Resources

Priority 1 – Deploy Multi-factor Authentication (MFA)

CISA in their January and August 2023 Bulletins again called out some of the most important ways that schools can protect themselves from cyber attacks. In both reports, CISA suggested that schools start their Cybersecurity journey by implementing six of the Highest-priority security measures.

Read more

Tech Tidbit – Thoughts About Passwords

Recently it was worldwide “change your password” day! I have a few thoughts. If you attended the CSI CyberSecurity event in December, you heard the NYS SED CISO get caught up in the incongruent password guidance between NYS and NIST CSF. Unfortunately, there was no breakthrough in this discussion, but NYS SED heard you that […]

Read more

Using CPGs in Real Life – Minimize Exposures to Common Attacks

Would you be comfortable giving your plumber the key to your house so he/she can come in at any time to fix anything they might feel is amiss? The answer is probably no. Did you know that when you give a vendor unfettered access to your network you are essentially doing the same thing? Similarly, […]

Read more

Using CPGs in Real Life – Patching

Everyone knows the adage “No one is perfect”. Unfortunately for anyone with a computer network, the bad actors who want to infiltrate your system are ready to take full advantage of any mistake they can find. The Cybersecurity and Infrastructure Security Agency (CISA) knows this, as they called out CPG 1.E (Mitigate Known Exploited Vulnerabilities) in […]

Read more

Tech Tidbit – No One Is Exempt From Security

My wife works for a multi-billion dollar hospital network you all will know. Every time she signs into their mandated VPN and MFA solution she curses out, “How annoying it is to have to do this each time to do anything!” I was the only “IT guy” in earshot to hear her frustration.

Read more

CSI Webinar – Come learn how to provide world-class protection for your district against cyberattacks in a sane, manageable way.

New York State K-12 school districts must follow EdLaw 2-d. We all know that is easier said than done. It is hard work with limited staff and limited resources to properly protect student and staff personally identifiable data while protecting the integrity of the district’s network and making sure there are proper controls to protect […]

Read more

Tech Tidbit – Managing and Protecting Local Administrator Accounts

Microsoft has tried hard to increase awareness of “pass the hash” attacks. They have been patching, but the threats keep coming. Back in April Microsoft released something quite awesome – their next-generation Local Administrator Password Solution (LAPS). Quite simply LAPS allows you to automatically rotate the password for a designated “local administrator” account on endpoints.

Read more

CSI Tech Talk Part II – Recording Available January 24, 2024

Join us, as Jeff Pigula, CSI Senior Network Engineer (Cisco CCNA and CC-NSF) will be discussing the changing world of PoE power management – what you need to know to keep from being driven crazy with the proliferation of new PoE devices being added to your network.

Read more

Weekly Tech Tidbit – Malware Defenses

This week, I would like to talk to you about Malware Defenses. This topic is in the NIST Detect and Protect categories. Antivirus has been around for what seems like forever. However, as long as antivirus has existed, we have had the problem with getting it on “all” servers and “all” endpoints.

Read more

CSI’s Tech Talk-Wednesday, April 17th [IN PERSON] Save your seat today!

We are pleased to announce our upcoming Tech Talk/SYSOP will be IN PERSON on Wednesday, April 17th! This is the first in-person Tech Talk since the pandemic and we are looking forward to seeing you all there! We encourage you to join Bob Knapp, Scott Quimby, and members of the CSI engineering team in person as they […]

Read more

Using CPGs in Real Life – Perform and Test Backups

What would you do if you came into school tomorrow and were told that all your District’s data had been corrupted? Your next step would be to check in with your IT staff to see if they were clearing your system and restoring your data with a backup.

Read more

CSI Tech Talk I October 2023 – Recording Available

We live in interesting times and continue to face some very unique challenges to keep your school district safe and stable so teachers can teach, students can learn, and the staff behind the scenes can do all the important tasks that make the district function well.

Read more

CSI’s Tech Talk II October 2023 – Recording Available

We live in interesting times and continue to face some very unique challenges to keep your school district safe and stable so teachers can teach, students can learn, and the staff behind the scenes can do all the important tasks that make the district function well.

Read more

CSI Tech Talk I January 2023 – Recording Available

Tech Tidbits – Scott’s updates on security, updates, and industry news since we last got together. Harden your endpoints as part of your overall security plan – We talk about patching constantly. However, recent ransomware attack post-mortem analysis has shown that there are a number of free, and mostly easy endpoint configuration changes you can quickly make to […]

Read more

Tech Talk II January 2023 – Recording Available

Tech Talk Part II will be a special session on email. We will talk about the following: Reading email headers. Every time something bad comes into the district, there is invariably a question about where it came from and why it got in.

Read more