Investment Risk Management Podcast: Strategies to Secure Capital

Protect Your Student and Staff Data

In this episode of the Learning Counsel’s EduJedi Report, host LeiLani Cauthen, CEO and Publisher of the Learning Counsel, speaks with Doug Walsten from Cisco about the broad landscape of K–12 information security. Their conversation frames the modern challenge schools face: protecting student and staff data both when it is stored (data-at-rest) and when it is being transmitted (data-in-motion). This is especially urgent as districts increasingly rely on cloud services, learning platforms, and a wide range of classroom apps that all contain personal information.

Walsten outlines how data can exist across many locations—district servers, cloud systems, teacher devices, and third-party applications—and why that distributed reality complicates security and compliance. Laws and regulations governing student privacy apply regardless of where data lives, so leaders must view security as a governance and risk-management priority. The podcast includes illustrative stories about what can go wrong in school environments, giving administrators concrete context for the risks they manage.

Key takeaways from the discussion include clear, practical steps school leaders and IT teams can take to reduce risk and better protect sensitive information:

Inventory and Classify Data

Begin with a thorough inventory of the systems, applications, and repositories that store student and staff information. Classify data by sensitivity so you can prioritize protection for the most critical records. Knowing where personal data resides is the foundation of any effective security program.

Secure Data-at-Rest and Data-in-Motion

Use encryption and strong access controls for data stored on servers, endpoints, and in cloud services. For data in transit, ensure secure communication channels using up-to-date protocols and centralized network protections. Protecting both states of data reduces the chance of unauthorized disclosure whether files are stored or being shared across networks.

Access Management and Authentication

Implement identity and access management practices such as single sign-on, multi-factor authentication, and least-privilege access. Limit who can view or modify sensitive student records, and ensure role-based permissions are reviewed regularly. Strong authentication reduces account compromise risk from phishing or credential theft.

Vendor and App Governance

Many schools use thousands of third-party apps. Vet vendors for security and privacy practices, require clear data processing agreements, and monitor third-party access. Establish a procurement and approval process so apps are evaluated before being adopted into instruction or district workflows.

Training, Policies, and Incident Response

Human factors are often the weakest link. Provide regular cybersecurity training for teachers, staff, and administrators on topics such as phishing awareness, secure handling of student information, and device hygiene. Maintain clear privacy and acceptable-use policies, and keep an incident response plan ready so your team can act quickly if a breach or data leak occurs.

Ongoing Monitoring and Continuous Improvement

Take a proactive approach by monitoring networks, logging access to sensitive systems, and conducting regular security assessments. Use the findings to refine policies, update controls, and guide investment decisions. Security is not a one-time project but an ongoing process that must adapt as technology and threats evolve.

The episode is recommended listening for district leaders, IT staff, school administrators, and anyone responsible for student privacy and cybersecurity. It provides a clear framework for understanding risks and practical actions to protect student and staff data while supporting digital learning initiatives.

Click Here to Listen

If you can listen to only one podcast this week about K–12 data security, this episode is a concise, practical resource. It highlights the importance of governance, technical controls, vendor oversight, and staff training to protect the investment schools make in student and staff information. Prioritizing these steps helps districts manage risk, maintain compliance, and keep their communities safe.