Technology Department  •  Helendale School District

Incident Response & Communication Protocol

The order in which the District investigates a cybersecurity incident, communicates about it, notifies its insurance carrier, and coordinates with County partners.

Staff reference • Approved messaging comes from the Superintendent's office

IR
Protocol

Incident Response

Loading tip…
5
Response Phases
2
Notice Types
1
Approving Authority
3
External Partners

The Governing Principle

The District does not describe an incident until it understands the incident. Scope is established first, and only then does the District state what happened, who was affected, and what is being done about it. Statements made before the facts are known have to be corrected later, and a correction costs far more credibility than a short, explained delay. The one exception is protective instruction, described below, which is issued immediately because it protects people rather than characterizing events.

Owns the investigation

Technology Department

Containment, evidence preservation, log analysis, scope determination, endpoint remediation, and the technical record.

Approves all messaging

Superintendent's Office

Reviews and authorizes every staff, family, and public statement, with Human Resources and Educational Services reviewing as appropriate. All Board reporting flows from here.

Owns the carrier relationship

Business Services

Holds the risk-management and cyber liability relationship, submits the annual application, and is the route through which notice is filed.

The Response Sequence

Each phase produces something the next phase depends on. The investigation produces the facts that messaging requires. Messaging produces the record the carrier and the Board receive. Phases are worked in order, and a phase does not open until the one before it has closed.

01

Investigate and Contain

Technology Department leads
Phase One

The first objective is to stop the activity and determine its true scope. Nothing is characterized publicly until that scope is established, because the answer to "how many people were affected" changes several times during the first hours of an incident.

  • Preserve evidence before changing anything. Export logs and image affected systems before rebuilding them.
  • Contain the source. Suspend or reset the affected account, force password changes, and purge the message from mailboxes where the platform allows it.
  • Request perimeter blocks through County partners for the attacker domains and infrastructure involved.
  • Establish scope: who received it, who opened it, who clicked, which devices reached the payload, and whether stored information was accessible.
  • Identify and isolate affected devices, then reprovision them. Where firewall logs give addresses but not hardware identifiers, devices are traced through lease records and wireless controller data.
  • Confirm with Business Services that no payroll or vendor payment fraud accompanied the incident.
Gate: scope confirmed and documented before Phase Two opens

The One Exception: Protective Alerts

A protective alert is issued as soon as an active threat is confirmed, without waiting for the investigation to finish. It exists to stop people from being harmed in the next hour. It states what not to open, what not to click, and what to change, and it directs anyone who already acted to report it immediately.

A protective alert never characterizes cause, scope, or exposure. It does not say how many accounts are involved, whether data was accessed, or who is responsible. Those statements belong to Phase Two, after the facts are settled. Keeping the two separate is what allows the District to warn people quickly without saying anything it will later have to retract.

02

Communicate and Notify

Superintendent approves, Technology drafts
Phase Two

Once findings are final, the District communicates in a fixed order, using one approved set of language. The sequence matters: staff are informed before families so that the people answering phones are never learning the news from the person calling them.

  • Staff first. A full notice describing what occurred, what the District did, and what employees should do.
  • Families second. A plain-language safety notice with no investigative detail and no personally identifiable information.
  • Front office third. Everyone answering phones receives the same approved talking points, so callers hear one consistent answer at every site.
  • Board reporting last. A final written report to the Superintendent, then to the Board of Trustees, in plain language.
  • Media inquiries and non-parent callers are routed to the district office at (760) 952-1180 and the Superintendent's office. No site staff speaks to media.
Content standard. District notices state what happened, what the District did, and what the reader should do. They exclude technical indicators, vendor and malware names, and the names of individual employees. Where an employee's name appeared on a fraudulent message, the District corrects the record without repeating or redistributing the fraudulent content.
Gate: Superintendent approval required before any message leaves the District
03

Notify the Cyber Liability Carrier

Through the risk-management program, Business Services owns the relationship
Phase Three

Notice is filed through the District's joint powers authority risk-management program rather than sent directly to the underwriter. A report only notice can be submitted in an abundance of caution even when no claim is anticipated. Late notice is itself a coverage risk, so the notice goes in early and is updated as findings develop.

  • Request a breach coach and the carrier's approved panel vendors before any outside cost is incurred.
  • Ask for written confirmation of coverage and which coverage parts apply.
  • Provide the factual record: what happened, when, what was contained, and what remains under review.
  • Follow carrier guidance on legal counsel and on any required regulatory or individual notification.
  • Keep a running record of every communication with the program and the carrier.

Do

  • File early, even as a report only notice
  • Preserve and image systems before rebuilding
  • Work through the risk-management program contacts
  • Ask for panel counsel and panel forensics
  • Keep messaging consistent with what the carrier has been told

Do Not

  • Retain your own forensics firm or counsel before approval
  • Admit fault or assign blame in writing
  • Declare data safe before the review is complete
  • Rebuild affected machines before evidence is captured
  • Let public messaging drift from the notice on file
Gate: carrier guidance received before outside vendors are engaged
04

Coordinate with County Partners

San Bernardino County Superintendent of Schools
Phase Four

The District does not operate its own perimeter firewall. Filtering happens at the County managed egress, which makes County network staff an operational partner rather than an outside vendor. The initial block request is made in the first hour of an incident as part of containment. Sustained coordination continues through remediation and closeout.

  • Request outbound blocks on the attacker domains and infrastructure, and confirm the blocks are in place.
  • Request preserved egress logs, which identify the internal addresses that reached the malicious destination.
  • Ask for continued monitoring so that any ongoing beacon activity after the block is reported back.
  • Notify the originating district directly when a compromised account in another domain is the source of the campaign.
  • Reassess scheduled network work during an active incident and postpone where it would complicate the response.
  • Use the partnership for prevention as well: endpoint detection, supplemental email screening, and email authentication review.
Known limitation. Firewall logs identify internal addresses, not hardware identifiers. Mapping an address to a specific machine requires lease history and wireless records captured at the time of the event, which is one more reason evidence is preserved before any device is rebuilt.
05

Close Out and Strengthen

Reporting, review, and prevention
Phase Five

An incident closes with a written record and a set of changes, not simply with the activity stopping. Reporting is produced at three levels of detail for three different audiences.

  • Board and public record: a plain-language final report and question set, excluding technical indicators and individual names.
  • Legal counsel: a separate confidential briefing containing the complete technical record and the questions counsel needs to assess.
  • Internal: the full technical record retained by the Technology Department.
  • Prevention work identified during the review is scheduled and tracked, including awareness training, multifactor authentication, endpoint protection, and email screening.
  • The District states honestly what could and could not have been prevented, and offers no guarantee that a future attempt will fail.

What Staff Do During an Incident

Short list, and it does not change.

Report It Immediately

Forward the message and report it, including if you already clicked or downloaded something. Early reporting is what turns an incident into a contained event.

Report to IT
Use Approved Language Only

If you answer phones, use the talking points issued by the District. Do not speculate about cause, scope, or whether information was exposed.

Stop Using the Device

If a file downloaded or a link was opened on a District device, set it aside and stop using it until the Technology Department inspects or replaces it.

Nobody Is in Trouble for Reporting

Clicking a well-built phishing message is not carelessness. These campaigns pass authentication checks, arrive from real compromised accounts at real organizations, and use trusted cloud services to host what they deliver. The only outcome the District cannot work with is silence. Report it, and the response begins in minutes rather than days.

Report It Now

Common Questions

What staff and families ask most often during and after an incident.

Why does the District wait to explain what happened?
Because the accurate answer is not available in the first hours. Scope changes as logs are analyzed, and a number announced early is almost always wrong. The District issues immediate protective instruction so that people can act to keep themselves safe, then issues a full account once the investigation is complete. A short delay with an explanation is preferable to a statement that has to be corrected.
I received a warning with almost no detail in it. Why?
That was a protective alert. Its only job is to tell you what not to open and what to change right away. Detail about cause and scope follows in the formal notification, after the investigation closes.
A parent is asking whether their information was exposed. What do I say?
Use the approved talking points and do not confirm or deny exposure. Explain that the District is reviewing the matter and will communicate directly if there is anything a family needs to do. Route specific concerns to the district office at (760) 952-1180.
Who talks to the media?
The Superintendent's office. All media inquiries and any caller who is not a parent or student are routed to the district office. No site or department staff speaks on the District's behalf.
Why is the insurance carrier notified even when nothing appears to have been lost?
Policies carry notice conditions, and delayed notice can jeopardize coverage. A report only notice is filed in an abundance of caution. Filing it does not assert that a claim exists, and it preserves the District's position if the picture changes later.
Why does the County get involved in a District incident?
The District's internet traffic passes through a County managed perimeter, so blocking malicious destinations and retrieving the logs that identify affected machines both require County action. County staff are operational partners in containment and in the prevention work that follows.
Where does the Board fit in?
The Board receives a written final report through the Superintendent once the investigation is complete. It is written in plain language and deliberately excludes technical indicators and individual names.