cyber contacts at the FBI?”</p><p>He adds you should also reach out neighboring schools, take advantage of free threat sharing services, and try to share as much intel as possible within and between districts. </p><h2 id="enlist-parents-and-get-students-interested-xa0">Enlist Parents and Get Students Interested  </h2><p>Conversations around cybersecurity should also include parents. “There’s a lot of [cybersecurity] experience within the parents,” Scott says. In 2019 <a href="https://www.ibm.com/blogs/corporate-social-responsibility/2021/02/silicon-bayou-ibmers-help-louisiana/" target="_blank"><u>when a school district in Louisiana experienced a ransomware attack</u></a>, many parents in the area, who were also experts in cybersecurity, helped the district recover. </p><p>The discussions around cybersecurity not only help protect schools but can build interest in potential careers for students one day. “At IBM we talk about ‘new collar’ jobs, we talk about the fact that cybersecurity is one of the biggest growing fields, and we don&apos;t have enough people for it,” Scott says. </p><h2 id="individual-teachers-can-help-xa0">Individual Teachers Can Help </h2><p>While district-level security planning is needed, the actions of each teacher can make a difference. Scott says that just as teachers are able to physically lock their classrooms if there’s a threat in their physical school, they can also take steps to protect their remote classes. </p><p>“Consider the extra password to access a meeting. Consider looking at the email and going ‘Is this really an attachment I&apos;m expecting?’ before I open it. It&apos;s just that little moment of thought that I think each individual person can take,” he says. </p><p>Providing educators with training and simple tips on how to recognize cyber threats, such as keeping an eye out for suspicious attachments, can really help, says Scott. “When they have the information, people make really great decisions,” he says. </p><h2 id="remember-that-returning-to-in-person-school-doesn-x2019-t-eliminate-risk">Remember That Returning to In-Person School Doesn’t Eliminate Risk</h2><p>As more and more schools resume in-person learning, the risk of cyber attacks won’t decrease. One security advantage of remote school is that educators’ devices spend less time connected to a central system. When more educators return to physical buildings, their devices will spend more time connected to the central system and will talk to each other more, Scott says.</p><p>“I actually think the risk gets a little greater as we move back,” says Scott.  </p><ul><li><a href="https://www.techlearning.com/how-to/free-professional-development-helps-educators-teach-cybersecurity" target="_blank">Free Professional Development Helps Educators Teach Cybersecurity</a></li><li><a href="https://www.techlearning.com/news/how-higher-ed-is-handling-cybersecurity-during-covid-19" target="_blank">How Higher Ed is Handling Cybersecurity During COVID-19</a></li><li><a href="https://www.techlearning.com/news/updating-blooms-taxonomy-for-digital-learning" target="_blank">Updating Bloom’s Taxonomy for Digital Learning</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How Higher Ed is Handling Cybersecurity During COVID-19 ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/how-higher-ed-is-handling-cybersecurity-during-covid-19</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity during COVID-19 has been a priority for higher ed institutions as attacks have increased ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zQuthcWmHJ2YLEDc8We7WR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VLQFwYiA7cLXDsmbgWhBLo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Oct 2020 09:00:45 +0000</pubDate>                                                                                                                                <updated>Sat, 20 Feb 2021 20:42:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ erik.ofgang@futurenet.com (Erik Ofgang) ]]></author>                    <dc:creator><![CDATA[ Erik Ofgang ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/4t5ro4CXB7QUaPA28UMYb9.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VLQFwYiA7cLXDsmbgWhBLo-1280-80.jpg">
                                                            <media:credit><![CDATA[Unsplash: Petter Lagson]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VLQFwYiA7cLXDsmbgWhBLo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As with many other areas of society, the pandemic hasn’t changed threats to cybersecurity in higher ed but has amplified those that already exist, say experts. </p><p>Phishing attempts are up as hackers try to take advantage of the uncertainty pervading campuses and confusion about things such as testing. As more classes have gone hybrid or online, Zoom bombers and the like are back at it trying to disrupt video sessions. Perhaps most significantly, campus research institutions are seeing an uptick in attacks from groups associated with nation states as they try to steal data about coronavirus vaccine trials and other COVID-19 research. </p><h2 id="the-threat-phishing-scams-xa0">The Threat: Phishing scams </h2><p>“What we&apos;re seeing more of right now are people taking advantage of a lot of the disasters or worries that are out there,” says Sandy Silk, director of IT security education and consulting at <a href="https://www.harvard.edu/" target="_blank">Harvard University</a>. </p><p>Emails about free coronavirus testing or time-off policies can be easy to fake. “We have a lot of information coming to us in email and other ways, too,” says Silk. “And we&apos;re exhausted from everything spinning. So even the best of us are probably apt to click on something just without thinking.”</p><p><strong>How to guard against it</strong></p><p>“I&apos;m hoping that most schools are encouraging two-factor authentication wherever they can,” Silk says. </p><p>With two-factor verification, a hacker won’t be able to access your accounts even if they’re able to steal your password. Some learning management systems, such as Google Classroom, have this capability built-in, and Silk urges faculty members to encourage students to use it. </p><p>She adds faculty should store data on their university systems, which are vetted by their IT teams and updated constantly. </p><h2 id="the-threat-attacks-from-nation-states-xa0">The Threat: Attacks from nation states </h2><p>“Our number one concern right now has been attacks from nation states specifically focused on Covid-19 research,” says Curtis A. Carver Jr., vice president and chief information officer at The <a href="https://www.uab.edu/home/" target="_blank">University of Alabama at Birmingham</a>. “We&apos;re definitely seeing a lot of activity, as people are trying to break in and they&apos;re targeting those researchers, trying to get into those particular systems.” </p><p>At UAB <a href="https://www.uab.edu/news/research/item/11514-preclinical-study-of-covid-19-vaccine-candidate-shows-potent-t-cell-responses" target="_blank">researchers are studying</a> a potential coronavirus vaccine. In July security officials in the U.S., United Kingdom, and Canada <a href="https://www.cnn.com/2020/07/16/politics/russia-cyberattack-covid-vaccine-research/index.html" target="_blank">warned</a> that a hacking group associated with Russia was targeting institutions associated with coronavirus research. </p><p>Carver says that while similar attacks occurred in past years, incidents have intensified since the pandemic began. “These are very sophisticated attacks and it&apos;s probably every single week the FBI is reaching out to me,” Carver says.</p><p><strong>How to guard against it: </strong></p><p>UAB has an extensive <a href="https://en.wikipedia.org/wiki/Defense_in_depth_(computing)" target="_blank">Defense in Depth</a> security system that researchers are required to store data behind, and which so far they believe has fended off attacks. </p><p>“It&apos;s always hard to determine whether you&apos;re successful or not; it appears that we&apos;re being successful,” Carver says. “We have communicated with our research community that they are under attack and to follow the appropriate protocols.” </p><p>It’s also a reminder for all researchers and faculty to store any sensitive data on the universities’ approved systems, as you never know who might be trying to hack into the system and how sophisticated an attack may be. </p><h2 id="the-threat-zoom-bombing-xa0">The Threat: Zoom bombing </h2><p>While Zoom has become the most prominent video conferencing tool, Silk says other communication platforms are also vulnerable to Zoom bombing if not protected. </p><p>“If you are just using the same personal room all the time without any passcode, as soon as that gets posted anywhere public, it&apos;s not secret,” Silk says. “Once it&apos;s posted publicly and shared, if you&apos;ve never changed it, anyone can tune in at any time to something in your Zoom, WebEx, Microsoft Teams, whatever it may be.” </p><p>Hackers can even find links to video conferences that have never been posted. “There are tools that will go out and look for those potential combinations of letters and numbers that will give you a real Zoom conference,” she says. </p><p><strong>How to guard against it: </strong></p><p>Setting up your video meetings with your learning management systems will put them behind the two-factor authentication system your institution hopefully has in place, Silk says. In addition, passwords and waiting rooms should be used, and the host needs to be aware of capabilities. “How do I kick people out? How do I lock the meeting once everybody&apos;s there, so no one else comes in?” Silk says. She adds, these are important tools for hosts to familiarize themselves with. </p><ul><li><a href="https://www.techlearning.com/how-to/edtech-in-action-creating-a-cybersecurity-plan" target="_blank"><strong>Edtech In Action: Creating A Cybersecurity Plan</strong></a></li><li><a href="https://www.techlearning.com/news/cybersecurity-in-k-12-practical-advice-part-2" target="_blank"><strong>Cybersecurity in K-12: Practical Advice</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to Teach Tech in an Online Environment ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/how-to-teach-tech-in-an-online-environment</link>
                                                                            <description>
                            <![CDATA[ Ironically, teaching tech through tech is a challenge, but Champlain College Online is cracking the code ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kAxSjC8jfZVrdvwheRSvoK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KUkYmAs4J4y5JouAJGFhXG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2020 15:35:12 +0000</pubDate>                                                                                                                                <updated>Sat, 20 Feb 2021 16:35:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sascha Zuger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/gHQk3x9WMA66CvfWv6PdTH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KUkYmAs4J4y5JouAJGFhXG-1280-80.jpg">
                                                            <media:credit><![CDATA[Champlain College]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Champlain College adult student]]></media:description>                                                            <media:text><![CDATA[Champlain College adult student]]></media:text>
                                <media:title type="plain"><![CDATA[Champlain College adult student]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KUkYmAs4J4y5JouAJGFhXG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Champlain College Online—one of the oldest U.S. online higher ed Institutions (also home to a robust traditional brick-and-mortar component)—is known for technology. Targeted toward adult learners, the college offers popular degree programs in cybersecurity, digital forensics, healthcare, and business accounting, among other areas.</p><p>At first glance, it might seem tech would be one area in which remote learning is a seamless transition. Kathleen Hyde, Chair of Cyber Securities, CIS and Web Design Development of <a href="https://online.champlain.edu/" target="_blank">Champlain College</a> discusses the new challenges and offers tips to solve problems before any arise.</p><h2 id="the-good-the-bad-and-the-bug-x2019-ly">The Good, The Bad and The Bug’ly</h2><p>First, the positive news: “We have absolutely seen an uptick in potential students asking for digital forensics and cybersecurity programs," says Hyde. "They are attending webinars and asking about Computer Information Science degrees."</p><p>In addition to students looking for a general information tech degree, the institution has seen a major uptick in the web design and development program in the last five to six months. </p><p>"So much of what we do relies on web infrastructure and web technology," says Hyde. "With the pandemic, everything has moved online. In the work arena, there&apos;s an incredible need for qualified applicants for positions that are available now and are anticipated. If you weren&apos;t online before you are now."</p><p>Challenges to teaching technical skills online definitely exist, specifically in the adult learning sections. "We&apos;re talking about career changers, students coming from a variety of backgrounds, for example coming from a career in customer service and they now want to become a cyber security pro—there&apos;s a lot they have to learn," says Hyde. </p><p>In that particular case, it&apos;s important to safeguard against frustration. If there is a course that isn&apos;t designed well to teach tech, it can cause a lot of issues. Educators have to work on introducing the concepts and then leading the students to apply those concepts, says Hyde. </p><p>Bugs and hiccups can be overcome with a little foresight. For example, with the variety of backgrounds and geographical locations involved with remote learning, issues with bandwidth and available hardware are common. </p><p>"One of the things we do is provide our students with minimum hardware specs so we know they have the tools," says Hyde. "Every six months we review those specs to make sure we are telling our students exactly what they need to be successful within our program, because of the requirements needed for the different software.”</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:66.70%;"><img id="iPJKtFkATQpSJZuqRMgjoG" name="Champlain-College2.jpg" alt="Champlain College adult student" src="https://cdn.mos.cms.futurecdn.net/iPJKtFkATQpSJZuqRMgjoG.jpg" mos="" align="middle" fullscreen="" width="970" height="647" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Champlain College)</span></figcaption></figure><h2 id="pro-tips">Pro Tips</h2><p><strong>Know your students and know your industry</strong>. Everything starts here because teaching and learning is a relationship, says Hyde. Yes, it&apos;s a product, but it&apos;s critical to know what students will need in the future so that they are going to be experienced and have the skill sets required by industry. </p><p><strong>Design courses that provide value</strong>. When you are building programs, make sure to design courses that introduce key concepts and can take the students from learning the concept and the theory all the way through application. "Our students acquire skills they can use the real world," says Hyde. "Some students have those skills and they need to enhance them, others are career-changers who need to acquire those skills to apply for a position in a new field or require upskilling to maintain their current position. We allow them to apply what they learn and become familiar with software used in the industry, things such as Wire Shark, AXIOM, EnCase and also open source titles in our forensic BDI. We use a virtual environment to teach students how to actually use the software."</p><p><strong>Test for effective course design</strong>. "In the rush to bring everything online this spring, many things were rolled out and then people went, &apos;Ooh, this isn&apos;t working, we didn&apos;t anticipate this,&apos;" says Hyde, who adds it&apos;s important to leave time to test to make sure there isn&apos;t a gap. "I&apos;ve seen students introduced, say on encryption—and then told they need to encrypt something, but aren&apos;t given the steps in between. Not every student will be able to make that jump or grasp it on their own, you need to teach that and not ask them to make that leap."</p><p>Ultimately, it comes down to effective course design, a skill similar to being a good technical writer. Hyde likes to have her labs tested by someone who is not tech savvy, so she can determine whether or not the instructions are going to work and be well understood by the majority of students. Anyone participating has to be able to follow those steps with no gaps. "There&apos;s nothing more frustrating for an adult learner working a full-time job to go on late at night to work on an assignment or a lab only to realize they can&apos;t get past step three," says Hyde.</p><p><strong>Offer flexible learning options</strong>. Include a combination of real time, synchronous and asynchronous learning, says Hyde. And with all, still offer students the opportunity to have one-on-one meetings with their instructor. At Champlain, many educators have Open Hour and students can do a drop-in Zoom or Meet, or visit in-person to reduce frustration, get answers to questions, and further develop the relationship. Institutions should consider offering virtual infrastructure-supported courses for a different level of experience. Not every student has the ability to develop their own lab, so let them personally experience the learning instead of just reading about it in a textbook.</p><p><strong>Foster true conversation</strong>. In an asynchronous setting, if you have a well designed discussion question, students are going to want to come to the classroom and participate, says Hyde. The students start responding and have an ongoing dialogue. "We require our instructors to be present, not just reading and grading at the end of week," she says. "There&apos;s an expectation our instructors can engage in that discussion, bringing their personal and work life experiences to add to it, which adds a richness and creates a true conversation—that&apos;s where a lot of the learning takes place. And when the answer comes from a peer it can be more well received and memorable."</p><p><strong>Be agile</strong>. "We all were incredibly agile this spring, to suddenly shift from in-person to remote learning," says Hyde. "But we still need to think about that with respect to program and industry needs. In the midst of this we have actually changed some our programs and added certificates, blockchain and data science, to respond to the needs of the industry."</p><h2 id="tools-they-use">Tools They Use</h2><p><strong>Information Security/Cybersecurity </strong></p><ul><li>OpenVas</li><li>Nessus</li><li>Nexpose</li><li>Nmap</li><li>Hydra</li><li>Burp Suite</li><li>Zabbix</li><li>Splunk</li><li>SNORT</li><li>Recon-ng</li><li>Wpscan</li><li>Sysinternals Suite</li><li>AngryIP</li><li>Metasploitable</li><li>Logstash</li><li>Hping3</li><li>Python</li><li>Wireshark</li><li>Kali Linux</li></ul><p><strong>Digital Forensics</strong></p><ul><li>Autopsy</li><li>Magnet AXIOM</li><li>Cellebrite UFED Physical Analyzer</li><li>Cellebrite UFED Reader</li><li>EnCase</li><li>FTK Imager</li><li>NetworkMiner</li><li>OpenPuff</li><li>Python</li><li>RegRipper</li><li>Silent Eye</li><li>The Sleuth Kit</li><li>Volatility</li><li>Wireshark</li><li>X-Ways Forensics</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How It’s Done: Hands-On Cybersecurity Training  ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/how-its-done-hands-on-cybersecurity-training</link>
                                                                            <description>
                            <![CDATA[ The Cyber Fusion Center at Maryville University provides practical cybersecurity training for aspiring security professionals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WFLrPLakeKmEcSMpfYcjT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/imdgYSPjQ25xp6evvSJaZf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Jun 2020 15:25:01 +0000</pubDate>                                                                                                                                <updated>Sat, 20 Feb 2021 16:25:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ellen Ullman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/imdgYSPjQ25xp6evvSJaZf-1280-80.jpg">
                                                            <media:credit><![CDATA[ Maryville University]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two female students talk in cybersecurity lab]]></media:description>                                                            <media:text><![CDATA[Two female students talk in cybersecurity lab]]></media:text>
                                <media:title type="plain"><![CDATA[Two female students talk in cybersecurity lab]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/imdgYSPjQ25xp6evvSJaZf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When Maryville University in St. Louis opened its grant-funded <a href="https://www.maryville.edu/bu/cybersecurity/cyber-fusion-center" target="_blank">Cyber Fusion Center</a> in 2016, the institution’s leaders knew a successful program was being launched but had no idea just how valuable it would become. Given that nearly every company now conducts business digitally, the risk around security continues to proliferate. The Cyber Fusion Center gives students a front-row, hands-on learning experience.</p><p>“We provide cybersecurity services to about 20 organizations,” says Tammy M. Gocial, Ph.D., associate academic vice president and interim dean for Maryville’s John E. Simon School of Business. “We help them understand their potential vulnerability from a cyberattack and offer them support to shore up where they might be vulnerable.”</p><p>A physical lab in which Maryville students get real-world experience in data analytics and cybersecurity training, the Cyber Fusion Center also allows students to work remotely, handling everything from penetration testing and vulnerability management to digital forensics and cyber threat monitoring.</p><p>Maryville has been a front runner in online learning, having built a robust model seven years ago. Several thousand students have taken online classes, and the college prides itself on delivering strong courses in traditional and cutting-edge disciplines.</p><p>“We have 700 students who major in cybersecurity, both undergraduate and graduate, and they were able to adapt to online classes this past semester,” says Mark Lombardi, Ph.D., president of Maryville. “Through these programs we’ve reached an even greater educational awareness about the new environment we’re operating in that relies on everything from Zoom meetings to transferring information electronically.”</p><p>According to Lombardi, the pandemic has highlighted the importance of the cybersecurity program, proving yet that these kinds of skills are in tremendous demand in every industry. During the last few months of distance learning, students continued their work remotely and didn’t miss a beat. Even though some of the not-for-profits they serve did not need as much assistance, the students learned to handle different types of threats such as people hacking into Zoom meetings. “As the tactics and strategies shifted, our students adapted,” says Lombardi.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:826px;"><p class="vanilla-image-block" style="padding-top:52.78%;"><img id="2W6zTf2airXXr3jq9DqCtM" name="Ai82D3J9mYsPabCk4Chd5D-970-80.jpg" alt="Students learn in cybersecurity lab" src="https://cdn.mos.cms.futurecdn.net/2W6zTf2airXXr3jq9DqCtM.jpg" mos="" align="middle" fullscreen="" width="826" height="436" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Maryville University)</span></figcaption></figure><h2 id="solving-real-world-challenges-xa0">Solving real-world challenges </h2><p>Students can take Cyber Fusion Center courses as an elective and receive course credit or as an internship; either way, they get hands-on experience while developing crucial skills in computer forensics, ethical hacking, and information security. </p><p>The center is managed by faculty experts and staffed by students who are enrolled in Maryville’s online Bachelor of Science in Cyber Security program or online Master of Science in Cyber Security program.</p><p>As a result of the pandemic, Gocial says students are doing more with ethical hacking and helping companies navigate phishing. “With most of the workforce working from home, lots of people are mixing business and work on the same computer,” says Gocial. “People are ordering online and hackers are getting better and better at spoofing legitimate companies, especially Amazon.” </p><p>Maryville students identify these types of situations and devise ways to help companies educate their employees about what to look for and how to avoid being scammed. </p><p>After an air force base in Illinois that was tasked with building up its cyber protection asked Cyber Fusion Center students to try to hack it, a space for students to practice ethical hacking was launched. “It’s like a network sandbox,” says Gocial. “It’s a lot of fun for the students and they love the challenge!”</p><p>Overall, she says students develop a lot of synergy by working on Center projects. “With cybersecurity, there’s so much problem-solving and analysis that it’s very collaborative,” Gocial says. “It used to happen in person but now it’s happening through Zoom meetings.”</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:68.25%;"><img id="ktUDM99tyHe7dxyC77JSQN" name="tHbmwRxRRS3yZohduCusdM-970-80.jpg" alt="Male students smiling in cybersecurity lab" src="https://cdn.mos.cms.futurecdn.net/ktUDM99tyHe7dxyC77JSQN.jpg" mos="" align="middle" fullscreen="" width="970" height="662" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Maryville University)</span></figcaption></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity Planning for Next School Year ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/tech-and-learning-district-leadership-lunch-n-learn-cybersecurity-planning-for-next-year</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity planning for the school year ahead was the subject discussed by leaders from Santa Fe Public Schools and Loudon Schools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">viuemmnhbBTeHAc3jwJQcH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CBX53j7YoTG9JJL2XyABWM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2020 16:20:18 +0000</pubDate>                                                                                                                                <updated>Sun, 20 Jun 2021 19:17:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ray Bendici ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CBX53j7YoTG9JJL2XyABWM-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity planning]]></media:description>                                                            <media:text><![CDATA[cybersecurity planning]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity planning]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CBX53j7YoTG9JJL2XyABWM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In this virtual roundtable, Dr. Kecia Ray talked cybersecurity planning with Matthew Baird, Network Security Manager, Santa Fe Public School District, Tom Ryan, Chief Information and Strategy Officer, Santa Fe Public School District, Dave Lemmon, Senior Director, North America, ContentKeeper Technologies, and Vince Scheivert, Assistant Superintendent for Digital Innovation, Loudon County Public Schools. </p><p>The discussion touched upon subjects such as keeping data private, cybersecurity concerns, and monitoring online activity to make sure students are safe and content is appropriate.</p><p>See the on-demand version <a href="https://event.on24.com/wcc/r/2358773/896BDC693B1166DEE8F941BB37749C4B" target="_blank"><strong>here</strong></a></p><h2 id="key-takeaways-3">Key Takeaways</h2><p><strong>Finding balance</strong>. School IT personnel have to find the balance with providing security and promoting educational access. “The mission isn’t security,” said Tom Ryan, Chief Information and Strategy Officer, Santa Fe Public School District. “The mission is supporting the teaching and learning in a secure environment.” Having a cross-functional team helps IT teams to set the policies and standards to keep the balance that allows great teaching and learning.</p><p><strong>Threat awareness</strong>. “Cyber attacks are not unlikely to happen, they are likely to happen,” said Ryan. To that extent, you have to increase awareness of cyber threats among your end users, added Matthew Baird, Network Security Manager, Santa Fe Public School District.</p><p>Also understanding that threats are imminent should encourage leaders to proactively work with cyber insurance advisors, who can help in making informed decisions regarding issues such as ransomware attacks -- should you pay or not? Having these conversations ahead of time can help in creating a plan of action rather than waiting until you’re under attack. Districts should also stay connected with local and national security resources.</p><p><strong>Vulnerability management</strong>. Having fringe protection isn’t enough, especially with so many devices at home, said Baird. Having a good vulnerability management system is key, as it can help you accurately determine the risk level of certain vulnerabilities. It’s also important to test your ability to restore from backups -- you don’t wait until an attack has happened to see if you can rebuild a network. By testing regularly, if something does happen, you’ll know that your backups are working properly. </p><p><strong>Visibility and protection. “</strong>If you don’t see it, you can’t control it,” said Dave Lemmon, Senior Director, North America, <a href="https://www.contentkeeper.com/" target="_blank"><u><strong>ContentKeeper Technologies</strong></u></a>. You need to see all web activity to protect students, including a view of every device a school owns. Districts need to secure all sources of web traffic. Students sometimes make themselves anonymous and then poke a hole through the firewall, which creates an opening for malware or ransomware. Administrators need to be aware of what’s happening in order to protect students. For example, protecting students from accessing the dark web -- “No one knows you’re 13 on the dark web,” said Lemmon. “You have access to everything, but everyone has access to you.” Trouble will eventually find students.</p><p><strong>Control is key</strong>. Having tools such as sub-domain control builds harmony between IT and academics, said Lemmon. That level of control allows students to access certain sites or the only parts of a domain that they need, which can keep them out of trouble. It’s also important to have safety alerts that use contextual analysis. For example: If a search is doing a search with the word “kill” --  ‘To Kill a Mockingbird’ should not trigger an alert, but a search for ‘How do I kill myself?’ should. </p><p><strong>Re-herd the cats. </strong>When remote learning started, many educators found all sorts of new platforms and software to use for remote learning, but often those tools were not properly vetted by a district, said Vince Scheivert, Assistant Superintendent for Digital Innovation, Loudon County Public Schools. “How do we re-herd the cats?” asked Scheivert. “How do we bring everyone back into the safe resources and tools we use?” That’s been the goal of his team for Fall, to have everyone using the same approved resources, including video conferencing platforms. “Just like vampires can’t get into your house without being invited in, no one should get into your video conference without an invite,” said Scheivert. </p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:835px;"><p class="vanilla-image-block" style="padding-top:56.53%;"><img id="k3MLVgdGY5rgP6vGFV9cU5" name="6-3 webinar 4.jpg" alt="cybersecurity planning" src="https://cdn.mos.cms.futurecdn.net/k3MLVgdGY5rgP6vGFV9cU5.jpg" mos="" align="middle" fullscreen="" width="835" height="472" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Tom Ryan)</span></figcaption></figure><p><strong>Team effort</strong>. “Cybersecurity is everyone in the district’s job,” said Scheivert. “Everyone has a role to play.” That includes teachers, students, and parents, and everyone aware of the various cyberthreats. “There is no minimum amount of security, there’s just the maximum that you can afford,” he added. “Safety and security should support innovation, not impede it.”</p><p><strong>Special populations.</strong> How do you make special population students and parents aware of cybersecurity threats and best practices? Ryan suggested partnering with the educators who work with these students to look at what’s the appropriate way to communicate the message. Often, the educators can better communicate than IT with their students. </p><h2 id="lunch-apos-n-learn-with-tech-amp-learning">Lunch &apos;n Learn with Tech & Learning</h2><p>This report is part of Tech & Learning&apos;s <a href="https://www.techlearningevents.com/roundtables_remotelearning/503617" target="_blank">District Leadership Lunch ‘n Learn Roundtable series</a>, hosted by Dr. Kecia Ray. In this series, districts from across the U.S. share their strategic plans, the challenges they are facing, and the creative solutions they are using to support students and teachers. Access previous webinars and register for our upcoming events <a href="https://www.techlearningevents.com/roundtables_remotelearning/503617" target="_blank">here</a>. </p><h2 id="more-from-t-amp-l-lunch-apos-n-learn-roundtable-recaps-xa0">More from T&L: Lunch &apos;n Learn roundtable recaps </h2><ul><li><a href="https://www.techlearning.com/news/student-safety-strategies"><strong>Student Safety Strategies</strong></a></li><li><a href="https://www.techlearning.com/news/creating-secure-and-equitable-learning-environments"><strong>Creating Secure and Equitable Learning Environments</strong></a></li><li><a href="https://www.techlearning.com/tag/webinars"><strong>T&L Webinars</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How It's Done: Digital Forensics Master of Science Degree ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/how-to/how-its-done-digital-forensics-master-of-science-degree</link>
                                                                            <description>
                            <![CDATA[ Creating digital forensics analysts, detectives of the cyber world ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">V8kKzrXB35LoRFDhFYzABM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S9HSRYo28XUjBwqDUKxEE4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Mar 2020 11:41:55 +0000</pubDate>                                                                                                                                <updated>Sun, 21 Feb 2021 11:42:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sascha Zuger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/gHQk3x9WMA66CvfWv6PdTH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S9HSRYo28XUjBwqDUKxEE4-1280-80.jpg">
                                                            <media:credit><![CDATA[Ed Zuger]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital forensics students at the University of the Cumberlands]]></media:description>                                                            <media:text><![CDATA[Digital forensics students at the University of the Cumberlands]]></media:text>
                                <media:title type="plain"><![CDATA[Digital forensics students at the University of the Cumberlands]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S9HSRYo28XUjBwqDUKxEE4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity is clearly a growing field, with endless challenges. When things go south, digital forensics experts secure the cyber scene, collect evidence, and solve the whodunit. One Kentucky university is training these detectives of the digital world.</p><p>We chat with Ed Zuger, Associate Professor and Director of Digital Forensics, about the creation and evolution of this unique masters program.</p><p><strong>Who</strong>: University of the Cumberlands, School of Computer and Information Sciences, <a href="https://www.ucumberlands.edu/" target="_blank">ucumberlands.edu</a></p><p><strong>Where</strong>: Williamsburg, KY </p><p><strong>What</strong>: Master of Science in Digital Forensics (MSDF)</p><p>In 2014, the University of the Cumberlands, under the direction and force of Dr. Donnie Grimes, saw the severe gap between industry and government’s cybersecurity needs and the pittance of professionals, particularly leaders, with such distinct skills. We created our M.S. in Information Systems Security and within three highly successful years grew to over 100 faculty helping thousands. The natural academic and practical progression—“What next after all these cyber pros inevitably cannot stop the black hats?” It’s the uniquely talented digital forensics experts who secure the digital scene, collect evidence, and solve the whodunit. The MSDF was born.</p><p>There’s no point for us at UC to teach to our fancy, so I identified the market’s need for digital forensics analysts and made sure the necessary hard skills were balanced with complementary soft skills to create professionals, leaders, innovators who want to practice and apply their service. Atop the main MSDF curriculum of hard skills, such as mobile forensics or malware analysis, UC’s MSDF students learn the regulatory domain. They take a deep dive into evidence law; leadership and communications attuned to information security environments. It’s an education with a substrate of ethics and growth into servant-leaders.</p><p>Though we have a beautiful main campus in the bucolic Appalachian Foothills (and satellite campuses in D.C., Seattle, and Dallas-Fort Worth) all of these graduate-level, School of Computer and Information Sciences programs are available online.</p><ul><li><a href="https://www.techlearning.com/news/how-higher-ed-is-handling-cybersecurity-during-covid-19" target="_blank"><strong>How Higher Ed is Handling Cybersecurity During COVID-19</strong></a></li><li><a href="https://www.techlearning.com/news/tech-and-learning-district-leadership-lunch-n-learn-cybersecurity-planning-for-next-year" target="_blank"><strong>Cybersecurity Planning for Next School Year</strong></a></li></ul><h2 id="positive-results">Positive Results</h2><p>We’re securing your information security and privacy, first and foremost. It’s the DF version of cops chasing robbers. We’re expanding students’ opportunities in cybersecurity and IT, drawing in students with biology, real estate, and legal backgrounds to join forces with the techies and security nerds. A forensics investigation, at its base, follows the scientific process, or in a more entertaining view solves a puzzle. That, in the end, is what students become. Smart, efficient, courtroom-ready problem solvers.</p><p>Some graduates land in law firms using digital forensics to solve divorce and other civil disputes. Others enter the corporate world where keeping internal fraud, waste, and abuse out of the public eye—and operating securely in the global minefield of networks—are critical to share value. One of the first to earn the degree became a U.S. Secret Service special agent. (She’s my go-to exemplar with a biology B.S. whenever non-tech students are nervous about getting into the MSDF at UC.) </p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:66.70%;"><img id="t4cR9s9uSxC87mV7NRKuv3" name="Digital Forensics2.jpg" alt="Campus of University of the Cumberlands" src="https://cdn.mos.cms.futurecdn.net/t4cR9s9uSxC87mV7NRKuv3.jpg" mos="" align="middle" fullscreen="" width="970" height="647" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: University of the Cumberlands)</span></figcaption></figure><h2 id="biggest-challenge">Biggest Challenge</h2><p>Slow growth. Students might have a sense of the field from TV or films, but we had to really polish how we discussed digital forensics with prospective students. We have a worldwide student body so the messaging language needed to be particularly clear. </p><p>We now have a formal advisory board of talented program directors (of complementary degrees at Cumberland) who share their diverse academic experience. Sappy as it sounds, it’s the proverbial group effort that fixes things at this level.</p><h2 id="pro-tips-2">Pro Tips</h2><p>First, know that you can’t take the reins, batten down in your office and come out a couple months later, “program-in-a-can.” Build a team and immerse yourselves into the cybersecurity community. We’re surprisingly small—insular almost, but a very collegial bunch. After all, when your network gets hit, we’re all connected down-or-upstream. We’ll help you, help us. </p><p>Identify and perfect some standards to create the program skeleton. These will ultimately become your courses and learning outcomes. Make sure the institution’s leadership understands, even champions, the program. We are blessed at UC—if you do the groundwork with students’ educational welfare in mind and can conform to the mission, there’s a green light coming. This support makes all the difference. </p><h2 id="finding-funding">Finding Funding</h2><p>Successful internal budgetary proposal, alongside the academic proposal, proffered to our curriculum committee.</p><h2 id="tech-tools">Tech Tools</h2><p>Many of our DF tools are open source. By the time the student gets to my capstone project and conducts an actual forensics examination, they have a useful toolkit. </p><p>The federal government provides “dummy” hard drives and data sets to investigate. Global academicians create simulations and solutions for practice. The students “defend” their investigation via Zoom. We have encountered forensic findings from publicly acquired devices that cause me to contact state or federal law enforcement, C-level leaders of organizations, or other need-to-know actors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The State Of E-Rate ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/resources/the-state-of-e-rate</link>
                                                                            <description>
                            <![CDATA[ An excerpt from COSN’s K12 Cybersecurity cost report, released in September, argues that E-rate funds should not only make the Internet accessible to all students, but also make it safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">egZFQ3BEu5x2QK7YDYXa5J</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vVNhuoQVWvNPX3NzkS2uFC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Oct 2019 14:28:38 +0000</pubDate>                                                                                                                                <updated>Sun, 29 Dec 2019 23:00:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ TL Editors ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vVNhuoQVWvNPX3NzkS2uFC-1280-80.jpg">
                                                            <media:credit><![CDATA[GETTY IMAGES/LUCKYSTEP48]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vVNhuoQVWvNPX3NzkS2uFC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An excerpt from COSN’s K12 Cybersecurity cost report, released in September, argues that E-rate funds should not only make the Internet accessible to all students, but also make it safe.</p><p>Since the E-Rate program was created as part of the Telecommunications Act of 1996 it has helped ensure that eligible schools and libraries have affordable access to the Internet. The 2014 E-Rate modernization orders (July & December 2014) continued this commitment.</p><p>However, network access and Internet connectivity are no longer enough. While E-Rate funds help level the playing field by defraying school system costs for Internet access and network infrastructure, the very nature of the Internet has changed since the program’s inception.</p><p>The Internet is now an essential communications and data transmission conduit for education, government, business, and personal activity. In addition, it is also host to a wide range of nefarious hackers, identity thieves, and criminal and nation-state sponsored organizations utilizing networks to steal data, disrupt network activities, and destroy data systems.</p><p>The risks to school systems are only increasing as the number of data breaches and cyberattacks increase every year. According to USA Today, billions of people were affected by data breaches and cyberattacks in 2018 — 765 million in the months of April, May and June alone. In addition to data theft, ransomware attacks continue to pose a very real threat to school systems. This was recently demonstrated by the rash of ransomware attacks in Louisiana school systems in July 2019 which caused Louisiana Governor Edwards to declare a state of emergency. Louisiana’s experience is not an isolated incident; in 2018 there were over 204 million ransomware attacks worldwide.</p><p>While E-Rate should not be expected to cover all aspects of school cybersecurity, several simple changes to the E-Rate program would have a very profound impact on the ability of school systems to protect and defend their networks and systems from cyberattacks.</p><p><strong>1.</strong> Expanding the range of firewall services that can be reimbursed through E-Rate would significantly increase perimeter and data transit security for school system networks and Internet access. This would include expanding the definition of covered firewall equipment and services in Category 2 beyond the current basic firewall functionality of ingress/egress traffic management to encompass advanced protections such as intrusion detection/prevention systems (IDS/IPS), advanced threat protection (ATP), anti-virus/anti-malware filtering, SSL encryption, encrypted traffic inspection, data loss prevention(DLP), and spam filtering. These are examples of additional functionality available on next generation firewalls that are not currently funded by E-Rate.</p><p><strong>2.</strong> Expanding E-Rate to cover advanced security services provided by a school system’s Internet Service Provider, including DDoS mitigation and the same advanced firewall features recommended to be added under Category 1, would both enhance school system cybersecurity and remove the burden of finding staffing to support these systems. Currently, ERate will discount basic ingress/egress firewalls provided by the Internet Service Provider, if that is part of the ISPs basic service package. However, this is limited to the most basic of firewall functionality. Expanding the definition of covered firewall services that an ISP could provide would allow school systems to contract with their ISP for advanced firewall features to protect their networks, and have the ISP be responsible for operating and managing these systems, reducing the burden on school systems to find positions and qualified staff to do this work in house. Many school systems use the same ISP provider, being able to purchase advanced firewall functionality through the ISP could be more cost-effective and leverage economies of scale driving down the price as more school systems purchase additional cybersecurity services. E-Rate does not currently offer discounts for distributed denial of service (DDoS) mitigation services that help school systems maintain connectivity and availability when faced with a DDoS attack. Where school systems have been able to find funding for DDoS mitigation provided by their ISP, this has been an effective method to mitigate the impact of DDoS attacks on teaching and learning and deter future attacks. Those districts have found the rates of attempted DDoS attacks decrease once attackers discover DDoS mitigation has rendered this attack vector ineffective.</p><p><strong>3.</strong> Clarifying or updating the definition of “basic firewall” to align with technology industry standards would enable school systems to align their cybersecurity defenses with recognized industry standards and provide improved protection of their networks. E-Rate currently funds “basic firewall” services in both Category 1 and Category 2, and “basic” has been interpreted to be limited to ingress/egress traffic management. As noted earlier, this leaves school systems with inadequate firewall defenses. This definition of “basic firewall” no longer aligns with technology industry standards.</p><p>A “standard” firewall across the technology industry is typically a next generation firewall (NGFW) or unified threat management (UTM) appliance or service that offers, but is not limited to, the following protections:</p><p>■ Advanced threat protection (ATP)<br>■ Anti-virus & anti-malware protection<br>■ Data loss prevention (DLP)<br>■ DDoS mitigation » Intrusion detection/protection (IDS/IPS)<br>■ SSL inspection<br>■ Virtual private network (VPN)<br>■ Web filtering</p><p>As new cybersecurity defense technologies become available, the definition of discounted firewall services should expand to encompass current protections.</p><p><strong>4.</strong> Making managed security services and/or security operations center (SOC) services for the purposes of monitoring and responding to cybersecurity attacks and incursions eligible for E-Rate funding would significantly improve the ability of school systems to monitor and defend their networks. Managed security services and SOCs leverage economies of scale to monitor and respond to security incidents across multiple organizations’ networks. The ability to fund participation in these services through E-Rate would expand school system access to cybersecurity tools and trained resources, removing staffing and technology funding challenges from the cybersecurity equation.</p><p><strong>5.</strong> Adding web content filtering to the list of discounted services would remove a significant financial burden from school systems. The implementation of web content filtering is required for participation in the E-Rate program but is not a covered expense. The FCC’s 2014 E-rate Modernization Order reiterates, citing to the 2001 Children’s Internet Protection Act Order, the agency’s position that the Children’s Internet Protection Act prohibits the use of Universal Service Fund resources for filtering. We believe Congress’s intent was for that prohibition to apply to other appropriated funding, and not E-rate funds, and we urge the FCC to work with Congress to address this issue.</p><p>The E-Rate program has the opportunity to significantly improve the cybersecurity stance of currently funded networks and Internet access. An E-Rate program that does not address the lack of adequate funding for school cybersecurity equipment, services and personnel is putting schools and their communities at risk. The recommendations above do not include expansion of E-Rate funding to include user and end point protection technologies such as anti-virus/anti-malware endpoint protection, multi-factor authentication, mobile device management, and identity and access management. Those technologies are targeted toward end user devices and access, and as such, are less directly correlated to E-Rate’s goal of providing network and Internet connectivity and access to schools. The recommended changes focus on providing responsible and secure network and Internet connectivity and access to schools.</p><p>For the full report, go to: <a href="https://d31hzlhk6di2h5.cloudfront.net/20190903/dc/58/ef/e2/bf672a44bdce9162a0ccc373/cosn_cybersecurity_cost_report.pdf" target="_blank"><em>tinyurl.com/y5tg7xa2</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Digital Resources for National Cyber Security and National Bullying Prevention Month ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/digital-resources-for-national-cyber-security-and-national-bullying-prevention-month</link>
                                                                            <description>
                            <![CDATA[ Digital Resources for National Cyber Security and National Bullying Prevention Month ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SFVRvk8VKfcPuYBuhEQ9Hk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NS9RzEgNWfxPV4qgCQnRBh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Oct 2019 09:34:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Deborah Marshall and Lisa McKnight Ward ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NS9RzEgNWfxPV4qgCQnRBh-1280-80.jpg">
                                                            <media:credit><![CDATA[iStock/Highwaystarz-Photography]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sad teen girl looks at her cell phone while two girls in the background smirk]]></media:description>                                                            <media:text><![CDATA[Sad teen girl looks at her cell phone while two girls in the background smirk]]></media:text>
                                <media:title type="plain"><![CDATA[Sad teen girl looks at her cell phone while two girls in the background smirk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NS9RzEgNWfxPV4qgCQnRBh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>October is <strong>National Cyber Security and National Bullying Prevention Month</strong>. This is a perfect time for lessons and discussions in classrooms throughout the school building.  Discussions can be as simple as a pre-writing that starts at the first few minutes of class as a warm up activity or a full lesson that links Cyber Security to concepts or standards in that course.  Topics can include: Facts & Figures: Cyber Bullying and How to make positive change. See the link below for more information from the <strong>Do Something Global Movement</strong>. </p><p>To continue our Technology Literacy them, teens should read about Smartphone Security Checker to secure their mobile phones or learn about how to use public WiFi safely. Whether you teach Cyber Security, Social Studies, Economics & Personal Finance or Career & Technical Education there is something for every level.<br><br><strong>Cyber Bullying Information: </strong><br>Information from the government website to stop bullying <a href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.stopbullying.gov%2Fcyberbullying%2Fwhat-is-it%2Findex.html&data=02%7C01%7Cdmarshall%40nps.k12.va.us%7Ca69b2af0e34f4a0880fc08d745d29ff4%7C0c3b3cb60d6a4d31b043f61fb69363d3%7C0%7C0%7C637054643249265651&sdata=VwRKMycnFWlyJyYYFPHeQh5poZodAOVBm1lJ%2Fsyy0DM%3D&reserved=0">https://www.stopbullying.gov/cyberbullying/what-is-it/index.html</a><br> <br><strong>Facts about Cyber bullying from the Do Something global movement</strong> <a href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.dosomething.org%2Fus%2Ffacts%2F11-facts-about-cyber-bullying&data=02%7C01%7Cdmarshall%40nps.k12.va.us%7Ca69b2af0e34f4a0880fc08d745d29ff4%7C0c3b3cb60d6a4d31b043f61fb69363d3%7C0%7C0%7C637054643249275643&sdata=561lR7njKk03srE7VBTnZKlopXaYqRtlu9lSHl8bCRM%3D&reserved=0">https://www.dosomething.org/us/facts/11-facts-about-cyber-bullying</a>   Stats, information handouts, and even a bookmark you can download which has a pledge the kids can sign. <a href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.pacer.org%2Fbullying%2Fresources%2Fcyberbullying%2F&data=02%7C01%7Cdmarshall%40nps.k12.va.us%7Ca69b2af0e34f4a0880fc08d745d29ff4%7C0c3b3cb60d6a4d31b043f61fb69363d3%7C0%7C0%7C637054643249275643&sdata=c0nVRNtPdWMBbY3Y4HtPRudsgmPCORrmkoAXBbVZgTk%3D&reserved=0">https://www.pacer.org/bullying/resources/cyberbullying/</a>  <br><br><strong>Cyber Security Information</strong><br>The Department of Homeland Security offers student resources. <a href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.dhs.gov%2Fpublication%2Fstopthinkconnect-student-resources&data=02%7C01%7Cdmarshall%40nps.k12.va.us%7C4387271d11124619396508d745cb9d1e%7C0c3b3cb60d6a4d31b043f61fb69363d3%7C0%7C0%7C637054613136604897&sdata=hK0O1P9%2FsEJ16AxGDAk4HMcb1NPSLD6KJ%2FkVoTzZ4X4%3D&reserved=0">https://www.dhs.gov/publication/stopthinkconnect-student-resources</a><br><br><strong>Websites with tips and tip sheets</strong> about digital declutters, staying safe on vacation and at tax time and even a  Cyber Safety "tech talk" for parents to give their kids. Sheets may be downloaded in many languages. <a href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fstopthinkconnect.org%2Ftips-advice%2Fgeneral-tips-and-advice&data=02%7C01%7Cdmarshall%40nps.k12.va.us%7C4387271d11124619396508d745cb9d1e%7C0c3b3cb60d6a4d31b043f61fb69363d3%7C0%7C0%7C637054613136604897&sdata=uKRMjm9L6FkqR%2FKgYsLpGCPnWeaF%2FMav%2BD8g5ji00fU%3D&reserved=0">https://stopthinkconnect.org/tips-advice/general-tips-and-advice</a><br><br>NICCS: <strong>National Initiative for CyberSecurity Careers and Studies:  Resources for Teachers: </strong><a href="https://niccs.us-cert.gov/formal-education/integrating-cybersecurity-classroom">https://niccs.us-cert.gov/formal-education/integrating-cybersecurity-classroom</a> <br><br><strong>NICE CyberSecurity Workforce Framework</strong> <a href="https://niccs.us-cert.gov/workforce-development/cyber-security-workforce-framework">https://niccs.us-cert.gov/workforce-development/cyber-security-workforce-framework</a> <br><br><strong>Cyber Security Career Profiles</strong>: <a href="https://niccs.us-cert.gov/sites/default/files/documents/pdf/career%20profiles5.pdf?trackDocs=career%20profiles5.pdf">https://niccs.us-cert.gov/sites/default/files/documents/pdf/career%20profiles5.pdf?trackDocs=career%20profiles5.pdf</a> <br><br><strong>Brochure:</strong> <a href="https://niccs.us-cert.gov/sites/default/files/documents/pdf/cda_cybereducation_5ways_final.pdf?trackDocs=cda_cybereducation_5ways_final.pdf">https://niccs.us-cert.gov/sites/default/files/documents/pdf/cda_cybereducation_5ways_final.pdf?trackDocs=cda_cybereducation_5ways_final.pdf</a> <br><br><strong>Posters: </strong><a href="https://niccs.us-cert.gov/sites/default/files/documents/pdf/cea_cybersecurityeducationalposters_20190222_v11f.pdf?trackDocs=cea_cybersecurityeducationalposters_20190222_v11f.pdf">https://niccs.us-cert.gov/sites/default/files/documents/pdf/cea_cybersecurityeducationalposters_20190222_v11f.pdf?trackDocs=cea_cybersecurityeducationalposters_20190222_v11f.pdf</a> <br><br>From NICERC: <strong>An Academic Division of The Innovation Center  Cipher Disk Activity</strong>: A great hands on way to learn encryption and decryption. <a href="https://nicerc.org/2018/09/classroom-activity-cipher-disk-student/">https://nicerc.org/2018/09/classroom-activity-cipher-disk-student/</a> <br><br><strong>The Secret Code of Lewis’s and Clark. Password Challenge for Students</strong> <a href="https://nicerc.org/2018/09/classroom-activity-the-secret-code-of-lewis-and-clark-student/">https://nicerc.org/2018/09/classroom-activity-the-secret-code-of-lewis-and-clark-student/</a> <br><br>November/Upcoming Events:<br><br>GIS Day: Geographic Information Systems (GIS): November 13: <a href="http://www.gisday.com/">http://www.gisday.com/</a><br><br>Enjoy October!</p><p><em>cross posted at</em> <a href="https://collaborationsdigitalandotherwise.weebly.com/january.html"><em>collaborationsdigitalandotherwise.weebly.com</em></a></p><p><em>Deborah Marshall is the Department Chair of Career & Technical Education and Lisa McKnight Ward is the librarian at Granby High School in Norfolk, Virginia. Both are</em> <em>Nationally Board Certified,</em> <em>former Teachers of the Year, who have taught multiple subjects including AP and IB courses. They have over a decade of experience</em> <em>collaborating on technology-based learning. Read more at</em><a href="https://collaborationsdigitalandotherwise.weebly.com/"><em> collaborationsdigitalandotherwise.weebly.com/</em></a><br></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 4 Reasons Why You Shouldn't Limit Tech Use to A Communal Area ]]></title>
                                                                                                                                                                                                <link>https://www.techlearning.com/news/4-reasons-why-you-shouldnt-limit-tech-use-to-a-communal-area</link>
                                                                            <description>
                            <![CDATA[ Innovative educators should help parents see past simplified safety advice like: only use technology in a communal area. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FutDmLnCFtZKsQPrCfAVEa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/76x38fU8SqPqiWyHiUsANd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Apr 2019 09:07:05 +0000</pubDate>                                                                                                                                <updated>Tue, 09 Apr 2019 09:21:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Lisa Nielsen ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/76x38fU8SqPqiWyHiUsANd-1280-80.jpg">
                                                            <media:credit><![CDATA[Thinkstock/Jacob Ammentorp Lund]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Five teens studying and laughing with laptop computers]]></media:description>                                                            <media:text><![CDATA[Five teens studying and laughing with laptop computers]]></media:text>
                                <media:title type="plain"><![CDATA[Five teens studying and laughing with laptop computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/76x38fU8SqPqiWyHiUsANd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:86.41%;"><img id="ZCZncHBer5wDtTppWvK5NQ" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZCZncHBer5wDtTppWvK5NQ.jpg" mos="" align="right" fullscreen="" width="1280" height="1106" attribution="" endorsement="" class="pull-right"></p></div></div></figure><p> Youth need privacy for healthy growth, development, and to work through ideas. Yet in these monitoring-obsessed days of child-rearing, privacy is often thrown to the side in exchange for surveillance. <br><br>That&apos;s why innovative educators help parents see past simplified safety advice like: only use technology in a communal area. While imposing such restrictions is easy and may give a false sense of security, it is ineffective.</p><p><strong>Here&apos;s why:</strong></p><h2 id="does-not-foster-trust">Does not foster trust</h2><p>What&apos;s better than monitoring is working to foster trust and staying connected with your child. When you have developed connections and communication, your child is more likely to share what she’s up to.</p><h2 id="drives-behavior-underground">Drives behavior underground</h2><p>Monitoring doesn&apos;t stop bad behavior, it drives it underground. Find out for yourself. Ask a teen who&apos;s monitored if it makes them stop doing something or just become better at <a href="https://www.psychologytoday.com/us/blog/our-gender-ourselves/201312/why-teens-need-privacy-online">lying about what they&apos;re doing</a>.</p><h2 id="your-child-needs-privacy-xa0">Your child needs privacy </h2><p>Wanting privacy goes along with the development of independence. A young person doesn&apos;t want all their thoughts, feelings, and creations on display. Privacy allows young people to work out their thinking and feelings in a safe place.</p><h2 id="does-not-promote-safe-independent-use">Does not promote safe independent use</h2><p>Your child is not always going to be using technology at home and you are not always going to be there to monitor them. More effective than surveillance is supporting your child in using technology effectively. This means fostering a trusting relationship where you can speak to one another.</p><p>What do you think? Is this in alignment with advice you give parents? How are you helping to instill responsible use in the youth with whom you work? </p><p><a href="http://theinnovativeeducator.blogspot.com/"><u><em>Lisa Nielsen</em></u></a> <em>(</em><a href="https://twitter.com/InnovativeEdu/"><u><em>@InnovativeEdu</em></u></a><em>) has worked as a public-school educator and administrator since 1997. She is a prolific writer best known for her award-winning blog,</em><a href="http://www.innovativeeducator.com/"> <u><em>The Innovative Educator</em></u></a><em>. Nielsen is the author of</em><a href="https://theinnovativeeducator.blogspot.com/p/my-book.html"> <u><em>several books</em></u></a><em>and her writing has been featured in media outlets such as</em><a href="http://www.nytimes.com/schoolbook/2011/11/01/cellphones-why-not-use-them-to-teach/"> <u><em>The New York Times</em></u></a><em>,</em><a href="http://www.wsj.com/articles/does-technology-belong-in-classroom-instruction-1431100454"><u><em>The Wall Street Journal</em></u></a><em>,</em> <a href="https://www.techlearning.com/"><u><em>Tech&Learning</em></u></a><em>, and</em> <a href="http://thejournal.com/articles/2011/11/09/7-byod-myths.aspx"><u><em>T.H.E. Journal</em></u></a><em>.</em>  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>