HOLYOKE — Days after a cybersecurity breach caused Springfield Public Schools to shut down the week after Labor Day, Holyoke Mayor Joshua Garcia announced that the city has secured cyber liability insurance.
Garcia said in a statement on Facebook that, effective Sept. 11, the city and Holyoke Public Schools have secured the insurance coverage through the city’s insurance program.
“Recent events involving Springfield Public Schools are an important reminder that cybersecurity is a serious issue for every city and school district,” Garcia said. “I want our residents to know that Holyoke is taking steps to protect our city, our schools, our employees, our students and the information entrusted to us.”
The cyber incident in Springfield, which first caught the city’s attention on Sept. 1, was determined to be a level four threat. School personnel in Springfield have been locked out of access to third-party platforms and vendors, including the medical information system, transportation and food services.
The insurance policy in Holyoke provides an additional layer of financial and operational protection should the city or school district experience a cyber incident.
Garcia explained that insurance is only part of the solution and Holyoke has also strengthened its technology and cybersecurity systems over the years — including expanding multi-factor authentication — upgrading outdated servers and technology, strengthening firewalls and other network protections, and improving security for public-facing websites and systems.
Holyoke has also been strengthening access controls, identifying and addressing older technology that may create security risks, and improving monitoring, backups and its ability to respond to a cyber incident, according to Garcia.
Garcia said this is not a permanent solution, but it better prepares the city for any possible threat.
“It’s important to note that no system can completely eliminate the risk of a cyberattack. That is why cybersecurity requires ongoing attention and investment,” Garcia said. “We will continue to assess our risks and make the investments necessary to keep our city and schools safe and resilient.”
In a statement to Reminder Publishing, Holyoke Public Schools Superintendent Jackie Glasheen said the city’s decision to make this investment in support of cybersecurity.
“Such insurance could be immensely helpful in the event of a data breach,” Glasheen stated. “While at this time law enforcement has not determined what caused the situation in Springfield, we want to remind our community that there are important steps everyone can take to help prevent some security breaches from ever happening. Please be extra vigilant when reviewing emails, links, attachments and requests for information. Cybersecurity is everyone’s responsibility, and one click can put an entire organization at risk.”
She explained that if you receive an email you were not expecting, even if it initially appears to come from a legitimate source, do not click a link, open an attachment, scan a QR code, enter a password or respond with information until you have confirmed that the message is legitimate.
Glasheen listed actions people should take if they receive something suspicious:
•Check the sender’s actual email address, not just the display name.
•Be suspicious of urgent requests, “bonus” letters, password resets, shared documents, or calendar invites from unknown senders.
•Do not approve a login or two-step verification prompt you did not initiate.
•When in doubt, contact the sender another way or submit a helpdesk ticket if that is an option.
•Use the “Report phishing” option in your email provider if a message appears suspicious.


