{"id":6393,"date":"2011-05-21T11:16:12","date_gmt":"2011-05-21T15:16:12","guid":{"rendered":"http:\/\/rbach.net\/blog\/?p=6393"},"modified":"2022-12-30T16:08:59","modified_gmt":"2022-12-30T21:08:59","slug":"2-of-3-k-12-networks-breached-multiple-times-a-year","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/2-of-3-k-12-networks-breached-multiple-times-a-year\/","title":{"rendered":"2\/3 K-12 Networks Breached Multiple Times"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-100845\" title=\"2 of 3 K-12 Networks Breached Multiple Times a Year\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft1-4.jpg?resize=118%2C88&#038;ssl=1\" alt=\"2 of 3 K-12 Networks Breached Multiple Times a Year\" width=\"118\" height=\"88\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft1-4.jpg?resize=150%2C112&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft1-4.jpg?resize=75%2C56&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft1-4.jpg?w=224&amp;ssl=1 224w\" sizes=\"auto, (max-width: 118px) 100vw, 118px\" \/>Panda Security, a provider of cloud-based <a href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Security_software\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">security software<\/a>, recently released a report that says <strong>63 percent of K-12 schools experience malware outbreaks or unauthorized user access at least twice a year<\/strong>.\u00a0 The report, <a title=\"Panda\" href=\"http:\/\/press.pandasecurity.com\/wp-content\/uploads\/2011\/03\/Panda-K12-Education-IT-Security-Study_03.23.11.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Kindergarten-12 Education IT Security Report<\/a> (PDF), had some other interesting infobits.<\/p>\n<h3>Personal devices on K-12 networks<\/h3>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-100847 \" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Panda-Antivirus.jpg?resize=75%2C75&#038;ssl=1\" alt=\"\" width=\"75\" height=\"75\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Panda-Antivirus.jpg?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Panda-Antivirus.jpg?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Panda-Antivirus.jpg?w=240&amp;ssl=1 240w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/>The <a title=\"Panda\" href=\"http:\/\/press.pandasecurity.com\/news\/panda-security-study-reveals-63-percent-of-schools-plagued-by-it-security-breaches-at-least-twice-a-year\/\" target=\"_blank\" rel=\"noopener noreferrer\">survey<\/a> reports that eighty-two percent of schools allow students and staff to<strong> connect personal computers and laptops to the school network<\/strong>. Panda says schools recognize outside devices introduce external risks, but they <strong>struggle to fully integrate <a title=\"Security policy\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Security_policy\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">security policies<\/a><\/strong> for multiple devices. Only 74 percent of districts are monitoring the use of external devices. Fifteen percent <strong>fail to take any extra security measures<\/strong>, leaving those school systems more vulnerable to infection.<a href=\"http:\/\/press.pandasecurity.com\/news\/panda-security-study-reveals-63-percent-of-schools-plagued-by-it-security-breaches-at-least-twice-a-year\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-100850 \" title=\"Pamda Laptop chart\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaLaptop.jpg?resize=297%2C180&#038;ssl=1\" alt=\"Pamda Laptop chart\" width=\"297\" height=\"180\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaLaptop.jpg?w=536&amp;ssl=1 536w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaLaptop.jpg?resize=75%2C45&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaLaptop.jpg?resize=150%2C91&amp;ssl=1 150w\" sizes=\"auto, (max-width: 297px) 100vw, 297px\" \/><\/a> Most schools have implemented <a title=\"Computer security\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Computer_security\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">IT security<\/a> best practices, there is still room for improvement reports Panda. The report says ninety percent of schools install anti-virus and\/or <a href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Malware\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">anti-malware<\/a> on computers, but nearly 25 percent fail to use firewalls, block high-risk websites, or employ user authentication. 86% prevented the use of very risky websites; while 89% mandated users install security software on their systems. Further, 15% of respondents acknowledged that there weren&#8217;t any extra security measures in their districts if they wanted to use laptops.<a href=\"http:\/\/press.pandasecurity.com\/news\/panda-security-study-reveals-63-percent-of-schools-plagued-by-it-security-breaches-at-least-twice-a-year\/\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-100852\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaBestPratices.jpg?resize=403%2C180&#038;ssl=1\" alt=\"Panda Best Pratices\" width=\"403\" height=\"180\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaBestPratices.jpg?w=628&amp;ssl=1 628w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaBestPratices.jpg?resize=75%2C33&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaBestPratices.jpg?resize=150%2C67&amp;ssl=1 150w\" sizes=\"auto, (max-width: 403px) 100vw, 403px\" \/><\/a><\/p>\n<h3>Social media threats<\/h3>\n<p>Social media is a top concern for schools, but the stringency of school policy varies greatly. Ninety-five percent of schools have a social media policy in place, citing the mitigation of malware-related risks as the main reason for implementation. Twenty-nine percent of schools <strong>allow students unlimited access to social media sites<\/strong>, while 32 percent deny students access altogether.<\/p>\n<p><a href=\"http:\/\/press.pandasecurity.com\/news\/panda-security-study-reveals-63-percent-of-schools-plagued-by-it-security-breaches-at-least-twice-a-year\/\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-100855 \" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaSocialMedia-e1566139421284-150x108.jpg?resize=153%2C110&#038;ssl=1\" alt=\"Panda Social Media\" width=\"153\" height=\"110\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaSocialMedia-e1566139421284.jpg?resize=150%2C108&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaSocialMedia-e1566139421284.jpg?resize=75%2C54&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PandaSocialMedia-e1566139421284.jpg?w=383&amp;ssl=1 383w\" sizes=\"auto, (max-width: 153px) 100vw, 153px\" \/><\/a>Schools lack the funding to be secure. I have always said that schools face attacks from the inside and the outside. Insiders in a K-12 school network range from technically unsavvy to damn good malicious attackers. Despite this, the report says 72% of schools reported that budget limitations were the main obstacle, to better security and 38% reported non-availability of staff, and 29% of the schools, reported their IT staff had to attend to other more important tasks than IT security.\u00a0 IT administrative staff at 38 percent of schools report removing viruses or malware from <a title=\"Information technology\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Information_technology\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">IT systems<\/a> a few times a week, and 21 percent are doing this daily according to Panda.<\/p>\n<p>With malware on the rise and new threats propagated through social media every day, having the right security tools in schools has never been more important. Security issues consume staff time, diverting attention from the business of education. <a href=\"https:\/\/www.helpnetsecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Help Net Security<\/em><\/a> quotes Rick Carlson, president of Panda Security US, who has a great grasp of the obvious, \u201cWhile the <a title=\"Internet\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Internet\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">Internet<\/a> is an invaluable tool for education, it can cause serious interruptions to day-to-day operations if schools fail to properly address security concerns.\u201d<\/p>\n<p><em><strong>rb-<\/strong><\/em><\/p>\n<p><em>Just to prove the point, the <a title=\"Oakland Press\" href=\"http:\/\/www.theoaklandpress.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Oakland Press<\/a> is reporting that 4 students at Romeo High School in <a title=\"Romeo, Michigan\" href=\"http:\/\/maps.google.com\/maps?ll=42.8030555556,-83.0108333333&amp;spn=0.1,0.1&amp;q=42.8030555556,-83.0108333333%20%28Romeo%2C%20Michigan%29&amp;t=h\" target=\"_blank\" rel=\"geolocation noopener noreferrer\">Romeo, Michigan<\/a> were caught allegedly intercepting 60 staff members&#8217; emails, including the Superintendent after &#8220;something goofy&#8221; happened to the website. While I have no first-hand knowledge, the news did say the attackers went after people who read their emails on their cellphones. So more than likely it was some kind of <a title=\"Wikipedia\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Bluesnarfing\" target=\"_blank\" rel=\"noopener noreferrer\">Bluesnarfing<\/a> attack, maybe including a <a title=\"Wikipedia\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Cain_and_Abel_%28software%29\" target=\"_blank\" rel=\"noopener noreferrer\">Cain and Able<\/a> payload to get at passwords.<\/em><\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"https:\/\/web.archive.org\/web\/20150410185046\/http:\/\/www.boston.com:80\/business\/technology\/gallery\/datatheft\/\" target=\"_blank\" rel=\"noopener noreferrer\">Notable data breaches<\/a> (boston.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Panda Security K-12 IT Security Report that says 63% of schools experience malware outbreaks at least twice a year<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3045,565,1819,23,19,15,562,4,1878],"class_list":["post-6393","post","type-post","status-publish","format-standard","hentry","category-security","tag-3045","tag-anti-virus","tag-computer","tag-malware","tag-michigan","tag-networking","tag-panda-security","tag-security","tag-social"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/6393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=6393"}],"version-history":[{"count":9,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/6393\/revisions"}],"predecessor-version":[{"id":131361,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/6393\/revisions\/131361"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=6393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=6393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=6393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}