Episode 140 - Ransomware Story with Eric @ OKC Public Schools
Oct 20, 2023
auto_awesome
Eric Hileman, Executive Director for IT Services at Oklahoma City Public Schools, recounts their experience with a ransomware attack, discussing mistakes made, luck involved, and the message that 'it can happen to you'. Topics include compromised devices, media communication, and lessons learned.
Open communication and collaboration played a crucial role in successfully handling the ransomware incident, with the IT department maintaining a transparent relationship with local media outlets and receiving support from the community.
The ransomware incident highlighted the need for better cybersecurity infrastructure and tools, leading the district to invest in next-gen AV endpoint tools, log aggregators, and a transition to a zero-trust network security model with multi-factor authentication (MFA).
Deep dives
The Importance of Open Communication and Collaboration
Open communication and collaboration played a crucial role in the successful handling of the ransomware incident. The IT department had a good relationship with local media outlets, allowing them to communicate transparently with the community throughout the crisis. The community responded with support and solidarity, understanding that cybersecurity incidents can happen to anyone. The district's IT staff also demonstrated high collaboration, working together to recover from the incident and receiving appreciation from teachers and staff.
Lessons Learned and Changes Implemented
The incident highlighted the need for better cybersecurity infrastructure and tools. The district decided to invest in next-gen AV endpoint tools, log aggregators, and other layered defense methods to prevent similar incidents in the future. They also plan to transition to a zero-trust network security model and implement multi-factor authentication (MFA) to enhance security. The incident served as a wake-up call, reinforcing the importance of being proactive and implementing best practices in cybersecurity.
Positive Community Response
The district received a positive response from the community, with minimal pushback or blame directed towards the IT department. The open communication and transparent approach helped build trust and understanding among stakeholders. The community rallied behind the district, providing support and treats for the IT team. This incident demonstrated the value of strong relationships with media outlets and the power of collaborative efforts in crisis management.
Counting Blessings and Recognizing Luck
Despite facing a ransomware attack, the district considered themselves lucky, with only 26 machines being encrypted out of around 10,000 devices. Reflecting on the incident, they acknowledged that it could have been much worse and were grateful for the minimal impact. They viewed the incident as a reminder to be prepared and to continuously improve their cybersecurity measures.
Eric recounts the story of how his district was hit with ransomware in 2019 but narrowly escaped a major cyber attack. He describes the early days of the attack, including the response from his team and district, and then recounts how they recovered with only a very small grazing from the attack. His story is filled with lessons learned from the incident, including things they should have done before the attack as well as how his district handled the incident as a community.
Chris was not able to make this week’s episode so we’re also considering Eric for the full-time gig.
Visit our YouTube channel and subscribe. We plan to post video recordings soon.