Data Breach Simulation Exercise
How to Minimize Damage & Maximize Outcomes in the Wake of a Data Breach
May 2018
Link to Slides
Exploding Data!
Social Media in Schools: What Now?
4
Bite-Sized Tips & Tricks
5
But Wait! There’s More!
6
NOTHING TO HIDE???
7
8
In 1991 for about $3000 on sale…
9
EVOLVING, SOPHISTICATED SCAMS
10
Kids these days…
11
BLUE: phishing attacks �PURPLE: breaches or hacks resulting in the disclosure of personal data �YELLOW: ransomware attacks �GREEN: denial-of-service attacks (green pins); and�RED: other cyber incidents resulting in school disruptions & unauthorized disclosures
12
The K-12 Cyber Incident Map
13
RIPPED FROM THE HEADLINES!
14
TERRIFYING NEW HACKING TREND!
15
IMPORTANCE OF DIGITAL CITIZENSHIP
CHANGING LANDSCAPE OF DATA PRIVACY
16
LEGISLATIVE CHANGES
17
FUTURE READY!
18
LEGISLATIVE TRENDS
19
GDPR???
20
2018 Ballot Measure?
21
COPPA OVERVIEW
ALL THE COOL KIDS ARE DOING IT…
WHAT IS…EXAMPLE
DO YOU ASK BEFORE YOU APP?
SIMPLE TIPS FOR TEACHERS
SOCIALIZE SAFELY!
28
29
http://www.visualcapitalist.com/happens-internet-minute-2017/
DATA BREACH SIMULATION
30
DATA BREACH SIMULATION
31
Be Prepared for the Unexpected!
32
SUGGESTIONS
33
DATA BREACH SIMULATION
Each team will develop two key products:
34
During the event, you will be asked to participate in press conferences about the scenario. Be prepared to respond to members of the media about what is happening and how your organization is responding.
DATA BREACH SIMULATION
35
BACKGROUND
36
BACKGROUND (cont.)
37
SCENARIO
38
SCENARIO
39
DATA BREACH SCENARIO
40
DATA BREACH SCENARIO (cont.)
41
This exercise works best if approached as a “murder mystery” game. The more you synthesize the information and role play, the more useful the exercise becomes.
Questions?
42
DATA BREACH SCENARIO
43
10 Minutes
WHERE ARE WE?
44
SCENARIO UPDATE
45
DATA BREACH SCENARIO
46
10 Minutes
WHERE ARE WE?
47
SCENARIO UPDATE
48
SCENARIO UPDATE
49
DATA BREACH SCENARIO
50
10 Minutes
WHERE ARE WE?
51
SCENARIO UPDATE
52
DATA BREACH SCENARIO
53
10 Minutes
DEVELOP A COMMUNICATION PLAN
54
DISCUSS UPDATES & DEVELOP A PR PLAN
55
15 Minutes
PRESS CONFERENCE
56
Where Are We?
57
DEVELOP AN INCIDENT RESPONSE PLAN
58
DEVELOP AN INCIDENT RESPONSE PLAN
59
10 Minutes
UNVEIL YOUR RESPONSE PLAN
60
WRAP-UP
61
RESOURCE EXAMPLES
MORE RESOURCE EXAMPLES
HELPFUL ORGANIZATIONS
SIMPLE TIPS TO PROTECT PRIVACY
65
Student Data Privacy Law References
66
Law/Guidance Source | Web Site/Page |
Family Educational Rights and Privacy Act (FERPA) | |
Privacy Technical Assistance Center (PTAC) | |
California Education Code (EC) | |
Children’s Online Privacy Protection Act (COPPA) | |
Protection of Pupil Rights Amendment (PPRA) | |
AB 1442 (Social Media) | |
AB 1584 (Third Party Contracts) | |
SB 1177 (Student Online Personal Information Protection Act) | |
SB 178 (Electronic Devices) |
ED TECH DATA PRIVACY RESOURCES
Resource Title | URL |
California Student Privacy Alliance | |
Common Sense Education Privacy Evaluations | |
Common Sense Media’s “What Is…” Videos | |
Privacy Expert Video | |
US Department of Ed Student Privacy Page | |
FERPA Sherpa for Educators | |
IKeepSafe Vetted Products | |
TAPD (Technical Assistance & Professional Development Cybersecurity Ed Program | |
Ask Before You App Video | |
Data Privacy Guidebook | |
Common Sense Ed Student Privacy Tips Video | |
Common Sense Ed Social Media Privacy Video |
Student Data Privacy Resources
Tool/Resource | Web Site/Page |
US Department of Education’s Student Privacy Web Page | |
Data Privacy Guidebook | |
National Center for Education Statistics (NCES) Forum Guide to Education Data Privacy | |
Common Sense Media’s Privacy & Internet Safety Page | |
On Guard Online for Parents | |
On Guard Online for Educators | |
Future of Privacy Forum for K-12 Education | |
NCES’s Data Stewardship: Managing PII in Student Education Records Report | |
FERPA Sherpa Student Privacy Resource Center | |
The CDE’s Data Privacy Web Page | |
K12 Cybersecurity Resource Center | |
Threatwire video podcast |
General Data Privacy Resources
Tool/Resource | Web Site/Page |
On Guard Online | |
National Cyber Security Alliance’s Stay Safe Online Web Page | |
Common Sense Media’s Digital Citizenship Page | |
Future of Privacy Forum | |
Privacy Paradox (Podcast) | |
Bloomberg Digital Defense (Jordan Robertson, Columnist) | |
Wall Street Journal Personal Tech News (Geoffrey A. Fowler, Columnist) | |
Wired Magazine Editor-in-Chief Nicholas Thompson |
Geoff Belleau, Consultant
@EdTech_Cal
California Dept of Education
gbelleau@cde.ca.gov
70
Elizabeth Wisnia, Consultant
@cdeprivacy
California Dept of Education�ewisnia@cde.ca.gov