
The summer season has come to an end, and children across America are back in school. If you missed the opportunity to test your data security measures while your students were away, here are the things you must do at the start of the academic year to get your cybersecurity ducks in a row.
As you may very well know, cybercriminals don’t hold themselves back from victimizing innocent little children, school teachers humbly living out their vocation, or anyone, really. Therefore, beyond fostering kids’ minds and bodies, schools now have the additional responsibility of protecting them from the dangers lurking in an increasingly digitized world.
Here is a checklist of 10 steps you must accomplish right away. Since this is a two-parter, we’ll only take on the first five steps in this post.
1. Get a qualified security advisor
Having a cybersecurity expert guide you through your security program is crucial. They could be an external or internal resource, and it doesn’t matter if they’re paid or not, as long as they’re qualified. Try contacting your local university — they may have senior students who could help you out or know of a professor who would be perfect for the job.
2. Assess your risk
You can’t accurately assess what’s going on in your school, security-wise, until you do a formal risk assessment. And you can’t protect your school from a threat if you don’t know what it is. A risk assessment will provide you with what you need to know to implement an effective security program, which will undoubtedly include disaster recovery, business continuity, and incident response planning.
3. Create security protocols
After you finish a risk assessment, you’ll understand which security controls need to be put into place. These could be technical, physical, or administrative controls. You will also want to pay attention to access management. This way, you can monitor who is coming and going from your school network. Try to review your security protocols every six months at the very least, though doing so every three months would be ideal.
4. Create an IT asset inventory
What are the devices that comprise your school’s IT infrastructure and/or are linked to your network? Who has access to which systems? And do you keep track of where your data is? Here’s an illustration to show you why this is important: If you agreed to have your data transferred to third parties as part of a software license agreement (EULA), sensitive information may end up in places you don’t intend it to reach. To prevent data from leaking, you need to know what you have IT-wise and where all of that is.
5. For every part of your cybersecurity program, determine who has ownership of it
Determine who is in charge of what element of your security program. Consider, for example, when you enter into a contract with a vendor. What parts are theirs and what parts are yours? If any gray areas exist, resolve them as soon as possible. It’s also critical to establish who is responsible for notifying the school, parents, and government in the event of a data breach. If someone isn’t informed that they have responsibility for something right away, they’ll likely believe someone else will deal with it. This will likely result in significant security gaps that your school may be held accountable for.
If you can’t wait for Part 2 of this post, go to IT consulting Orange County now.



