The order in which the District investigates a cybersecurity incident, communicates about it, notifies its insurance carrier, and coordinates with County partners.
Staff reference • Approved messaging comes from the Superintendent's office
Incident Response
The District does not describe an incident until it understands the incident. Scope is established first, and only then does the District state what happened, who was affected, and what is being done about it. Statements made before the facts are known have to be corrected later, and a correction costs far more credibility than a short, explained delay. The one exception is protective instruction, described below, which is issued immediately because it protects people rather than characterizing events.
Owns the investigation
Technology Department
Containment, evidence preservation, log analysis, scope determination, endpoint remediation, and the technical record.
Approves all messaging
Superintendent's Office
Reviews and authorizes every staff, family, and public statement, with Human Resources and Educational Services reviewing as appropriate. All Board reporting flows from here.
Owns the carrier relationship
Business Services
Holds the risk-management and cyber liability relationship, submits the annual application, and is the route through which notice is filed.
Each phase produces something the next phase depends on. The investigation produces the facts that messaging requires. Messaging produces the record the carrier and the Board receive. Phases are worked in order, and a phase does not open until the one before it has closed.
The first objective is to stop the activity and determine its true scope. Nothing is characterized publicly until that scope is established, because the answer to "how many people were affected" changes several times during the first hours of an incident.
A protective alert is issued as soon as an active threat is confirmed, without waiting for the investigation to finish. It exists to stop people from being harmed in the next hour. It states what not to open, what not to click, and what to change, and it directs anyone who already acted to report it immediately.
A protective alert never characterizes cause, scope, or exposure. It does not say how many accounts are involved, whether data was accessed, or who is responsible. Those statements belong to Phase Two, after the facts are settled. Keeping the two separate is what allows the District to warn people quickly without saying anything it will later have to retract.
Once findings are final, the District communicates in a fixed order, using one approved set of language. The sequence matters: staff are informed before families so that the people answering phones are never learning the news from the person calling them.
Notice is filed through the District's joint powers authority risk-management program rather than sent directly to the underwriter. A report only notice can be submitted in an abundance of caution even when no claim is anticipated. Late notice is itself a coverage risk, so the notice goes in early and is updated as findings develop.
The District does not operate its own perimeter firewall. Filtering happens at the County managed egress, which makes County network staff an operational partner rather than an outside vendor. The initial block request is made in the first hour of an incident as part of containment. Sustained coordination continues through remediation and closeout.
An incident closes with a written record and a set of changes, not simply with the activity stopping. Reporting is produced at three levels of detail for three different audiences.
Short list, and it does not change.
Forward the message and report it, including if you already clicked or downloaded something. Early reporting is what turns an incident into a contained event.
Report to ITIf you answer phones, use the talking points issued by the District. Do not speculate about cause, scope, or whether information was exposed.
If a file downloaded or a link was opened on a District device, set it aside and stop using it until the Technology Department inspects or replaces it.
Clicking a well-built phishing message is not carelessness. These campaigns pass authentication checks, arrive from real compromised accounts at real organizations, and use trusted cloud services to host what they deliver. The only outcome the District cannot work with is silence. Report it, and the response begins in minutes rather than days.
Report It NowWhat staff and families ask most often during and after an incident.