Cybersecurity expert leads Risk Management Assessment

Risk Management Assessment workshopThe LHRIC’s Technology Support Services and RIC One Data Privacy and Security Service welcomed retired Col. Michael Hastings, Cyber Security Advisor for the Cybersecurity & Infrastructure Security Agency, and his colleague Chad Shroy. They presented the workshop, “Risk Management Assessment Session,” for our component district partners.

The presentation focused on Risk Management as a framework for identifying, tracking, and managing cybersecurity risks and shared best practices associated with cybersecurity risk management, along with a discussion of risks particular to K-12 education. The hands-on workshop utilized a risk assessment toolkit developed by CISA.

"The Risk Assessment Workshop was a continuation of the collaborative Incident Response Plan work between the LHRIC’s Technology Support Team, Data Privacy Team and districts in our region," said Dr. Madalyn L. Romano, Manager, LHRIC Data Privacy and Security Service. "The tool that Col. Hastings demonstrated provided districts with the ability to assess their risk and get a better understanding of the cybersecurity measures in place at the LHRIC for MIT and Collaborative districts."

Risk management assessment workshop presenter

On Jan. 25, the LHRIC will present, "Incident Response Plan Tabletop Exercise." In two sessions, 9 a.m. to noon and 1 to 4 p.m., the LHRIC's RIC ONE DPS Team will host a Tabletop Exercise to help districts "kick the tires" on their Incident Response Plans. The sessions are face to face and will be held at the LHRIC's offices at 450 Mamaroneck Avenue in Harrison. While these upcoming sessions are at full capacity, additional sessions will be scheduled for the summer.

Attendees are invited to bring their incident response plans and their teams. Participating in a tabletop exercise will enable teams to see how they will react to a theoretical cyber or data breach incident and how effective their response plan is. These exercises provide a realistic scenario and questions that will help guide the continued development of incident response plans.