Audits Reveal Cybersecurity Weaknesses in New York School Districts

The Office of the New York State Comptroller has completed audits on three school districts in the state. The audits uncovered that the districts have neglected to follow some crucial cybersecurity policies, leaving them potentially vulnerable to cyberattacks.

The state performed audits on the Clyde-Savannah Central School District, the Honeoye Falls-Lima Central School District, and the Naples Central School District.

The report for the Clyde-Savannah Central School District found that “Officials did not regularly review network user accounts and permissions to determine whether they were appropriate or needed to be disabled.” It found more than 350 unneeded network user accounts, more than 50 unneeded shared or generic user accounts, and five unneeded administrative user accounts. The report defined unneeded accounts as those that have not been used in at least six months. Additionally, the audit uncovered 224 user accounts belonging to graduated seniors that should have already been disabled or deleted.

The report recommended that the district “regularly review network user accounts and disable those that are unnecessary.”

Cybersecurity

The Honeoye Falls-Lima Central School District report revealed that the district failed to “adopt key information technology (IT) security policies, resulting in increased risk that data, hardware and software may be lost or damaged by inappropriate use or access.” Most notably, it uncovered that many school computers were being used for non-academic activities like online banking, shopping, and gambling, according to New York ABC affiliate WHAM.

It further speculated that users may not have known that visiting these types of websites could have an impact on cybersecurity. According to Jonathan S. Weissman, senior lecturer at the Rochester Institute of Technology, “Humans are the weakest link in any cybersecurity implementation. All it takes is one user to open a link or open an attachment to undermine everything as far as cybersecurity is concerned.”

Finally, the audit for the Naples Central School District similarly found 89 accounts that had not been used for at least six months. Of these, seven had never been used, and 63 more of them were “unneeded,” according to the report. The report explains, “Unneeded network user accounts can be potential entry points for attackers because they are not monitored or used and, if accessed by an attacker, possibly could be used to inappropriately access and view PPSI [personal, private and sensitive information].”

As most K-12 schools around the country continue to operate using virtual and remote learning, proper cybersecurity measures have gained an extra degree of importance.

The state office requested that all three districts adopt and maintain comprehensive IT security procedures, conduct regular reviews of all network user accounts, and delete or disable unnecessary items. The districts agreed and have begun putting measures in place to address the issues.

About the Author

Matt Jones is senior editor of Spaces4Learning. He can be reached at [email protected].

Featured

  • DLR Group Appoints New K–12 Education Practice Leader

    Integrated design firm DLR Group recently announced that it has named its new global K–12 Education leader, Senior Principal Carmen Wyckoff, AIA, LEED AP, according to a news release. Her teams have members in all 36 of the firm’s offices in the U.S., Puerto Rico, the U.S. Virgin Islands, Europe, and Asia.

  • Texas K–12 District to Build New Elementary, High Schools

    The High Island Independent School District on the Bolivar Peninsula in Southeast Texas recently announced that construction on a new elementary school and a new high school will begin in January 2026, according to local news. Funding will come from a $27.9-million bond passed in May 2025.

  • UCNJ Launches $30M Modernization of Physical Education Center

    The Union College of Union County (UCNJ) in Cranford, N.J., recently broke ground on a new $30-million modernization project for its Physical Education Center (PECK), according to a news release. The college partnered with DIGroup Architecture for the project’s design, transitioning the existing 42,000-square-foot structure into a campus hub for student athletics and campus life.

  • Empowering People Through Smart, Sustainable Campuses

    Sustainability is facing increasing scrutiny, with some questioning its costs and priorities. Yet for universities, it remains an essential driver of resilience, operational efficiency and long-term competitiveness. At the same time, there is a growing recognition that sustainable transformation is not just about reducing energy consumption and emissions to comply with tightening regulations ‒ it’s about creating vibrant, comfortable environments where people can thrive, innovate and connect. For university leadership, this is a complex balancing act, with rising energy costs and limited budgets only adding to the challenge.

Digital Edition