State audit red flags Millbrook Central School District’s IT Dept.

MILLBROOK — The Millbrook Central School District (MCSD) was called out by the New York State Comptroller’s Office during a recent audit for several red flags found during the review. It was the result of  an Information Technology (IT) audit released on Aug. 20; the objective was to determine if officials at the MCSD established adequate controls over user accounts in order to prevent unauthorized access, use and loss. 

According to Comptroller Thomas DiNapoli, they did not have adequate controls over user accounts, did not prevent unauthorized access, use or loss and did not periodically review and disable unneeded network user accounts. Additionally, the audit found that the MCSD did not develop a breach notification policy as mandated by New York State law. 

“When we heard they were going to audit us, we looked at it as a good thing,” said President of the Millbrook Board of Education (BOE) Perry Hartswick. “With so many technical challenges from COVID, any extra eyes were a good thing. What they found were important issues, but simple.”

The audit, which was conducted from July 1, 2019 through Nov. 8, 2020, showed the accounts of 46 students no longer enrolled in the district were active, as were the accounts of 13 employees who left their jobs and did not have their accounts disabled from the years 2013-2018. Nine generic accounts were also not disabled for the years 2015-2018.

According to the review, “the user accounts provided access to the district’s network and should have been actively managed to minimize the risk of misuse.” If not, it warned, those accounts could be “potential entry points for attackers to inappropriately access and view Personal, Private or Sensitive Information (PPSI) on the network.” 

The state also advised that districts should have “written procedures in place for granting, changing and revoking user permissions to the network; also, to minimize the risk of unauthorized access, district officials should regularly review enabled network user accounts to ensure they are still needed. Officials must disable unnecessary or unneeded accounts promptly, including user accounts of former employees.”

Recommendations made were for the district “to develop written procedures to manage system access, which will include a periodic review of user access and disabling user accounts when access is no longer needed.” DiNapoli also recommended the development of a breach notification policy.

The MCSD serves not only the village of Millbrook, but the towns of Washington, Union Vale, Clinton, LaGrange, Stanford and Pleasant Valley. Its Board of Education has seven elected board members. 

Superintendent of Schools Laura Mitchell, who began her position in January 2020, did not return multiple requests for an interview but did respond to the audit report on the district’s website, www.millbrookcsd.org. 

“The district is in agreement with these recommendations and is in the process of developing policies and procedures accordingly,” stated Mitchell. “Specifically, the district has already implemented a protocol for regular verification of student enrollment for the specific purposes of maintaining, creating or deactivating students accounts.” 

The district has 944 students and 350 employees, with network user accounts totaling 1,325.

“A parallel process is being developed for staff accounts,” added the superintendent. “The district will also continue working with our local BOCES and cyber security support partners to create an appropriate breach notification policy.”

Some residents took to Facebook to comment on the report, in less than flattering terms. 

“They keep getting money given to that department and the meetings are harder to watch now than when they were on Zoom. The camera and microphone that they have implemented is terrible.” 

Another comment simply said the report was “shocking.”

The MCSD has touted its technology department throughout the years, starting in 2004 through 2007 and again from 2016 through 2019. In April 2020, Elliott Garcia was hired as director of Technology and Data Services. 

Since then the district said it has been making great strides to update both its equipment and its IT practices to protect student and staff accounts. 

Hartswick said that since Garcia was hired he has “devised a plan and executed it, resolving the issues pointed out” in the state audit.

Latest News

Habitat for Humanity brings home-buying pilot to Town of North East

NORTH EAST — Habitat for Humanity of Dutchess County will conduct a presentation on Thursday, May 9 on buying a three-bedroom affordable home to be built in the Town of North East.

The presentation will be held at the NorthEast-Millerton Library Annex at 5:30 p.m.

Keep ReadingShow less
The artist called ransome

‘Migration Collage' by ransome

Alexander Wilburn

If you claim a single sobriquet as your artistic moniker, you’re already in a club with some big names, from Zendaya to Beyoncé to the mysterious Banksy. At Geary, the contemporary art gallery in Millerton founded by New Yorkers Jack Geary and Dolly Bross Geary, a new installation and painting exhibition titled “The Bitter and the Sweet” showcases the work of the artist known only as ransome — all lowercase, like the nom de plume of the late Black American social critic bell hooks.

Currently based in Rhinebeck, N.Y., ransome’s work looks farther South and farther back — to The Great Migration, when Jim Crow laws, racial segregation, and the public violence of lynching paved the way for over six million Black Americans to seek haven in northern cities, particularly New York urban areas, like Brooklyn and Baltimore. The Great Migration took place from the turn of the 20th century up through the 1970s, and ransome’s own life is a reflection of the final wave — born in North Carolina, he found a new home in his youth in New Jersey.

Keep ReadingShow less
Four Brothers ready for summer season

Hospitality, ease of living and just plain fun are rolled into one for those who are intrigued by the leisure-time Caravana experience at the family-owned Four Brothers Drive-in in Amenia. Tom Stefanopoulos, pictured above, highlights fun possibilities offered by Hotel Caravana.

Leila Hawken

The month-long process of unwrapping and preparing the various features at the Four Brothers Drive-In is nearing completion, and the imaginative recreational destination will be ready to open for the season on Friday, May 10.

The drive-in theater is already open, as is the Snack Shack, and the rest of the recreational features are activating one by one, soon to be offering maximum fun for the whole family.

Keep ReadingShow less
Sun all day, Rain all night. A short guide to happiness and saving money, and something to eat, too.
Pamela Osborne

If you’ve been thinking that you have a constitutional right to happiness, you would be wrong about that. All the Constitution says is that if you are alive and free (and that is apparently enough for many, or no one would be crossing our borders), you do also have a right to take a shot at finding happiness. The actual pursuit of that is up to you, though.

But how do you get there? On a less elevated platform than that provided by the founding fathers I read, years ago, an interview with Mary Kay Ash, the founder of Mary Kay Cosmetics. Her company, based on Avon and Tupperware models, was very successful. But to be happy, she offered,, you need three things: 1) someone to love; 2) work you enjoy; and 3) something to look forward to.

Keep ReadingShow less