All Episodes

May 14, 2026 49 mins

On this episode, the guys discuss Google's announcement of the new "Googlebook" (a reported merge of Android and Chrome OS), growing controversy and litigation around iReady and screen time in schools, and a debrief of the recent Canvas/Instructure security incident with guest Michael Klein from the Institute for Security and Technology.

Unofficial demo of AluminumOS: https://youtu.be/dXmFIfv_tIA?si=Baw0OInBqJf-IkDD

The largest segment is a deep dive into the Canvas/Instructure incident with cybersecurity expert Michael Klein. He walks through the timeline (initial unauthorized activity detected April 29; exfiltration via cross‑site scripting of a free‑for‑teachers account; a later attack that posted extortion notes to some users), the involvement of CrowdStrike, the public claims by the ShinyHunters group, and Instructure’s statement about an agreement with the actor. The conversation covers the technical nature of the attack, impacts on confidentiality, integrity and availability (including disruptions to finals/registrar functions), the downstream consequences for integrations with SIS and other edtech systems, and why many institutions remain cautious to reconnect APIs.

Michael and the hosts discuss practical guidance and explore policy implications.

Join us July 6th-10th, 2026 – GAMEIS Conference in Savannah, GA

————

Sponsored by:

SysCloud Meter Fortinet Incident IQ ClassLink NTP ————

Join the K12TechPro Community (exclusively for K12 Tech professionals)

Buy some swag (tech dept gift boxes, shirts, hoodies...)!!!

Email us at k12techtalk@gmail.com

OR our "professional" email addy is info@k12techtalkpodcast.com

X @k12techtalkpod

Facebook

Visit our LinkedIn

Music by Colt Ball

Disclaimer: The views and work done by Josh, Chris, and Mark are solely their own and do not reflect the opinions or positions of sponsors or any respective employers or organizations associated with the guys. K12 Tech Talk itself does not endorse or validate the ideas, views, or statements expressed by Josh, Chris, and Mark's individual views and opinions are not representative of K12 Tech Talk. Furthermore, any references or mention of products, services, organizations, or individuals on K12 Tech Talk should not be considered as endorsements related to any employer or organization associated with the guys.

Listen
Watch
Mark as Played
Transcript

Episode Transcript

Available transcripts are automatically generated. Complete accuracy is not guaranteed.
(00:00):
On this week's episode of the K-12 Tech Talk podcast, Google has announced the Google Book,

(00:06):
which will bring together the Android and Chrome OS ecosystems. And Michael Klein from the Institute
for Security and Technology joins us to debrief the Canvas breach from last week. Thanks for listening.
Live from the NTP studios, it is the K-12 Tech Talk podcast. This is episode 268, where three

(00:26):
nerds get together and talk about school technology stuff. I'm nerd number one. 264. What did I say?
268. We don't know where you are tonight. Yeah, and you said it is. Yeah. Do you want to restart?
No, we just go with it, man. We don't. Okay, go with it. It is. We're off to a fantastic start.
It's the end of the year, man. We got two more months. Again, we go through this every year.

(00:50):
Oh, that's right. That's yeah. Sail club just spun up. Yeah, he's waxing his boat. His sailboat.
Yeah, bring up two more months, Mark. Come on, bring it up. Let's go down the sailboat school.
So I guess I need to make a little bit. Well, first introductions. I'm Josh here in mid-Missouri.
Nerd number two down the street drinking a new beverage tonight. I drink Mason Pierre

(01:16):
sparkling water now. I went from energy drink only to sparkling water with and I'd still do
energy drinks and I drink coffee now. Oh, you guys know that? Yeah. No, no. Every morning coffee. No.
Big boy. How much sugar do you put in it? Two two packets of sweetener. Okay. Eight ounces of coffee,

(01:37):
two sweetener packets and a little a little dollop of cream creamer. Is this all right?
I feel like you're entering adulthood. Heck, yeah. Well, full sin transparency. I had some
chest pain like a month ago. And so I've tried to cut back on energy drinks and I haven't had the
chest pain again. So these aren't like I'm just not trying to change just because I want to.

(02:06):
I actually had I didn't say anything for a while to people. Then I finally told Stephanie.
So now I'm drinking water and coffee. Here's here's to the news.
Here's to holding nothing back on a podcast. And you forget that you're talking to more than
two people. But you didn't tell your wife because she's a nurse. Yeah, she's freak out.

(02:31):
And she did. But but here we are. Mason water.
It's fine. Well, since since we're in in full introductions, Mark, Mark, how are you? I'm here.
Yeah, I'm just how's your health? How do you have any chest pains, Mark?
Tell us about your vices. Have you picked up any new habits, illicit drugs, anything?

(02:56):
No, I got I got I got nothing new. I'm still here. I also take fiber gummies now.
Are they fiber? I think, yeah, do it. You should you should really try the calm gummies.
Once again, we're off the rails and we have barely gotten through the intro.
Dude, we we were off the rails five seconds in when I said it was episode 268 and it's 264.

(03:20):
I don't know where the hell 268 came from. Yeah, man. I have a little bit of a confession to make.
Oh, since since I mean, Chris started, OK, since Chris, since Chris opened the door,
you know how they say people should get their own house in order before they make commentary or

(03:47):
critique other people. Are you also having heart palpitations? Oh, all the time that I've been
diagnosed with palpitations 20 years ago. So we're on our after dinner walk tonight. And my
wife says, if you see John, it's her tech director at her school. He might tell you a story. She went

(04:12):
back and walked into the I.T. department and asked about a problem without submitting a ticket.
And she told their I.T. director, don't tell Josh because he'll be really mad.
Well, Chris is having a heart attack and you're worried about your wife not submitting a ticket.
I'm worried about tomorrow, man. Do I get to see tomorrow?

(04:35):
And you're talking about your wife with a printer jam?
On your dinner stroll through the neighborhood? Yeah. With your controlled palpitations?
We just found out Chris has weeks to live because he's been chugging energy drinks
and you're worried about a ticket. Chris, how many energy drinks were you drinking a day?

(04:58):
Two. Four. Two to three. Should we get on with it? Yeah, let's do. Well, let me talk about Meter.
Meter.com slash K-12 Tech Talk. Meter can design your enterprise hardware. They have intuitive
software. They can optimize your operations and help you with your deployment, with your
networking deployment. So check out meter.com slash K-12 Tech Talk. Can they monitor your

(05:23):
caffeine intake? I think you could ask them. Okay. So we're going to get into the news, but Mark,
the biggest newsworthy item, we're going to talk to a friend here in a little bit. He's going to
join us. And so we're going to save most of that till the end, right? Yeah, yeah, yeah. We're going
to end the news segment by talking about the big infrastructure Canvas breach and bring on our

(05:48):
favorite. I guess he's now a regular cybersecurity, Michael Klein. But before that, let's talk about
the other big news, which was this week, Google announced the successor to the Chromebook?
Question mark? Yeah. I'm not quite sure. I don't know. The Googlebook. The Googlebook is going to

(06:09):
be the new hardware operating system from Google. At first I thought this is just the new Pixelbook,
but no, this does seem to be the final merge of the Android and Chrome OS. There is a leak online.
We'll put the YouTube link in the show notes here where you can actually see what this looks like.

(06:30):
And then obviously the Google announcements, you can see some screenshots and demos of that.
But this really does look like a merge of the Android and Chrome OS environment. When you,
when you boot it up, you see the Android logo. So it is a branch off of Android,
but when it actually boots into the desktop, it looks more like the existing Chrome OS. So

(06:51):
this looks like the final merging of the two. It does appear to be, like I said,
on the Android branch. So the future of Chrome OS is really what a lot of people are asking about
to follow up the announcement yesterday. They did post a message today that Chromebooks will
remain a reliable long-term investment, and you can continue to confidently purchase and deploy

(07:16):
them in businesses and schools. As for the future, and this is per Google's post on their website,
Chrome OS will continue to receive 10 years of automatic updates. You can continue to manage
your fleet in the Google admin console without needing new licenses. And when the time comes,
we'll provide multiple pathways to transition to the new experience. So yeah, it does appear
that Chrome OS will be going away or merging into the Google Book ecosystem, but the timeline is

(07:42):
still up in the air and what that will look like is unknown. And whether or not your existing
hardware will be able to run this new Google Book Aluminum OS, the unofficial name, is yet to be
determined. Because if you look at a lot of the demo videos from Google, it's very, very heavy
on the Gemini experience. Very heavy user experience that will obviously require more

(08:04):
high-end hardware. So unsure what will happen to your existing fleet right now,
but something to keep an eye on. You know, that was one of my concerns is if they were going to
force upgrade all of the existing Chromebooks to Aluminum OS. And you know, when you get to that
10-year mark in a Chromebook, they can be kind of sluggish. And trying to force those things

(08:30):
to upgrade to a new OS would be, that was my biggest concern, was that that would probably
be miserable. Whereas if they do this kind of tandem rollout where the new devices they're
selling are running Aluminum OS and the older devices, maybe even say the Chromebook Pluses
that are relatively new to the market, they could support an upgrade to Aluminum OS. Maybe that's

(08:51):
the path. So I feel a little bit better about this. In reality, I don't care real much
because I don't see it happening in the next three years. So I'll be retired by then. Do you like
it being called a Googlebook? I mean, is that kind of a... I'm not going to say it.
I'm not going to upset our friends at Google. I don't know. I think there could be other

(09:15):
revisions, other names. You could call it anything you want. Our teachers and our students
are going to call this thing a Chromebook for decades. Sure. I know that sucks. Like I literally
during new employee orientation, I spend less than five minutes, but I have a segment where I

(09:38):
preach the difference between a Chromebook and a laptop. What is Windows and what is a Chromebook?
How to look for identifying things. And now we're going to call this thing a Googlebook,
which doesn't roll off the tongue as well. I should also clarify too, I refer to Aluminum OS.

(09:59):
It's very likely that it's just more of an internal name for the operating system.
I don't think publicly we'll be talking about Aluminum OS. I think that the name
Googlebook will be the more formal name for this system. Yeah, because operating systems all have
their internal names. Android went with desserts for so many years. Can I keep answering about this

(10:22):
name thing? Go for it. The Chrome browser will still be the primary browser used on a Googlebook,
is that correct? Mm-hmm. So couldn't we have just kept calling these things Chromebooks?
They're probably... Why are we getting so stuck on the OS? It's probably they're going to try...
Chromebook running the Android OS, no big deal. They're probably going to try and make a

(10:45):
differentiation in user experience. Because that's one of the complaints you hear about a Chromebook
is that they can be sluggish at times, the user experience isn't the best. They're probably doing
that like, we're starting over fresh. This is a new experience. This is a new device. This is a
new operating system. So they're maybe trying to cut ties with Chrome OS and that moniker or

(11:07):
that thought. I don't know. I agree. And there's actually data even from Google's internal documents
that were leaked during some of the recent court cases that shows that students when they graduate
high school, they do not turn around and buy a Chromebook for personal use. So part of this
could be a rebrand to kind of step away from the school Chromebook mentality. But I still,

(11:28):
I don't care what you call it. Students, teachers are still going to call this thing a Chromebook
for a very long time. Yeah, I agree. Every interactive board in the school is still called
the smart board. No price point discussed, correct? No, just looking at some specs and...
No, that's the other thing too. Hardware is still yet to be determined. That's coming from
all the different manufacturers. It'll have to be cheaper than the Neo. Great point. I mean,

(11:54):
you're talking about a lot of hardware needed for a lot of the AI features that they're demoing.
You're going to have a lot of costs associated with AI. I'm assuming a lot of the AI will be
on device rather than cloud-based Gemini. But still, now you have a ceiling that you've got
to compete with. Chromebooks are known as the more cost-efficient device for schools. If you hit over

(12:17):
that $500, $600 mark, the Neo is going to wipe the floor. Yeah. Just the short amount of time that I
played with it, it is a more finished user experience. And especially if you're used to
the Mac OS environment, it's a very seamless transition. So yeah, hopefully Google can pull

(12:38):
it off with the Google Book. That's how people will pronounce it, Google Book. Can I get the
Google Book? All right, kids, get your Google Books out. Chris really doesn't like that name.
Well, you got Neo. It's brand recognition. Even Surface sounds cooler than Google Book.

(13:00):
Oh, man. All right. Well, moving on. There goes Google as a sponsor. Based upon name alone,
what do you want? You want a MacBook Neo, you want a Surface Book, or do you want a Google Book?
No one's going to pick Google Book. All right, moving on. The anti-screen time movement has

(13:20):
really focused its attention in recent weeks on a single ed tech application. One of the most
popular ones used by 14 million United States students, iReady, has received the ire of
districts, of teachers, of students and parents alike. There is a lawsuit currently against iReady
and there is a recent NBC article talking about the complaints that students and teachers and

(13:43):
parents have alike about it. And in Los Angeles's recent screen time policy, they actually called
out iReady and said we need to do an audit of how iReady is being used. So a lot of the gripes
and concerns kind of center around its design where students are participating in activities
and in lessons and then the teacher just receives an aggregate score at the end. They're not seeing

(14:06):
item level information. So it's a little bit more of a diagnostic tool, but some of the concerns
are saying, well, it's being used as an instructional tool more to supplant the teacher rather than
actually supplement and diagnose students' progress. So where this is going, really unsure.
We've talked about the lawsuit against iReady on here and it really seems a little bit too premature

(14:30):
to a lot of the claims that they're making, but the anti-screen time movement really over the
last few weeks, especially this week, has really, really focused its attention on iReady, probably
most likely because it is the top used and assigned ed tech app tool out there. And it has
been very successful for Curriculum Associates. Being a private equity backed company, they are

(14:55):
bringing in nearly $800 million in annual revenue, almost all of that from iReady. So
we'll see what happens. I think a lot of districts are starting to kind of kick the tires on iReady,
but I don't see this thing slowing down any time soon. Well, iReady, I think in Missouri,
is one of the approved reading plan assessment tools. And Chris, I know there's a number of

(15:20):
districts around us that use iReady for that multi, I don't know how many times a year,
three, four or five times a year, they do that reading assessment test with kids.
So you have a ton of districts that use it just for that purpose alone,
let alone the supplantive instruction part of it, Mark. Yeah. And I think, you know, hearing from

(15:42):
teachers and parents alike, I think the over usage of it is really what is causing a lot of this
challenge. But you got to kind of look behind the scenes and say, well, why is it being assigned so
much? Is it because it is a helping tool for a teacher or because administrators are clamoring
for the data that they get from it? Yeah. Or they're being required to do it by the state.
That's another good question. Yeah. All right. And our last story of the night is really the

(16:07):
big story of the last two weeks. We're going to return to this Canvas Instructure breach and to
really debrief what has happened over the last two weeks. We got to bring in our regular,
our cybersecurity expert. Michael, we've made you an unofficial guest of the podcast. Every time
something really, really bad happens in the world of cybersecurity, we're going to call you back in.
So Michael Klein from the Institute of Security and Technology, how are you doing today? And

(16:31):
what brings you here? Yeah, I'm doing OK. I'm excited to be back. Excited to be a friend of
the pod. And yeah, what brings me back is the Canvas Instructure incident that we've been
dealing with for the last week or so. I think like many people, I've been pretty much nonstop
dealing with this since at least Thursday of last week. And so maybe I'll take us back and

(16:54):
walk us through a little bit where we are. So maybe I'll just start with what is Instructure?
What's a learning management system? I'll just super quickly. So I think it's important to this
story. So Instructure is a learning management system used predominantly in higher education,
though it is used in K-12 as well. And it's a place where you as a teacher can post your lessons

(17:18):
and have conversations with students online. Students can post their homework. But it's
not just that. It also integrates with lots of other systems. And so this is going to be
important for the conversation as well. Based on our understanding of what's been reported,
and some of this is coming from a webinar with Instructure today, where they did their first
kind of open to the public webinar. The incident timeline starts on April 29th. Instructure detected

(17:43):
unauthorized activity in Canvas. They then revoked the access that those threat actors had. This was
Shiny Hunters. Shiny Hunters is one of a few groups of mostly teenage and early 20s cyber
criminals. You also have like Lapsus and Scattered Spider and a number of others that are kind of a
similar type of organization. But they used a cross-site scripting vulnerability to get into

(18:08):
an account that's a free-for-teachers account. And then from there escalate privileges to be able to
have an authorized administrator access. And from there they were able to exfiltrate a large
amount of information, including things like student's name, email, Instructure ID, as well as

(18:30):
messages potentially within the system. But they said there was not, there did not seem to be
access to any other kinds of PII, like financial information, social security numbers, or
credentials and things like that. They engaged CrowdStrike, which is obviously a threat
intelligence firm and does digital forensics and incident response. And Shiny Hunters posted on

(18:53):
their leak site that they had gotten this information. At this point we thought this is
just a data breach, right? At this point we're like, okay, we know how data breaches work. This
is a very big data breach. But at this point we just need to know, you know, which data for which
people over which period of time, right? And then we make our notifications and we try to mitigate
the risk from that. Fast forward to Thursday of last week when Shiny Hunters said, no, just

(19:18):
kidding, we're still here and used a second vulnerability that was also a cross-site
scripting attack to get into Instructure's essentially like their login page and then
be able to post a ransom note that students in 300 organizations saw. And so that kind of made
the rounds on social media and led to a bunch of other impacts, right? So when we think about

(19:40):
cybersecurity, sorry, and I've gone very deep already, but we think about our CIA triad, right?
Confidentiality, integrity, availability. Confidentiality is our data breaches, right?
What we had now is an availability problem because Instructure then took the entire website down
to make sure that they had evicted the threat actor. And now you've also, I think, lost the

(20:01):
trust of many in the system, right? And this is where it has become different from a lot of other
incidents because at this point you had state departments of education, school districts,
universities, and other ed tech vendors breaking their connections with Canvas because Canvas, as
I mentioned, is not just a learning management system. It also has APIs connecting to hundreds
of different ed tech applications, including sensitive systems like student information systems,

(20:25):
financial systems, especially in higher education and things like that. And so at this moment,
colleges are about to go into finals. They're moving towards graduation. And if you can't tell
the registrar that a student has a certain grade, then they can't graduate. And so now you're
looking at a really challenging moment for an extortion attempt to be happening. And so that's
kind of where we were. And they, again, brought in CrowdStrike. CrowdStrike has said they don't

(20:51):
have any indication that the threat actor is still in the environment. They've taken a number of
remediation steps. However, to my knowledge, no one I've spoken to has gotten a list of the
accounts that were impacted or the specific data that were impacted. And there are still a number
of states and universities and vendors who have not re-enabled their access to Instructure.

(21:13):
Now, Shiny Hunters is known for specifically targeting Salesforce instances. And so when we
first learned about this one, my understanding or my assumption was that Shiny Hunters was just
targeting Salesforce. Then the pivot to the actual product to Canvas itself. Do we know if the initial
target, the initial breach on April 29th, as you mentioned, was actually on Canvas or was it simply

(21:38):
targeted towards Salesforce? And at some point there was a pivot. So based on what has been
reported, including today in their open meeting, there are two different things happening here,
right? So there was a Salesforce breach that impacted many organizations through something
called Salesforce drift, right? Or Salesforce drift, including Infinite Campus, right? Was

(22:00):
impacted by this kind of breach. That is separate and apart, seemingly, from this breach. This breach
was a cross-site scripting vulnerability that was found in the system and then was used to exploit
that. We don't have any sense that there is a connection between those things. Two separate,
distinct events took place. Yep. Interesting. And the interesting thing here is both of the

(22:23):
vulnerabilities were the same kind of vulnerability and they were the same kind of vulnerability in
the same system, right? So the first data breach instance was a cross-site scripting attack into
Instructure free-for-teachers version. And then the second one was also through the same system,
at which point they've now shut down the free-for-teachers product. So today or yesterday,

(22:47):
Instructure releases their, I guess they're kind of not really a mea culpa, but their status update
to their user base, saying that they've come to an agreement with the, they used interesting
phrasing to me. I think they said unauthorized actors is what they called shiny hunters.
So give us a quick overview of what they said in their release to their user base.

(23:10):
Yeah. So what Instructure said was that they have reached an agreement with the threat actor
and there were kind of three or four pieces to that, right? So they never used the word
we paid a ransom or we paid the money, right? Although I think many people are assuming that
that's what happened. Sure. There's no proof of that yet, right? It's unlikely that shiny hunters

(23:31):
were just like, oh, okay, we're cool with it now. We're just not going to do anything. Right.
Love it. But the things that happen here, the things we usually look for, right? They said
the data was returned to them. They received confirmation that the data was deleted and that
shiny hunters said that they would not conduct any further extortion on the various institutions

(23:52):
that were impacted through this breach, right? Which is something that I think a lot of people
were concerned about, especially given the extortion note on last Thursday, which did say
it gave everybody the chance to pay them by a certain date, including the colleges and school
districts. All that is to say, it's hard to trust a cyber criminal organization and there is the

(24:15):
possibility that they won't further extort them for this. There's also the possibility that, you
know, people can splinter from these groups, right? These groups are loosely affiliated groups of young
people who sometimes have different feelings about the direction they want to go. You know, we saw
something similar with the power school incident. I believe it was power school incident where, you

(24:35):
know, pinky promise we're not going to do anything with the data. And again, different organizations,
different threat actors. But a couple weeks later, the threat actor was contacting districts,
individual districts, and, you know, individuals saying, hey, unless you want Suzy's information
released, we're going to release this. So there's not a great track record there. But again,

(24:57):
they've said they've deleted the data. You have to kind of, I guess at this point,
take them at their word, maybe. It'll be interesting. Yeah, I mean, that's certainly
what Instructure is doing, right? And so I think a couple things to point out in terms of differences
with the power school incident. I think one piece here is that we did have, with power school, we
only found out after everything was done, right? So power school had been hit. They had been

(25:22):
notified by the threat actor. They had paid the threat actor. And then they had kind of gone
through the steps of remediation for the most part that they were going to take, right? And then it
was announced that the incident happened. And so there was much more effective communication,
I think, because it was not in the same way, an ongoing situation, or at least not in quite the

(25:43):
same way. In this situation, it was like, they detected it, which is actually positive, right?
Like, seemingly power school did not detect the incident as it was occurring. And this was
detected. That may have also made the threat actor think, huh, we probably need to make this kind of
loud and threatening in order to get paid. And so I think it just changes the dynamic of the

(26:04):
situation. I think the other piece that's really important here, and then we talked a little bit
about it, is there was an operational disruption, both Canvas taking down their own infrastructure,
you know, for a time to make sure that they felt confident putting it back up. And then,
of course, the knock-on effects of many other people disconnecting their systems. And there
are still plenty of states and districts that have not reintegrated. And there's a multi-step

(26:28):
process here too, which we haven't talked about yet, which is like, you have Canvas, right? Like,
do I feel comfortable logging into Canvas and having people use Canvas again? Which is one
question. Then the other question is, do I reintegrate all the APIs, right? Do I reconnect
everything that goes to those more sensitive systems? And I think the risk is, you know,
I mean, significantly lower just to use Canvas again, because the data has already been taken,

(26:50):
right? So it's not like there's that much more harm to be done there in quite that way.
But I think the next one is a question about what is the risk appetite of various organizations and
what are the assurances they're being given that would make them feel comfortable reconnecting
their systems? I think that's a really important question about trust in the ecosystem.
Well, and in a bizarre move, Shiny Hunters actually posted a message today

(27:15):
to the community saying, hey, we've reached an agreement. We're done here. Please stop
contacting us, which goes to show how many institutions or media or individual citizens
are reaching out to Shiny Hunters to discuss, confirm, negotiate, who knows. But for them to
say, stop calling us. We're done here is a bizarre move. Absolutely. Now we can kind of look at this

(27:41):
as being in the past. I think last week when we first started talking about this one, we thought
this was a data breach that had come and gone. And we're just dealing with the results of that one.
But now that we have an active breach, data loss, a compromise of the system, the integrity of the
system has been compromised. Where do we go from here? What do we need to think about as a community

(28:03):
as a whole? And then for individual customers that use Canvas or are considering Canvas,
what should we be thinking about? Yeah, I think a few things. So one thing I should mention is
you know, when this happened with PowerSchool, I was in a different role. I was at the Department
of Education helping to kind of coordinate that response. And we were able to convene people

(28:25):
in a confidential setting to be able to have these conversations and understand the impact and kind
of how to move forward. If you fast forward to now, the authorities and the people and the capacity
that allowed that to happen have not really been maintained at the department and elsewhere.
I think there may be a desire to kind of bring that back. But I think what we ended up doing now

(28:47):
is I convened on Friday, so a day after the second incident, we got 22 states together
and had a conversation about what the impact looked like there. And then today, we brought
together 24 states and had a similar conversation about where people were. This is like state SISOs
as well as education SISOs for the state education agencies, just to get a sense of what the impact

(29:11):
looked like across higher ed and K-12. And so I think a couple of the big themes that came out
of those conversations were one, how do we do more effective vendor risk assessment and management,
right? Because it seems as though SOC 2s are not sufficient or they're no longer the trust signal
they once were, right? Because both PowerSchool and Instructure have robust SOC 2s, right? And

(29:37):
so then the question becomes, how do you change vendor behavior and vendor practices, right?
Before, during, and after an incident. So I think that's one set of policy questions that are coming
up right now. And you'll see House Homeland Security has called a hearing and is bringing
Instructure to a hearing, I think it was a week from now or two weeks from now.

(30:01):
I'm going to be briefing a couple of congressional committees tomorrow and the next day. And so
this is a very live topic for people right now, because I think this broke through in a way that
some other incidents had not. Potentially that's because of the timing towards graduation time.
I think that coming back to the LMS piece of this, when we think about what is our critical

(30:23):
infrastructure in our sector, most of it is behind the scenes. The LMS is the one thing that is
student facing and impactful in the classroom. You don't necessarily see that with an SIS or an ERP
system or those kinds of things, right? So this was very clear that this was a problem and it
showed the unintended consequences of one actor being compromised and everyone else losing faith,

(30:48):
momentarily at least, and like all the things that that breaks, right? And so I think that this is
bringing that conversation together where even vendors are now saying, wait, so how do we build
trust among each other? Because this is an opportunity for us to really look and say,
how do we, in a moment where trust in ed tech is at an all-time low and where there's a lot of

(31:11):
pushback on technology in schools, this is not a great look. And this is a moment where we might be
able to change the direction, hopefully, of the conversation. Yeah, this isn't doing any favors
for those screen time limit conversations and stuff like that. That's a great point that ed tech's

(31:31):
not in a great spot right now and this sure didn't help the situation. What would you tell a parent?
I've had a couple parents of college kids reach out to me and they're concerned about identity
theft. And I said, well, yes, but their social security number is likely already on the dark web.
Identity theft is a threat no matter what. I said, to me, the larger threat there is very,

(31:55):
very tailored phishing attempts at the student. Because now, in theory, they have access to
potentially what classes they were taking, definitely what university they're enrolled at.
You can time a phishing email really well around payment timelines of, hey, your fall semester
bill is due or something like that. What would you tell a parent or even a student

(32:20):
to watch out for at this point, Michael? This is one of those challenging things where,
unfortunately, we have to devolve responsibility down to people who shouldn't have to worry about
these things and didn't cause the problem in the first place. So I want to just name that first.
But what I would say is, I think the answer is twofold, right? I think you're right to say that

(32:40):
fraud is likely the direction here, right? And so the idea that you could have targeted phishing
attempts against students or against parents related to the university and any messages
that went back and forth and things like that, I think is definitely possible. I think the bigger
challenge is, do institutions that were caught up in this incident become the targets of further

(33:05):
breaches because people are now paying attention, right? And so that does pop up a lot, right,
where you get a focus on a particular industry for a period of time and then a certain threat
actor or group of threat actors kind of like work their way through that. So I do think that's
possible. In terms of what individuals can do, I think it's always just good practice, right,

(33:25):
to make sure that you're doing things like turning on multi-factor authentication, right?
Because I think that most of the attempts to phish you, regardless of what it is,
are things where they're going to be asking you for information. And if it is something that you
have phishing-resistant multi-factor authentication on, you can't get phished for that, right? That's

(33:45):
something where you just can't give up that information. Fraud's a little bit different,
right? Sending money to the wrong person is a challenge. And so that really has to do with
ensuring that if you get a phone call, making sure that you get a number to call back, right,
and then actually calling back that number. And so checking those things and having your
due diligence for those. And then I think, you know, it's always a good idea to just like lock

(34:08):
your credit if you're not using it. Like, I have my credit locked. I think those kinds of things
are just generally good practice and make you resilient to these things. And so I would
encourage people to go through those general good practice things because this is likely not
the first or last time this is going to happen to them. And so just being ready for that makes you
less liable to fall for those kinds of things. Or even if you do fall for it, you have to take four

(34:32):
or five steps before you're there. And you're like, it slowed you down enough to know you're
making a bad choice. Yeah. And that credit lock thing, that's free. All three major credit
organizations offer it as a service. You just have to create an account on their website and it's
free. Like, you can do it. It's not a big deal. My dad, my dad can do it. And he's not tech savvy
at all. Yeah. Even my old man, my old man can do it. A couple of other things I would say,

(34:56):
and especially for school districts right now, I think one important lesson here is thinking through
what happens when these core systems go down. Do you have ways to be resilient to that in terms of
analog or manual ways of doing the things you need to get done? Because a lot of people are
now experiencing that because the things that were connected between their LMS and their SIS

(35:20):
or other things like that are broken. People are having to like revert to old practices.
And so I think just like walking through that process as a tech department is really important
and also helping your administration, superintendents and others understand like
what this would look like if this happened to us. And for a lot of school districts,
one positive thing is that, you know, Canvas was not the predominant learning management system in

(35:43):
a lot of places. Some places do use it, but I would say swap in your local version of this thing
and think about what that would break in your district. And so just being able to take this
lesson and apply it to a system in your own school district where this would have that kind
of disruptive impact for you and how you would become resilient to that, I think is a really

(36:03):
important lesson to think through. Yeah, that's an easy tabletop conversation to have of like,
this system is down. It doesn't matter why it's down. This system is down. What does that ruin
for your day? You know, like is this final season, like in this example, what does that screw up
for finals? Yep, absolutely. And I don't know if this is relevant for this particular conversation,

(36:24):
but I think one of the things I continue to come back to is each piece of the problem that we saw
here could have been better handled if we had a more robust and better supported federal
incident response capacity, whether it's at the Department of Education and having enough people

(36:46):
there to kind of be able to help stand up responses to these, whether it is authorities
like critical infrastructure partnership advisory councils, which were the thing that allowed us to
convene in a confidential way without having to make it open to the public. All of the different
things that we had kind of set up over the course of many years, many of those no longer exist. And

(37:07):
so MS-ISAC obviously is no longer no cost to everyone, which means that the quick sharing
of information is not there for every public school and public institution. So all of these
pieces kind of wrap around and help support making a resilient ecosystem. And a lot of those
things at the moment are just not there. And so it makes it a lot more challenging in these moments.

(37:32):
Well, I think that's a big thing that I observed on the sideline was we saw the first
implications of a distributed federal education system, right? We did not have a response from
the Department of Education simply because a lot of that arm has been dismantled and distributed
down to states. And so, as you mentioned, you had a call with 22, 24 states. I'm going to guess that

(37:58):
was simply because you have a Rolodex of 22, 24 state CISOs and you can do that. We did not have
all 50. And I'm going to guess that within the 22, 24 states that you did have on the call,
the responses and the support that they're able to provide to their districts was varied.
This is not at all a knock on the states. They're doing the best that they can.

(38:19):
But it goes to show that when we have a system that goes across 50 states, but we don't have
a coordinated effort to respond to an incident that happens across all 50 states,
our school districts are the ones that suffer. Yeah, absolutely. And I think the other thing
I would say is we're also seeing pushes from, for example, SIIA, which is the Software Industry

(38:41):
Association, writing letters to Congress and saying, like, you should fund MS-ISAC. You should
bring back the REMS TA Center, which is an emergency management TA Center at the department.
You should fully fund the sector risk work at the Department of Education. So I think there's
an understanding that, you know, pieces of this puzzle are missing and there are places where you

(39:05):
can just turn things back on. Like, for example, that authority to convene people is not even a
law. That's just an authority that the Department of Homeland Security had created and structures
that were in place that were just taken away. And it should happen tomorrow. You could tomorrow just
say, we're bringing it back. Done. Right. Some of these things don't take a lot of kind of legal

(39:26):
jumping through hoops. Some of it is really just, like, making the choice to make a change.
Well, Michael, we have taken a good amount of your time this evening, and I know probably,
well, these guys make fun of me for what time I go to bed, so I won't open that door.
It's four in the afternoon, Josh. I don't understand why.

(39:46):
Don't say that, Mark. People will think we're doing this during the workday. We're not doing
this during the workday. Did you just hear Josh's school bell ring?
Shut up. Are you doing this at work?
Can I turn this back on you guys for a minute? So do any of you guys use Canvas?
We have dual enrollment kids with our local junior college.

(40:07):
Talk about that, because that came up.
They have Canvas accounts through the junior college, not through my district. And advice
was given to me from a consortium that that breach notification and disclosure
is the university or the college's responsibility, not my district's responsibility.

(40:28):
And I reached out to the college, the local junior college, and they were well aware of
the situation before the lockdown message and all of that. So I understood that as they were
handling that, they were going to go through those processes. But yeah, we have a number
of kids that have Canvas accounts, but it's not through my district.
Okay. Now swap out Canvas for another core system in your district.

(40:51):
What assurances would you need in order to, one, reopen that system, and two,
integrate that system with other systems? Like what would the minimums look like for you all?
Because I think that that is a problem that a lot of districts are working through, but also
states are trying to provide guidance to their districts around when, how safe is safe enough,
or when do we feel comfortable doing this?

(41:14):
It's, you know, I think there has to be some visibility of ownership there. One,
admitting there was a problem, like feeling like the system owner or company is having some
transparency in the case and telling you what is really going on. Maybe reporting from whatever
third-party incident response team that they had to mitigate the issue, what steps they put in

(41:39):
place, some sort of verification that that vulnerability, if this was a cross-scripting
vulnerability, that that's been taken care of or mitigated. Some of that is, I'm going to say this,
and it's going to sound like I'm passing the buck, but in reality, my role is to flip that switch on

(41:59):
or off most of the time. That decision of, hey, this is a critical system and has to be turned
back on now comes from my central office. And Chris, I don't know if you're in that same mentality
there, but, you know, if my boss says this is getting turned on, it's why I will advise as much
as I can, but if the stance is this has to come back on, it's coming back on. I will give advice

(42:25):
and, you know, we'll have those discussions behind closed doors, but if the ultimate decision is,
Josh, you need to turn this back on, I'm turning it back on. I think the hard part is, and a lot of
districts were figuring out, do I pull the trigger and disconnect? And then obviously, then this next
question is, when do I reconnect? The hard part is, I don't think you can ever know for sure whether

(42:46):
or not the system is safe. We are asking another vendor to do a service for us. And so in order to
do that, we have to trust that they know how to do that service and they know how to do it right.
So ultimately, it takes the vendor, the third party, to be able to say, we have a problem,
I need you to disconnect, or we're disconnecting for you, or it's okay to reconnect. I think the

(43:06):
real frustration that a lot of districts had during this event was that there was a lack of
information from the vendor, which they did, I will give them full credit, they did acknowledge
their lack of communication. I do think this was a little bit unique where this wasn't a
in hindsight breach, this was an active situation where you know that the bad guy is

(43:27):
in or around our systems. And so the company does need to be careful with what they do say.
But again, it goes back to a school district needs to hear from the vendor what is possible
or what is needed to be done. And I think that ultimately, we have to, if we're going to trust
them to do the service, we have to trust their word. And that's a hard pill to swallow.

(43:48):
Yeah, I think one last thing, and I'm just going to keep you guys on until you shut me up. But
I think one last thing here for me is, I think, and this has been a hobby horse of mine for a
while, because I didn't come from the world of IT. And in coming into it, I was like, oh,
risk management is a thing I need to understand. Like, what is a risk appetite? And like, how does

(44:08):
it look different for different kinds of systems? And I think it's just one of those things I
continue to come back to now is like, I think, school districts think a bit about that for
financial risk, they think a bit about that for reputational risk, they think a bit about that
for other kinds of risk. But I think cyber risk is hard. And Josh, to your point, it's not to say

(44:29):
you're the one who decides whether it goes on or off, you advise, of course, like, I think that's
correct. But I think one of the challenges is in the vast majority of our districts, including
certainly mine, when I was an IT director, I don't think I always had the tools to make an
effective assessment of whether a system was safe enough or not, or what the specific risks I was

(44:52):
taking on were. And I think that there's a conversation to be had there about, is there a
process where either states can help with that in a much stronger capacity, or some other entity?
I don't know. And I think, you know, of course, the Student Data Privacy Consortium is an excellent
way of addressing some of that risk for data privacy and contracting. It doesn't necessarily

(45:14):
yet speak to how safe is the product itself, right? These are all post hoc situations. And so
I don't know, it's one of those live topics for me that I'm trying to think through more because
making a decision in the moment is really hard, especially with limited information,
especially if you haven't before figured out, like, how much risk am I willing to take on

(45:36):
if the kids are supposed to graduate in three days, and we can't move the grades over, you know?
Right. And all doing it with less funding.
Right. So yeah, it's a big challenge. And I don't mean to leave on a bummer of a note.
Yeah, that's what you're doing.
Yeah.
I was feeling okay till right now.
Oh, bummer. Let's go with the world is a happy place. And like, it's going to be okay. We're

(46:00):
all going to work through it together.
Fantastic ending. And Michael, as much as we love having you on here, usually when you do come,
it's because something really bad has happened. So I hope to never see you again on the podcast.
This is it.
Well, I'll place a bet he's back within six months.
Yeah, yeah, very likely. Thank you very much, Michael Klein.

(46:25):
Thanks, guys.
Ciscloud, a proud sponsor of the K-12 Tech Talk podcast. They can back up your Google
Workspace and your Office 365 data so that you have a second copy of your data in case
of any problems. Check out Ciscloud at Ciscloud.com.
All right. Thanks for listening. And thanks to our sponsors. They make this episode and

(46:46):
the events that we get to attend possible. Let me run through some of the sponsors that
we love so much. Classlink, check out Classlink at Classlink.com.
NTP, you can email our friend David, David Wren at NTP-inc.com.
Fortinet, you can email Fortinet Podcast at Fortinet.com.
Get your Forti on, your FortiGate, your FortiAnalyzer and more.

(47:09):
And then Instant IQ. If you're leading IT in your K-12 district right now,
your job is not getting simpler. You manage a lot of devices. You're juggling tickets.
You're thinking about cybersecurity. You're planning your refresh cycles and more.
That's where Instant IQ comes in. They can help you with all of that.
They are a service management platform.

(47:30):
So we are on the road a little bit this summer, July 6th through the 10th.
We will be in Savannah, Georgia at the GAMIS Conference.
And you can check that conference out at GAMIS.org.
It's a great conference, and they're going to talk about network security
and network infrastructure and data privacy, AI, and more.

(47:51):
If you attend, you're going to get all kinds of value out of that registration.
You're going to get to work with other district leaders
and learn about the informed connections that you can make through their infrastructure,
how they protect their data, and just do a lot of networking.
It's more than just folks in Georgia. This is a national conference.

(48:11):
So check out GAMIS at GAMIS.org.
And then Midwest Tech Talk is July 19th through the 21st.
We will be at Midwest Tech Talk at Lake of the Ozarks in Missouri.
Go to MidwestTechTalk.com to learn more about that conference.
Thanks for listening.

(48:37):
The views and opinions expressed on the K-12 Tech Talk podcast are the personal opinions
of Josh, Chris, and Mark, and do not represent the views or opinions of our sponsors or other
organizations that we're affiliated with. The material and information presented here
is for general information and entertainment purposes only.
Thanks for listening, and we'll see you next week.
Advertise With Us

Popular Podcasts

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

Hey Jonas!

Hey Jonas!

Hey Jonas! The official Jonas Brothers podcast. Hosted by Kevin, Joe, and Nick Jonas. It’s the Jonas Brothers you know... musicians, actors, and well, yes, brothers. Now, they’re sharing another side of themselves in the playful, intimate, and irreverent way only they can. Spend time with the Jonas Brothers here and stay a little bit longer for deep conversations like never before.

Betrayal Weekly

Betrayal Weekly

Betrayal Weekly is back for a new season. Every Thursday, Betrayal Weekly shares first-hand accounts of broken trust, shocking deceptions, and the trail of destruction they leave behind. Hosted by Andrea Gunning, this weekly ongoing series digs into real-life stories of betrayal and the aftermath. From stories of double lives to dark discoveries, these are cautionary tales and accounts of resilience against all odds. From the producers of the critically acclaimed Betrayal series, Betrayal Weekly drops new episodes every Thursday. If you would like to share your story, you can reach out to the Betrayal Team by emailing them at betrayalpod@gmail.com and follow us on Instagram at @betrayalpod and @glasspodcasts. Please join our Substack for additional exclusive content, curated book recommendations, and community discussions. Sign up FREE by clicking this link Beyond Betrayal Substack. Join our community dedicated to truth, resilience, and healing. Your voice matters! Be a part of our Betrayal journey on Substack.

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices