Staying Ahead of K–12 Email Threats: How Aldine Protects 39,500 Mailboxes
Email security for K–12 districts are harder than it looks. Schools are facing a surge in phishing, account takeover, and socially engineered attacks that blend seamlessly into everyday communication — and existing defenses are no longer keeping up.
Aldine Independent School District knows this firsthand. Protecting 39,500 mailboxes across one of Texas's largest school systems, Aldine was seeing advanced attacks slip past native controls while manual phishing triage drained their cybersecurity team. After adding behavioral AI to their stack, they now stop 22,700 advanced attacks per month and have neutralized 23 account takeovers.
In this fireside chat, we'll cover:
How the threat landscape for K–12 email has evolved and why existing defenses fall short
Where native controls in platforms like Google Workspace and Microsoft 365 leave districts exposed
How behavioral AI catches the socially engineered attacks and account takeovers that rule-based tools miss
How Aldine’s security team reclaimed hours of manual work through automated detection and response
If you’re responsible for email security at a K–12 district, this session gives you a real-world benchmark and practical steps you can take back to your team.
Featured Speaker:
Mick Leach, Field CISO, Abnormal AI
Kyle Pearston, Cybersecurity Leader, Aldine ISD
Inside the Attacker’s Playbook: How EDR Evasion Really Works
Modern attackers are consistently finding ways to slip past Endpoint Detection and Response (EDR) tools. This webinar explores the technical reality of these evasions, covering kernel bypasses and process injection across all major operating systems. We focus specifically on the challenges faced by modern organizations to provide actionable strategies to improve visibility across cloud, identity, and network environments.
Attendees will learn the following:
How advanced cybercriminals routinely evade, blind, and disable Endpoint Detection and Response (EDR) solutions across Windows, Linux, and macOS environments using sophisticated techniques like direct syscalls, API unhooking, and kernel-level driver tampering.
Why traditional endpoint security creates dangerous blind spots across unmanaged network vectors leaving XDR and MDR frameworks equally vulnerable to evasion.
How to beat EDR evasion and build a connected SecOps stack that unifies visibility and response across the entire environment.
Featured Speaker:
Ricardo Marques, Technical Director - US
Quantum Computing: The Importance of Transparency
Join the GRF Business Resilience Council for a briefing with Dr. George Shea of The Foundation for Defense of Democracies.
As software and hardware supply chains grow more complex and interconnected, the inability to see inside the components that make up critical systems has become a defining national security vulnerability, one with a known and closing deadline.
NIST finalized its first post-quantum cryptography (PQC) standards in 2024, and the U.S. government has set expectations that federal systems complete the migration away from quantum-vulnerable algorithms well before a cryptographically relevant quantum computer (CRQC) is estimated to emerge, with most timelines placing that window between 2030 and 2035.
Cryptography Bills of Materials (CBOMs) are the prerequisite for meeting that deadline. An organization that cannot enumerate every instance of RSA, ECC, and other vulnerable algorithms across its systems, libraries, and dependencies cannot prioritize, sequence, or execute a migration at enterprise scale, and without a CBOM that inventory does not exist.
Software Bills of Materials (SBOMs) address the parallel challenge at the component level, providing the dependency visibility needed to identify where vulnerable cryptographic libraries are embedded several layers deep in a supply chain, precisely the exposure that is hardest to find and slowest to remediate.
Together, SBOMs and CBOMs represent the foundational transparency layer that makes the PQC transition tractable rather than chaotic, and federal procurement policy that fails to require both at machine-readable, continuously updated standards is not just lagging behind best practice, it is shortening the effective runway for one of the most consequential infrastructure modernization efforts in the history of U.S. national security.
Identity Orchestration: The Missing Layer in Your District's Digital Learning Environment
Managing student and staff access across dozens of apps, devices, and platforms is one of the most complex — and often overlooked — challenges facing K-12 IT teams today. This session breaks down identity orchestration into a practical six-layer framework, showing district leaders exactly how their portal, single sign-on, authentication, provisioning, rostering, and applications should work together — and where gaps in that system create real risk for students and staff. You'll walk away with concrete steps you can bring back to your team immediately, whether you're cleaning up an environment that's grown organically or building a stronger foundation for your district's next technology initiative.
Key takeaways:
A plain-language breakdown of the six layers of identity infrastructure and how to spot where your district's setup may be falling short
Why device management is a missing piece in most districts' identity strategy — and what it takes to close that security gap
A practical checklist for identifying access failures, deprovisioning risks, and cybersecurity exposure points in your current environment — with clear next steps for each
Featured Speakers:
Susan Bearden, Director of Product Marketing
Mat Pullen, Director of Product Marketing
AI Interrupted and What to Do Next: a TTX After Action Review
Brian Katula, Director of Operational Resilience at Global Resilience Federation
A Briefing on the 2026 Verizon Data Breach Investigations Report (DBIR)
David Hylender, Associate Director of Cybersecurity Consulting and DBIR Co-Author at Verizon Business
Philippe Langlois, Co-Author of the DBIR at Verizon Business
Escaping the Questionnaire Trap: Data-Driven Visibility and Resilience for Third-Party Software Risk
Gary Schwartz, SVP of Marketing at NetRise
Are We Already Behind? AI, Q-Day, and the Race for Resilience
Mark Orsi, CEO at Global Resilience Federation
Moona Ederveen-Schneider, Founder and Board Advisor, and Faculty at University of Cambridge
Sounil Yu, Chief AI Officer at Knostic
Y. John Jiang, PhD, Researcher and Author, Cloud Security Alliance
Alex Sharpe, Managing Director at Sharpe432 LLC and Adjunct Professor of Cybersecurity Risk and Strategy at NYU
Charles Blauner, Operating Partner at Crosspoint Capital Partners
Iran War and How It's Impacting U.S. Allies, Energy Markets and Supply Chains
Behnam Ben Taleblu, Iran Program Senior Director and Senior Fellow at The Foundation for Defense of Democracies
Updates and Lessons Learned About the Canvas Cybersecurity Incident
Join the GRF Business Resilience Council for a brief on the Canvas LMS cyber incident perpetrated by ShinyHunters.
K12 SIX National Director Doug Levin will moderate a discussion and Q&A with Instructure leadership including CISO Steve Proud, CMO Armin Molavi, and Senior Education Policy & Strategy Director Tracy Weeks.
*This event is TLP: AMBER
Roundtable on Copilot Risks and Real-World Defenses
This roundtable will bring members together to openly discuss the real-world security challenges introduced by AI like Copilot. The purpose of this session is designed to share experiences, concerns, and practical lessons learned from teams already using the tool.
Participants will explore topics such as:
• Client Confidentiality, Privilege & Ethical Obligations • Client Imposed AI Restrictions & Contractual Risk
• Data Retention, Discovery & Auditability of Copilot Interactions
• Visibility Gaps & “Shadow AI” in Legal Environments
• Secure Development & Legal Specific Code Risks
• IP Ownership, Licensing & Downstream Liability
• Governance Models: Policy vs. Enforcement
• Incident Response & “AI Caused” Security Events
• Knowing what we know, What would we do differently
The discussion will also dive into how organizations are adapting their security practices, what policies are being put in place, and how code review processes are evolving.
Attendees are encouraged to share their own perspectives, ask questions, and collaborate on potential solutions. By the end of the session, our goal is for participants will walk away with a broader understanding of the threat landscape, as well as actionable ideas and peer-driven strategies for safely integrating AI assistants into modern development workflows.
Speakers:
John Hall, Managing Director of Security & Information Governance at Troutman Pepper Locke
Kenny Hall, Director of Cyber Security and Risk Management at Butler Snow LLP
Karl Mueller, Senior Director and CISO at Crowell & Moring
Jon Washburn, Chief Information Security Officer at Stoel Rives
Moderated by: Eric Anderson, Senior Director, IT and Security at Seyfarth Shaw LLP
Leveraging Defender XDR & Sentinel Automations
As threats increasingly target identities, speed and consistency of response are critical. In this session, we’ll explore how Microsoft Defender XDR and Microsoft Sentinel can work together to automate high‑impact security actions—specifically disabling compromised user accounts and revoking active user sessions in near real time.
Attendees will learn how to leverage detection signals from Defender XDR and orchestrate automated response workflows in Sentinel to contain identity‑based attacks such as phishing, token theft, and account takeover. We’ll walk through practical automation patterns that reduce manual effort, shorten attacker dwell time, and enforce consistent response across the environment.
Key takeaways:
-Learn how to use Defender XDR signals to detect identity attacks
-See how Sentinel automates responses to phishing and account takeovers
-Apply automation patterns that save time and stop attackers faster
Whether you’re looking to mature your SOAR strategy or operationalize Zero Trust principles, this webinar will demonstrate how automation can transform identity protection from reactive to proactive.
Featured Speaker:
-Micah Linehan, Sr. Security Solutions Engineer
Building an Incident Response Plan for OT
The MFG-ISAC OT Training Program, in collaboration with Dragos OT-CERT, invites you to join a webinar featuring Dragos cybersecurity subject matter expert Elan Alvey. Elan will discuss how to build an effective incident response plan for OT environments and offer practical insights to strengthen your organization’s OT preparedness.
*The OT Training Program is open to anyone in the manufacturing space. If there is an organization or individual you would like to join this call or the program, they will need to register for the free Dragos OT-CERT portal. You can register here: https://www.dragos.com/community/ot-cert/registration
Please click the "How did you hear about OT-CERT" drop down menu to MFG-ISAC.
U.S. and Israeli Strikes on Iran and Tehran’s Retaliation
Join the GRF Business Resilience Council for a briefing from Austin Warnick, Director of National Security Intelligence at Flashpoint. Austin will address:
Kinetic Expansion: Analysis of combat operations and strikes within Iran and across the broader region
Cyber Landscape: Assessment of current threat actor activity, digital disruptions, and intercepted “chatter”
Strategic Perspective: The Flashpoint outlook and projections for the next phase of the conflict
The End of Chinese Control of the Panama Canal
Join the GRF Business Resilience Council for a briefing by Elaine Dezenski, Senior Director and Head of the Center on Economic and Financial Power (CEFP) at the Foundation for Defense of Democracies (FDD).
She will cover the Panama Supreme Court decision on January 29th that ended Chinese control of the ports surrounding the Panama Canal, and the decision's impact on global trade and supply chains, geopolitics and security.
OT Security Training Program
The OT Security Training Program is a partnership between Dragos OT-CERT and MFG-ISAC that gathers small and medium suppliers of large OT-centric businesses and provides free resources and training. By improving OT security and reducing risk, together we can strengthen resilience for the entire ecosystem.
The program will offer live virtual training and a portal to access training materials and guides. A chat tool will allow participants to communicate with one another to facilitate operationalizing the training materials.
Contact tchase@grf.org with questions about this free resource, or simply register for the webinar to join us.
*Please note: You must register for the free OT-CERT portal before you will be sent the invite for the training session. When you register, in the dropdown menu “How did you hear about OT-CERT,” select MFG-ISAC. Register for the portal here: https://www.dragos.com/community/ot-cert/registration/
Communications Disruption TTX - After Action Review
The GRF Business Resilience Council invites you to attend the After-Action Review of the Communications Disruption Tabletop Exercise (TTX) conducted in June & August 2025.
This AAR discussion will feature Brian Katula, Director of Operational Resilience at GRF & Byron Collie, Partner at Next Peak. They will present on findings, including strengths, areas for improvement, best practices and recommendations, as well as how to effectively implement and test these findings in your organizations.
The AAR will be distributed to all GRF members and exercise participants immediately following the call. Please direct any questions you have regarding this TLP: CLEAR meeting to Brian Katula at bkatula@grf.org
From Vendor Dependent to Crisis Ready: Joint Tabletops, OOB Comms, and Privilege that Holds Up
Heavy reliance on MSPs/MSSPs often widens the attack surface. In this session, we walk through a realistic incident storyboard: a managed SOC flags malicious activity, the provider may also be compromised, and the firm’s primary channels (email/IDP/chat) can’t be trusted. What fails first, where privilege gets jeopardized, and how quickly can you pivot?
We’ll translate that scenario into a crisis playbook: counsel-directed, privilege-preserving communication patterns; minimum viable out-of-band (OOB) controls (E2EE, role scoping, immutable audit without content exposure); and clear decision rights across IT/Sec/PR/GC/ExCom.
We’ll cover the tough edge cases—secure communications when an MSP becomes adverse or is under investigation—and how to run joint tabletops (Firm–MSP–Client) that actually build muscle memory: onboarding externals fast, testing unknown-third-party joins, and measuring time-to-pivot OOB.
You’ll leave with practical templates for injects, comms decision trees, and readiness metrics you can reuse—for your organization and with your clients.
Co-led by technical and legal experts, this session prioritizes privilege, defensibility, and operational control—so you can keep working cases even when primary systems and providers are under stress.
Speakers include:
Amy S. Mushahwar, Partner and Chair, Data Privacy, Security, Safety & Risk Management at Lowenstein Sandler
Matthew B. Welling, Partner, Data Strategy, Security and Privacy at Holland & Knight
Navroop Mitter, CEO of ArmorText -Matt Calligan, Director of Growth Markets at ArmorText
*Self report an hour of CPE
*CLE Credit Provided by Lowenstein Sandler LLP The firm is an accredited provider in California, New Jersey, and New York. If you are seeking credit in additional states, please indicate your jurisdiction on the Affirmation Survey that will be provided, and we will issue you a Uniform Certificate of Attendance.
Construction and Manufacturing Supply Chain Cybersecurity and the CMMC
John Kronick, CISO of Tutor Perini, and David Sheidlower, CISO of Turner Construction, will share their CMMC journey and address the importance of this regulation to primes and subcontractors.
We will also discuss the formation of a Construction ISAC and the path to becoming a charter member.
Attendees are encouraged to contribute questions, concerns, and best practices for discussion.
Background:
The Department of Defense published the final CMMC rule on September 10, 2025, which takes effect November 10, 2025. This impacts cybersecurity and supply chain/third party risk professionals who work with defense and federal contractors, including their supply chains.
Mark Berman of FutureFeed, an original CMMC AB board member, will provide a state of the CMMC briefing including:
• Latest CMMC requirements and timelines
• How the new CMMC rule, effective November 10, impacts businesses that are involved with the Department of Defense, federal contractors and their supply chains
• How protecting Controlled Unclassified Information (CUI) strengthens supply chain resilience
Manufacturing Resilience Through the Minimum Viable Factory
When cyberattacks occur in manufacturing environments, traditional business continuity and disaster recovery plans often show their gaps. Because recovery is rarely designed to consider the lack of trust after a cyber event, critical production dependencies suddenly become visible, control systems fail, and supply chain communications break down, causing Recovery Time Objectives (RTO) to stretch from hours into weeks. For manufacturing organizations, this means production stoppages, missed delivery deadlines, damaged equipment, and potentially compromised worker safety. A Minimum Viable Factory (MVF) strategy focuses on moving to a production and supply chain-focused approach to cyber recovery. Through deeper investigation of critical manufacturing processes, IT and OT Security teams can better partner with production managers and plant operations to identify the essential functions and systems that ensure a cyberattack remains a contained incident, rather than a catastrophic shutdown.
Join this webinar to explore key insights, including:
1. Defining the essential manufacturing processes that keep your production lines operational and your supply chain intact.
2. Understanding the difference between creating a Minimum Viable Factory (MVF) and traditional Business Continuity Management/Disaster Recovery (BCM/DR) approaches for manufacturing environments.
3. Learning three practical steps you can take to start building your own MVF with particular attention to securing the IT backbone of your operational technology (OT) environments.
4. Examining real-world examples and lessons learned from successfully implementing MVF strategies in various manufacturing sectors.
Protecting Employees & Business from Extremism, Deep Fakes, Impersonation & Cyber Scams
Join the BRC for a webinar featuring the following topics:
"Protecting Your Employees & Business from Extremism" - Sam Lichtenstein, Director of Analysis at RANE
"Deepfakes & Security" - Brian Katula, Director of Operational Resilience at GRF
"Crypto Currency & Real-World Threats” – Staci Elliott, Senior Analyst at BRC
"Impersonation as a Service, Scattered Spider & Shiny Hunters" – Chris Denning, CSO at BRC
Free OT Training From MFG-ISAC & Dragos OT-CERT
The OT Security Training Program is a partnership between Dragos OT-CERT and MFG-ISAC that gathers small and medium suppliers of large OT-centric businesses and provides free resources and training. By improving OT security and reducing risk, together we can strengthen resilience for the entire ecosystem.
The program will offer live virtual training, and a portal to access training materials and guides. A chat tool will allow participants to communicate with one another to facilitate operationalizing the training materials.
This webinar will be the first meeting of the program.
Construction Sector Operational Resilience & Threat Sharing Briefing
Join the Business Resilience Council (BRC), along with industry leaders John Kronick, CISO of Tutor Perini, and David Sheidlower, CISO of Turner Construction, for a conversation on the formation of a Construction Sector Interest Group focused on operational resilience and cybersecurity threat intelligence sharing.
This interactive, virtual session will include a briefing from BRC analysts and open Q&A on how construction firms and their supply chains can enhance resilience, strengthen security, and move beyond static compliance.
Discussion Topics
Even if you’re not a federal contractor, CMMC compliance represents a strong foundation for protecting sensitive client information
The Operational Resilience Framework (ORF) helps ensure the continuity of mission-critical services during disruptions
The Business Resilience Council (BRC) facilitates cross-sector collaboration and sharing of threat intelligence, warning and mitigation, and best practices
Why It Matters
The Construction Industry depends on many, and many depend on it
Construction projects involve vast sums of money which draw malicious actors
Participation in the BRC empowers firms to go beyond checkbox compliance and focus on resilience and capacity to deliver services in the face of threats
Together, CMMC, ORF, and BRC help position your organization as a resilient, reliable, and trusted partner within federal programs and across your broader infrastructure ecosystem
Who Should Attend
Risk Managers, CISOs, CSOs, cybersecurity analysts, company subs and primes
2025 Semiannual Ransomware Report Executive Briefing + Tutorial on Building, Administering Exercises
Join the Business Resilience Council (BRC) for a webinar that will feature two briefings:
First, an executive briefing of the GRF Semiannual Ransomware Report (SARR), providing high-level trend analysis of observed ransomware incidents from January through the end of June 2025. The SARR will be presented by Tim Chase, GRF Analyst and Director of the Manufacturing ISAC and Energy Analytic Security Exchange (EASE). Data in the report was culled from closed criminal forums and public disclosures.
Second, Brian Katula, GRF's Director of Operational Resilience will provide attendees with a tutorial on how to build and administer an exercise within your organization.
Supply Chain Resilience: Enhancing Detection and Response Strategies
Steve Cobb, CISO at SecurityScorecard
K-12 Crisis: Responding to a Sector-Wide Cyber Incident
Doug Levin, Director of K12 Security Information eXchange (K12 SIX)
Lisa Helme, Assistant Director of Student Pathways Division/State E-Rate Coordinator of Vermont Agency of Education
Andy Lombardo, Director of Technology for Maryville City Schools
Cyber-Physical Security and Digital Twins: A Strategic Approach to Resilience Measurement
Sri Gourisetti, Senior Cybersecurity Advisor for Office of the CISO at Google
Building Holistic Operational Resilience - Integrating Human & Technical Strategies
Edna Conway, Founder of EMC Advisors and former Chief Security & Risk Officer at Microsoft Azure
Ashley Rose, Founder of Living Security
Mark Orsi, CEO of Global Resilience Federation
Minimum Viable Company: The Unstoppable Blueprint for Digital Resilience
Yahya Jarraya, Co-founder of Astran
BRC Virtual Summit on Resilience & Security
Join the Business Resilience Council for the second annual Virtual Summit on Resilience & Security. The online, multi-sector event will feature speakers discussing topics relevant to all-hazards threats, including:
Emerging security threats
Global supply chain risk
Risks to business infrastructure from nation-state actors
Third-party management and resilience
Tackling a major service outage without operational down time
Join us for this complimentary half-day event! Registration and the Call for Presentations are now live.
Organizations interested in sponsoring should contact Jason Beard at jbeard@grf.org