Background
Walton County School District serves approximately 14,500 students across 15 schools and operates a highly diverse technology environment. In addition to managed devices such as laptops, phones, and Google Chromebooks for students, the district has multiple unmanaged IoT and OT assets, including BYOD, security cameras, access control systems, thermostats, HVAC controllers, and occasional rogue devices.
Cyber Security Analyst Kyle Kobos is responsible for the district’s cybersecurity stance. He and his network engineer are tasked with responding to security incidents and taking proactive measures, with a focus on blocking ransomware threats.
The Challenge
An expanding attack surface proliferating with IoT and OT assets was the driving factor in the decision to onboard the Armis platform. “We take a defense-in-depth approach to knowing where critical data is,” Kobos explained. “It became clear we needed to extend that same approach to knowing where our critical assets are too.”
Because staff often bring personal devices into schools to support and enhance student learning, Kobos identified potential security vulnerabilities associated with this practice. For instance, an instructor might bring an Alexa device and connect to the network using staff credentials.
Frequently, outside vendors also bring in devices that pose security risks.
Challenges
-
Gaining full visibility into IoT and OT assets -
Identifying unauthorized and unknown devices in the environment -
Bolstering security posture to prevent malware attacks -
Adhering to the Center for Internet Security (CIS) framework version 8.1 -
Working within the financial budget available for the district
The Results
-
Gained immediate visibility into the district’s environment and asset estate -
Identified 30,000+ assets - twice as many as expected -
Discovered suspicious and unauthorized connections and rogue devices -
Enhanced the patch management process by zeroing in on potential vulnerabilities -
Eliminated major pain points by adhering to the CIS framework -
Saved time and reduced workload -
Enhanced overall security posture