{"id":18381,"date":"2017-11-06T12:55:20","date_gmt":"2017-11-06T08:55:20","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/?p=18381"},"modified":"2017-11-06T12:55:20","modified_gmt":"2017-11-06T08:55:20","slug":"whaat-you-can-learn-from-recent-cyber-attacks-targeting-school-systems","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2017\/11\/06\/whaat-you-can-learn-from-recent-cyber-attacks-targeting-school-systems\/","title":{"rendered":"What you can learn from recent cyber attacks targeting school systems"},"content":{"rendered":"<p>Just after the school year commenced, Steve Bradshaw, superintendent of the Columbia Falls, Montana, schools got a menacing text from a number he didn\u2019t recognise. The cyber thug behind the message made a myriad of threats \u2013 including physical harm to district students and staff and releasing their personal information \u2013 unless a ransom was paid in Bitcoin. The community was thrust into a panic, and the district closed its 30 schools for three days. Was this response warranted or appropriate?<\/p>\n<p>Until recently, cyber attackers mostly targeted businesses and nonprofits large and small. But this celebrated case, which was eventually solved, shows that K-12 schools need much of the same cyber safety practices and policies as enterprises.<\/p>\n<p>In fact, Education Week just reported how there has been a spike in ransomware targeting K-12 schools.<\/p>\n<p><strong>Why hackers target schools<\/strong><\/p>\n<p>Schools are compelling targets for cybercriminals because they have lots of data that are valuable on the black market, according to Matthew Gardiner, senior product marketing manager. That includes Social Security Numbers, addresses, medical information and, in some cases, financial information, as well as connections to municipalities and vendors. \u201cThere are a lot of people coming through schools and they all have personal information held by the school \u2013 even one school can be made up of thousands of people.\u201d<\/p>\n<p>Capitalising on the human impulse to protect our children and to panic when they are threatened, the attackers chose language specifically designed to frighten recipients into action. And panic is one of a cybercriminals&#8217; best friends.<\/p>\n<p>\u201cCybercriminals aren\u2019t above trying to scare you to get paid,\u201d Gardiner adds, \u201cand they\u2019ll do whatever\u2019s necessary.\u201d Whether it is ransoming your data and systems back to you or threatening to dump sensitive communications into the public domain. Whatever it is, what you don\u2019t want them to do is what they will threaten to \u2013 and sometimes actually do \u2013 to increase a school systems&#8217; willingness to pay up.<\/p>\n<p>Schools also get targeted because \u201ctheir networks tend to be quite open in order to facilitate the free flow of information. This can make them somewhat easy to compromise,\u201d notes Jason McNew, CEO of Stronghold Cybersecurity and a former school board director. \u201cTo a cybercriminal, this equates to low barrier to entry, with medium returns. If a hacker needs to make a few bucks, it makes sense to target schools.\u201d In addition, most school systems have nowhere near the security sophistication or personnel as a bank or telecommunications company might have.<\/p>\n<p>The takeaway for district administrators? Don\u2019t assume because you\u2019re a school, you\u2019re not at risk from a cyberattack.<\/p>\n<p><strong>How to be better prepared for school cyber attacks<\/strong><\/p>\n<p>School districts need to become as vigilant about cybercrime as they are about cyberbullying and physical threats.<\/p>\n<p>\u201cEven though it&#8217;s not mandated by law, schools need to voluntarily create and implement a comprehensive cybersecurity program based on one of the well-known frameworks such as NIST 800 or ISO 27000,\u201d notes McNew, who previously worked for the White House Communications Agency\/Camp David and held one of the highest security clearances.<\/p>\n<p>Part of that plan must include email. Why? \u201cEmail is the dominant attack vector, so if someone\u2019s going to come at you, it\u2019s most likely going to be through email,\u201d Gardiner explains.<\/p>\n<ol>\n<li><strong>Develop a set of district email best practices.<\/strong> While your district or state IT team can be helpful here, it\u2019s best to work with external experts who live and breathe cybersecurity every day.Look for a partner who wants to collaborate with you, rather completely outsourcing the plan.Learn how to prepare for and respond to an email-based attack.<\/li>\n<li><strong>Train students, staff, and teachers on these cybersecurity practices.<\/strong> It\u2019s important to involve everyone who has access to email and other computer applications, from top administrators to teachers\u2019 aides and including students and PTAs. Outside experts like law enforcement or information security consultants are great resources for this training. You can even blend this with the school cyber safety and anti-bullying training. See how to structure your cybersecurity training.<\/li>\n<li><strong>Strengthen defences with cybersecurity solutions.<\/strong> Use technology to support strong authentication practices, provide antivirus protection and ensure email security as part of your basic security program. Look for a solution with a fraud defence system that blocks and quarantines suspect emails and a detection function that analyses links and attachments and removes malicious emails in real time when an attack is occurring. Get more details on email security solutions.<\/li>\n<li><strong>Integrate a cybercrime response into your school crisis plan.<\/strong> In addition to the response plan and team you have for physical threats, you need another for cyber threats. First, you need some technical expertise on the cyber team. Second, as we saw in Montana, sometimes the threats of physical violence coincide with a cyber attack \u2013 and one team can\u2019t manage both. Read about how to create crisis response and communications plans.<\/li>\n<\/ol>\n<p>Use this information to address school cyber threats as effectively as you treat physical ones.    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just after the school year commenced, Steve Bradshaw, superintendent of the Columbia Falls, Montana, schools got a menacing text from a number he didn\u2019t recognise. The cyber thug behind the message made a myriad of threats \u2013 including physical harm to district students and staff and releasing their personal information \u2013 unless a ransom was [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":18383,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1233,608,57,14,189],"tags":[1251,1252,1253,1254,1255,1256,1257,1258,1259,1260,69,1261,1262,1263,1264,1265,1266,1267,1268,1269],"class_list":["post-18381","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blogs","category-education","category-enterprise-security","category-more-news","category-regional-news","tag-bitcoin","tag-cyber-attackers","tag-cyber-safety","tag-cyberbullying","tag-cybercrime","tag-cybercrime-response","tag-cybercriminals","tag-cybersecurity-program","tag-cybersecurity-solutions","tag-cybersecurity-training","tag-data","tag-dominant-attack-vector","tag-education-week","tag-email","tag-email-security","tag-email-based-attack","tag-fraud-defence-system","tag-k-12-schools","tag-ransomware","tag-school-crisis-plan"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/18381","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=18381"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/18381\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/18383"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=18381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=18381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=18381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}