Case Study

K-12 School District Deploys Armis Across 15 Schools to Protect IoT and OT Assets Against Malware Attacks

Background

Walton County School District serves approximately 14,500 students across 15 schools and operates a highly diverse technology environment. In addition to managed devices such as laptops, phones, and Google Chromebooks for students, the district has multiple unmanaged IoT and OT assets, including BYOD, security cameras, access control systems, thermostats, HVAC controllers, and occasional rogue devices.

Cyber Security Analyst Kyle Kobos is responsible for the district’s cybersecurity stance. He and his network engineer are tasked with responding to security incidents and taking proactive measures, with a focus on blocking ransomware threats.

The Challenge

An expanding attack surface proliferating with IoT and OT assets was the driving factor in the decision to onboard the Armis platform. “We take a defense-in-depth approach to knowing where critical data is,” Kobos explained. “It became clear we needed to extend that same approach to knowing where our critical assets are too.”

Because staff often bring personal devices into schools to support and enhance student learning, Kobos identified potential security vulnerabilities associated with this practice. For instance, an instructor might bring an Alexa device and connect to the network using staff credentials.

Frequently, outside vendors also bring in devices that pose security risks.

Continue Reading

Challenges
  • Challenges IconGaining full visibility into IoT and OT assets
  • Challenges IconIdentifying unauthorized and unknown devices in the environment
  • Challenges IconBolstering security posture to prevent malware attacks
  • Challenges IconAdhering to the Center for Internet Security (CIS) framework version 8.1
  • Challenges IconWorking within the financial budget available for the district
The Results
  • Solution IconGained immediate visibility into the district’s environment and asset estate
  • Solution IconIdentified 30,000+ assets - twice as many as expected
  • Solution IconDiscovered suspicious and unauthorized connections and rogue devices
  • Solution IconEnhanced the patch management process by zeroing in on potential vulnerabilities
  • Solution IconEliminated major pain points by adhering to the CIS framework
  • Solution IconSaved time and reduced workload
  • Solution IconEnhanced overall security posture