Writing
Teaching
# week07 ### Welcome back ### Come up and ask me questions for 5 mins :) --- ## If you need help with your logbooks, let me know. -- ## Projects Jesse will now go and look at the course guideline. -- ## Questions? --- ## OK so what happened in the lecture? --- ## Case Study Time. -- ## Green Valley High School ### A third-party data breach Green Valley High School uses **Can'tvas**, a cloud learning management system operated by **Instructable**. Notes: Introduce the exercise as a fictionalised school scenario. The important feature is that the school is affected through a vendor rather than through its own systems. -- Instructable has reported a cybersecurity breach affecting several education customers. An attacker may have accessed Green Valley's student and staff information. -- ## What may have been exposed? - Names, email addresses and student IDs - Course enrolments - Assessment submissions and grades - Teacher feedback - Parent contact information Notes: These are the facts available at the beginning. If students ask for facts the scenario does not provide, "we do not know yet" is a useful answer. -- ## Your role You are the school's cybersecurity consulting team. The principal needs advice, but the facts are incomplete and decisions cannot wait. Notes: Put students into groups. Encourage them to state assumptions and separate what is known from what must be confirmed. -- ## 1. Assess the incident ### 15–20 minutes - What are the biggest security and privacy risks? - Who could be harmed, and how? - What must the school learn from Can'tvas? Notes: Look for harms grounded in the school context: phishing, impersonation, identity misuse, exposed grades or feedback, bullying, wellbeing, and loss of trust. There does not need to be one stakeholder group at greatest risk. -- ## The first 48 hours - What should the school do immediately? - What should it avoid doing? - What evidence should it preserve? - Who needs to be involved? Notes: Useful areas include escalation, the incident response plan, recording vendor answers, checking local systems and integrations, monitoring for phishing, considering temporary access restrictions, legal or privacy advice, and careful initial communication. -- ## Advise the principal Choose your **top three recommendations**. Explain why the school should do them in that order. Notes: Ask groups to make a decision rather than present an unranked brainstorm. Different rankings are acceptable when the assumptions and trade-offs are clear. -- ## 2. Manage the response The principal is unsure whether disclosure is the responsibility of the school or the vendor. They want to respond publicly without causing panic or claiming more than they know. Notes: This is the second reveal. The task is broader than deciding who is legally responsible: the school still has relationships and operational responsibilities to manage. -- ## What should the school do? - How should it communicate with staff, parents and students? - What support should it provide? - Should it continue using Can'tvas? - If yes, under what conditions? Notes: Give groups about 15 minutes. Look for communication that distinguishes confirmed facts from unknowns, gives people useful actions, avoids blame and overpromising, and provides a route for questions and wellbeing support. -- ## Make the call State and justify your recommendations. Balance: - Security and privacy - Student wellbeing - Cost and disruption - Trust and reputation Notes: Both continued use and a temporary restriction can be defensible. Push students to name the evidence or assurance that would change their decision. -- ## 3. Build future resilience One week later, Can'tvas confirms that the attacker also accessed archived student records from previous years. Who is affected now? Notes: Pause on the final question before showing the next slide. Students should notice that former students and possibly former staff or parents may now be affected. -- ## The next 12 months Recommend and rank **three to five practical measures**. For each one, explain: - Why it matters - How it reduces risk - What it costs or displaces Notes: Possible areas include data retention, deletion of old records, vendor assurance, contracts, access controls, integrations, response exercises, communication plans, and data governance. Opportunity cost includes time, disruption, staff capacity and reduced functionality—not only money. -- ## If you had to choose only two? Which measures would you prioritise? Why those two? Notes: Use this only if groups finish early or if you want to force a sharper prioritisation discussion. -- ## What made this difficult? - Acting before every fact is known - Depending on a third party - Communicating without overpromising - Choosing between competing harms Notes: Use this as a short class debrief. The goal is not one perfect answer; it is a defensible response that adapts as the facts change. --- ### Incident response - Preparation - Detection and analysis - Containment - Eradication - Recovery - Post-incident review Notes: Map the exercise back to the lifecycle. Ask where each phase appeared and where the boundaries blurred. Preparation and lessons learned should connect directly to the 12-month resilience recommendations.