After Ransomware Attack, District Hopes to Mandate Security Awareness

After Ransomware Attack, District Hopes to Mandate Security Awareness

An Illinois school district is working "around the clock" to bring its network back up after a ransomware attack. The problems struck Rockford Public School District 205 on Sept. 6, 2019, during the same week its 28,000 students returned to the classroom.

Outages included many of the district's phones, as well as its website and student information systems. Currently, the district is using its Facebook page to communicate with the community.

In statements to parents and staff, the school system reported that its IT team was working with an outside forensics firm to restore access. "Our No. 1 priority is the safety of our students and staff," an early notice stated. "This includes protecting staff and students' data and information. We have field experts helping our IT team evaluate the impact of this outage. We are working to get a complete picture of this incident and understand any impact to our data. We will provide additional updates and information when they’re available."

In a subsequent post last week, the district said that while it didn't appear that any personal information had been accessed by attackers, "user names and passwords might have been involved." As a result, when the computing systems are back online, users will need to change their passwords to gain access. They were also advised to change the passwords used on district-issued devices as well.

This week the district predicted that it would "hit several milestones" in its repair efforts, including restoring access to phones, bells and PA systems; providing staff with access to Google, Google Classroom and Google Drive; and restoring access to districtwide Wi-Fi so students could use their Chromebooks in class. "Our Information Technology team is working around the clock to rebuild our network and restore access," the Rockland officials wrote.

School board officials at Rockland will also vote later this week on spending $376,300 for IT upgrades. In a recommendation submitted by Executive Director of Technology, Jason Barthel, the allocations include $41,108 for "mandated" security awareness training from KnowBe4, which will be "specifically targeted to every...staff member".

The proposal also requested renewals of security software, including a Palo Alto Networks firewall subscription ($178,770 for three years), Sophos antivirus ($125,787 for four years) and Veeam for backup ($30,634 for an annual license).

Barthel noted in the document that his division would also begin reporting on the district's IT security status quarterly to the cabinet.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • students using digital devices, surrounded by abstract AI motifs and soft geometric design

    Ed Tech Startup Kira Launches AI-Native Learning Platform

    A new K-12 learning platform aims to bring personalized education to every student. Kira, one of the latest ed tech ventures from Andrew Ng, former director of Stanford's AI Lab and co-founder of Coursera and DeepLearning.AI, "integrates artificial intelligence directly into every educational workflow — from lesson planning and instruction to grading, intervention, and reporting," according to a news announcement.

  • toolbox featuring a circuit-like AI symbol and containing a screwdriver, wrench, and hammer

    Microsoft Launches AI Tools for Educators

    Microsoft has introduced a variety of AI tools aimed at helping educators develop personalized learning experiences for their students, create content more efficiently, and increase student engagement.

  • laptop displaying a red padlock icon sits on a wooden desk with a digital network interface background

    Reports Point to Domain Controllers as Prime Ransomware Targets

    A recent report from Microsoft reinforces warns of the critical role Active Directory (AD) domain controllers play in large-scale ransomware attacks, aligning with U.S. government advisories on the persistent threat of AD compromise.

  • Two hands shaking in the center with subtle technology icons, graphs, binary code, and a padlock in the dark blue background

    Two Areas for K-12 Schools to Assess for When to Work with a Managed Services Provider

    The complexity of today’s IT network infrastructure and increased cybersecurity risk are quickly moving beyond many school districts’ ability to manage on their own. But a new technology model, a partnership with a managed services provider, offers a way forward for schools to overcome these challenges.