Key Takeaways
- Calvert County Public Schools are implementing a multi‑layered cybersecurity framework that protects students, teachers, and family‑owned devices both at school and at home.
- National data show 82 % of K‑12 schools experienced a cyber incident in recent years, with ransomware recoveries averaging $2.28 million per incident.
- The district’s defense includes network protection, device filtering, classroom‑specific tools, application controls, and continuous cyber monitoring.
- A parental‑control app, Qustodio, is being added to give families greater visibility and control over student device use.
- The IT department conducts an annual review of all software to retire unused applications and keep the environment lean.
- The IT operation is funded by an approximate $3 million annual budget.
- A new cellphone‑use policy aligned with Maryland’s Joanne C. Benson Phone‑Free Schools Act will standardize restrictions across all grade levels, removing the current high‑school lunch‑period allowance.
- Board members discussed extending the policy to bus travel and opened the proposal for public review before final adoption.
Overview of Cybersecurity Presentation
On July 9, Matt Poteet, the director of information technology for Calvert Public Schools, addressed the local school board with a comprehensive update on the district’s cybersecurity posture for the upcoming year. He emphasized that internet safety is not a one‑time checklist but an ongoing, evolving commitment requiring continual vigilance and adaptation. Poteet outlined the district’s strategic approach, which combines technology, policy, and community partnership to safeguard digital learning environments. His presentation set the stage for a detailed discussion of the specific layers of protection currently in place and planned enhancements aimed at mitigating rising cyber threats.
National Cyber Threat Landscape
To contextualize the district’s efforts, Poteet cited national statistics that underscore the urgency of robust defenses. He reported that 82 % of schools across the United States experienced at least one cybersecurity incident in recent years, a figure sourced from the Center for Internet Security. Of particular concern, ransomware attacks targeting K‑12 institutions in 2025 resulted in an average recovery cost of $2.28 million per incident. These numbers illustrate the financial and operational stakes involved, reinforcing why Calvert’s proactive, multilayered strategy is essential rather than optional.
Calvert’s Layered Defense Strategy
Poteet described the district’s cybersecurity framework as a series of interconnected layers designed to protect students, support teachers, govern technology responsibly, and engage families. The first layer involves network protection, including firewalls, intrusion detection systems, and segmented traffic to limit lateral movement of threats. The second layer focuses on device filtering, ensuring that all school‑issued hardware—whether used in classrooms or taken home—receives consistent web‑filtering and malware‑scanning protections. Classroom‑specific tools provide real‑time monitoring of application usage, while app controls enforce whitelisting and blacklisting policies to prevent unauthorized software execution. Finally, continuous cyber monitoring aggregates logs and alerts, enabling rapid response to anomalous activity.
Protection Extends Beyond School Premises
A critical component of Calvert’s approach is the extension of safeguards beyond the physical school boundary. Poteet noted that devices deployed for student use in classrooms carry the same protective profiles when students take them home. This uniformity ensures that off‑campus internet activity remains subject to the same filtering, monitoring, and policy controls, thereby reducing the risk of exposure to harmful content or malicious actors. By maintaining a consistent security posture across environments, the district aims to create a seamless safety net that follows students wherever they learn.
Evolution Since COVID‑19
Reflecting on progress made since the onset of the pandemic, Poteet presented an illustration showing how the district’s cybersecurity measures have advanced. He highlighted improvements in endpoint protection, expanded use of cloud‑based security services, and refined incident‑response playbooks that were rapidly adapted during the shift to remote learning. School board member Melissa Goshorn acknowledged this growth, stating, “I know how far you guys have come from since COVID,” and expressed appreciation for the district’s forward‑looking posture. The evolution reflects both lessons learned during the crisis and sustained investment in resilient infrastructure.
Parental Control App Qustodio Integration
One notable enhancement discussed was the integration of the parental‑control application Qustodio into the district’s cybersecurity arsenal. Goshorn, who has used the app personally for years, remarked that while it is “imperfect,” its adoption in Calvert will “put parents in the driver’s seat.” The app provides families with visibility into device usage, screen‑time management, and content filtering, complementing the school’s technical controls. By empowering parents to monitor and guide their children’s digital habits, the district aims to foster a collaborative approach to online safety that extends oversight beyond school hours.
Application Lifecycle Management
In response to a query from board member Lisa Grenis about software hygiene, Poteet confirmed that the IT department conducts an annual review of all applications deployed across the district. This review identifies outdated, redundant, or underutilized programs that are then retired or replaced, reducing the attack surface and simplifying maintenance. Regular pruning of the software portfolio not only enhances security but also ensures that limited budgetary resources are directed toward tools that deliver measurable educational and protective value.
IT Budget Overview
Supporting these initiatives, the district’s information technology operation is funded by an approximate annual budget of $3 million, as reported on the school system’s website. This allocation covers personnel salaries, hardware refreshes, software licenses, cybersecurity services, and ongoing training for staff. Poteet indicated that the budget is strategically aligned with the layered defense model, ensuring sufficient resources for both preventive measures and incident‑response capabilities.
Pending Cellphone‑Use Policy
Shifting focus to device policy, Sabrina Bergen, director of student services, presented a pending policy governing students’ personal cellphone use in schools. The proposed measure is designed to comply with Maryland’s Joanne C. Benson Phone‑Free Schools Act, which mandates that all public school systems implement phone‑free environments by 2027. Currently, Calvert maintains a limited cellphone‑use procedure that permits high‑school students to use their devices during lunch. Bergen explained that the most significant change would be to remove this allowance, creating a consistent expectation across elementary, middle, and high school levels that personal cellphones remain unused throughout the school day.
Board Feedback and Next Steps
Board members engaged actively with the proposal. Paul Harrison suggested that, for consistency, the new policy should also apply during bus travel, extending the phone‑free environment to transportation periods. Melissa Goshorn inquired whether other Maryland districts had already adopted similar policies; Bergen responded that she was not aware of any comparable implementations at this time. The policy is presently undergoing public review, allowing parents, teachers, and community members to submit feedback before the board votes on final adoption. This inclusive step underscores the district’s commitment to transparent policymaking and community partnership in shaping safe digital practices.