DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NY State Comptroller DiNapoli Releases School District Audits

Posted on April 18, 2021 by Dissent

New York State Comptroller Thomas P. DiNapoli announced school district audits this week. Here are the summaries with links to the audit reports:

Hudson City School District – Information Technology (Columbia County)

District officials did not adequately secure and protect its information technology (IT) systems against unauthorized use, access and loss. The board and district officials also did not adopt adequate IT policies or a disaster recovery plan. Auditors found questionable internet use on four of six computers tested. School officials also did not disable 123 of the 462 enabled network accounts auditors examined. These 123 user accounts were not needed and included generic and former employee accounts. In addition, sensitive IT control weaknesses were communicated confidentially to officials.

Royalton-Hartland Central School District – Information Technology Contingency Planning (Genesee County, Niagara County and Orleans County)

The board and district officials have not developed and adopted a comprehensive written information technology (IT) contingency plan. The district pays $10,500 for central site infrastructure support, which includes a disaster recovery plan template, a key component of an IT contingency plan. Although the district paid for a template, officials did not obtain it. Without a comprehensive written IT contingency plan in place that is properly distributed to all responsible parties and periodically tested for efficacy, district officials have less assurance that employees will react quickly and effectively to maintain business continuity. As a result, important financial and other data could be lost, or suffer a disruption to operations.

Related posts:

  • Kept in the Dark — Meet the Hired Guns Who Make Sure School Cyberattacks Stay Hidden
  • Audits of New York schools and the State Education Department reveal ongoing significant concerns
  • HIPAA Security Rule Facility Access Controls – What are they and how do you implement them?
  • NYS Comptroller DiNapoli Releases More School District Audits
Category: Commentaries and AnalysesEducation SectorU.S.

Post navigation

← Phone House Spain hit by Babuk ransomware, 3 million users affected.
Vermont Health Connect had 10 data breaches last winter →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Stormous claims to have protected health info on 600,000 patients of North Country Healthcare. The data appear fake.
  • Back from the Brink: District Court Clears Air Regarding Individualized Damages Assessment in Data Breach Cases
  • Multiple lawsuits filed against Doyon Ltd over April 2024 data breach and late notification
  • Chinese hackers suspected in breach of powerful DC law firm
  • Qilin Emerged as The Most Active Group, Exploiting Unpatched Fortinet Vulnerabilities
  • CISA tags Citrix Bleed 2 as exploited, gives agencies a day to patch
  • McDonald’s McHire leak involving ‘123456’ admin password exposes 64 million applicant chat records
  • Qilin claims attack on Accu Reference Medical Laboratory. It wasn’t the lab’s first data breach.
  • Louis Vuitton hit by data breach in Türkiye, over 140,000 users exposed; UK customers also affected (1)
  • Infosys McCamish Systems Enters Consent Order with Vermont DFR Over Cyber Incident

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Australian law is now clearer about clinicians’ discretion to tell our patients’ relatives about their genetic risk
  • The ICO’s AI and biometrics strategy
  • Trump Border Czar Boasts ICE Can ‘Briefly Detain’ People Based On ‘Physical Appearance’
  • DeleteMyInfo Wins 2025 Digital Privacy Excellence Award from Internet Safety Council
  • TikTok Loses First Appeal Against £12.7M ICO Fine, Faces Second Investigation by DPC
  • German court offers EUR 5000 compensation for data breaches caused by Meta
  • How to Build on Washington’s “My Health, My Data” Act

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.
Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report