Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

From Biology Teacher to K-12 CTO: Amanda Lanicek

PDQ
07/10/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


with sysadmins from various different industries and different stages of their IT career. Today, we have a very special guest, Amanda Lanacek, CTO of Springtown Independent School District, managing over 5,000 devices. Amanda, welcome to the show. How are you? I'm great. Thanks for having me, Brock. Absolutely. Thank you. This is episode number two. So, I mean, you're right up there at the beginning of this whole series. That's a pretty special place to be, I feel like. I feel pretty special. Now, to get started, I think there's some news that we actually want to break, because you've kind of already spilled the beans over on LinkedIn, and you've shared it with some people, but you're actually joining the PDQ team. Is that right? I am, and I am super excited about it. Okay. Now, what... I got to understand the decision-making process here, because you've been in education for a long time, and you decided to jump over to PDQ. What was that process like, going through your head? I saw your post on LinkedIn about a technical brand manager position, and I was like, oh my goodness, this looks like something that I might be interested in. I never thought I would leave education. I thought I would live and die here, and it would be my life. But I think an opportunity to help people on a bigger platform and a bigger scale is really up my alley, and I look forward to it. My heart is in education, and I love helping people, and I think that PDQ, that is really at the heart of y'all's mission, is helping people to make sure that their stuff is up to date, and their vulnerabilities are secure. I am just super excited to be a part of that. We are super excited to have you join the team. Obviously, that's one of the reasons that I'm actually with PDQ as well, is they give us a lot of freedom to just put out resources to help people. Obviously, they have a product and a tool for system administrators, and we just try to make the best product possible, but they give us a lot of opportunities to work with customers, and community members, and just folks in the IT industry, and help them along their way. So anybody's always welcome to join our Reddit, our subreddit, our Discord server, ask general IT questions. We're always there to lend a helping hand. So anyways, let's dive into some of these questions. Now, the first one, walk me through your career journey, because I'm curious, was CTO always on your radar in education? No. So I started as a teacher, and ironically, I never thought that I would be a teacher. So I have a bachelor's in psychology, and I had done an internship at a high school as a school counselor, and then didn't have a job, because a bachelor's in psychology you really can't get very far with, and they called and they said, hey, would you be interested in teaching science? And prior to majoring in psychology, I was a biology major, and so I had enough credit hours, and I became a biology, and anatomy, and physiology, and chemistry teacher. And so I taught high school for five years, starting when I was 22. So that was weird, because some of my students were 18, 19, and I was 22, which you can only imagine caused all kinds of issues, because on their end, not mine, obviously, but it was a fun time. And then I moved to teaching third grade, and I taught elementary for five years, and through that became teacher of the year, had a lot of really cool experiences, and got my master's during that time in educational technology leadership. And from there, I went to be a digital learning coach, and then a digital learning director, and while I was a digital learning director, it was right after COVID, and school shutdowns, and everything. And the current CTO began looking at what his retirement could look like, and he was in Springtown ISD for 26 years, did a phenomenal job. And I took his job when he left, and my superintendent entrusted me with knowing what to do, and it was a wild time. That's great. I mean, what a journey. I feel like, you know, there's the people that know that IT is in their blood. That's where they go, they do the computer science route, they do the help desk route, and then they progress their career from there. And then there's people like you and I, like I didn't plan on being in IT, but an opportunity presented itself, and sure enough, I joined the Rinks, and was there for 15 years as a system administrator and education and financial. But it's a good career to be in, right? Even if you fall there by accident. Right. Yeah, it is. And I think that it brings a different perspective, you know, when we all come from different, you know, places. So what advice would you give someone maybe just starting this journey, and maybe they're even eyeing like CTO in education, or just those upper management positions in like IT, what would you give someone just starting out in their career on how to kind of achieve that success and kind of obtain that role that they're looking for? Yeah, so right now, I think more than ever, cybersecurity is, it's huge, right? You know, before it was just kind of something that we did, but now it's everyone needs to be involved in it. So I would if I were looking to move into a role, I would start looking at, you know, certain cybersecurity assessments that I could get my hands on and kind of grade whatever I'm looking at on that assessment. So if I'm in a K-12 role, and I'm looking at a school district, then take an assessment as that school district leader and learn what things need to be in place. And then look at district goals or company goals and how that aligns with technology. I think it's really important that we're looking at, you know, organizations goals, and then aligning our technology to those goals. Yeah, I feel like a lot of IT guys, or a lot of IT people, I should say, they focus on just the problems in front of them, instead of the business side and the business problems, right? That's just who we are is like, oh, hey, somebody comes to us for technical problems, and we resolve those issues instead of like, hey, let me look at the goals and the issues that maybe we're having as a school district or as a company, and how can I build technology to support those goals and those issues? Yeah, I think that, you know, it's very easy to get siloed. And, you know, five years ago, 10 years ago, in education, we were very siloed. But now, you know, things are happening, and more things are online. So technology or the tech director or CTO has their hands in more things than before. And so it's not siloed anymore. I think one of the most important things we did as a district was started implementing tabletop exercises. And then you find out like, oh, who's gonna call the Texas Cyber Command or the FBI if we have a cyber breach? Oh, you know, Amanda can't do it all. Who's gonna call our banks? Who's gonna do all this? And so I think that tabletop exercises are phenomenal, and everyone should do them. Oh, great answer. Great answer. Now, being IT in education, I feel like it carries certain connotations, you know, maybe some budget constraints and resource limitations and stuff. So if you could snap your fingers and fix one problem in IT, specifically in like the education side of things, what would you fix? Oh, like if it wasn't budget, budget, obviously, but if it wasn't budget, it would be the vendor procurement cycle. I think that oftentimes, that departments are siloed. And so you have your curriculum department or your business department that they want to go into an agreement with a specific vendor that needs access to your student information system, your business system, whatever it may be. And they're like, oh, yeah, we can give you API access, we can give you LTI access, whatever it might be. And they don't understand that process or the risks that come with that. So ideally, there would be like a mandated vendor procurement process that had all those cyber security things in it. That is one thing I definitely would love to see. I think a lot of people would agree with you there. If you are, if you're kind of in that same pain point, definitely go and follow Amanda on LinkedIn. Lots of helpful advice on there on LinkedIn. So thank you for providing those insights. Now, what's the craziest user request or IT ticket that maybe you've ever received or dealt with? So there, you know, I love to on LinkedIn put ticket stories, because there's some that are just so funny. Like, the other day, someone said that their keyboard was not was frozen, keyboard was frozen. And really, it was a battery operated keyboard and the batteries were dead in it. I was like, the keyboard's dead, frozen. I thought that was hilarious. But I once had someone put in a ticket for me or for me or my team to come set up their home Wi Fi router. They had just got Fiverr to their house and wanted us to come set up their home router. I'm like, Well, I'm glad you have faith in us. But that is definitely not our job. Please contact your ISP. But yeah, there's just there's funny things and I get it. Like before I was in this role, I probably put in some really funny tickets to that. It wasn't even like work related. Was it like, Oh, hey, I'm doing a lot of like work at home meetings? No, no, not work related at all. Yeah, just needed internet at their house. And so they asked the people that get the internet, you know? Yeah, no, I mean, I definitely as soon as I started in it, I started getting a lot of like at home requests, you know, and thankfully, I don't know if I ever had anyone put in a ticket for an at home request like that. But they would, they would come up to me and you know, personally asked like, Oh, hey, can you come and fix this? And I had said yes to a few of them. But I got to a point where I had to draw like a hard boundary line and just like, sorry, like, you know, I want to be nice about it. But it's like, I set this this boundary line for myself. And I just I don't cross it. Yeah. And that's, that's one thing like I want to help and I would love to go set up someone's home internet. But then there's just liability and all kinds of things that sometimes you just don't want to get yourself mixed up in. Yeah, 100%. Now, how long have you been because you are a customer of PDQ. You're using PDQ Connect. Is that right? Yes, I absolutely love PDQ Connect. How long have you been using PDQ? So we were PDQ deploying inventory before I took this position. So probably about five to seven years we've been using PDQ. We had smart deploy at one time and then we moved to PDQ Connect last year and I absolutely love it. So how did you first discover I guess maybe this maybe we won't know the answer to this question. But how did you first come across PDQ? So when I transitioned into this role, I was taught deploy and inventory and that's how we update our computers. And so I didn't know beyond just updating computers and patch management what PDQ could do and learned very quickly that it is a big resource. Yeah. So you kind of adopted it more than anything. Yes. Gotcha. OK. And when you first started using it, were you like, hey, this is a godsend or is it kind of like, OK, let's maybe look at some other products and maybe that's how you found PDQ Connect? No. So we were using deploy and inventory and things were going fine, you know, but I believe I don't honestly remember. I remember talking to someone about PDQ Connect. So I don't know if I got an email about it or if it was our rep, but did a demo and I was like, I have to have this. And I believe we might have piloted it. And I was like, I can't live without it. The vulnerability piece of PDQ Connect is phenomenal and it has made my life a hundred times easier because I don't have to go and match vulnerabilities to softwares or different things on devices. I can easily see which device has what vulnerability and I'm able to set up groups within PDQ Connect so that each of our campuses have a group and my technicians have access to the group that they're responsible for and they can go and remedy those vulnerabilities. So it has made the process and my time so much better. So is it safe to say that PDQ Connect has kind of freed up some of your team's time to maybe focus on other priorities? One hundred percent. That's good to hear. I mean, I think that's what we're always going for, right? Is our motto is simple, secure and pretty damn quick. And that, you know, when I was a system administrator for higher ed, you know, it was the same thing. It was like it was it was two of us, very limited resources, and PDQ Connect was the only thing keeping us afloat. Actually, not sorry, not Connect, D&I at the time. This is before Connect had come out. But deploy and inventory were the only thing keeping us afloat, keeping us patched and everything. But now with the vulnerability and scanner inside of PDQ Connect, being able to just not only see and prioritize, but remediate and automate those remediations with just a couple of clicks is incredibly valuable. Yes, I absolutely love it. I obsess over that vulnerability scan. OK, there's a perception that IT in education means constant resource constraints and doing more with less. Has that been your experience so far? So yes and no. Yes, it is, because you think about education, our our main focus is students and student success. And I think that as an IT leader in education, if you can't justify how what you're doing or what you would like to budget for, how it impacts student success, it makes it really hard. But if you can and you come with a good plan and you plan out, you know, I'm going to do this, we're going to change these devices, whatever it is, and this is why we're protecting student data, it will contribute to student success. And what that looks like in the classroom, it's not as hard. The constraints aren't there. So I think coming with a solid plan, you have a better foot in the door. Now, that ties into this next question, because IT is often considered a cost center, which can make negotiating those budgets pretty difficult because you've got to provide the value. Right. So what has helped you convince leadership to prioritize things like infrastructure and security when it comes to budgeting? So we did a cybersecurity assessment when I took over as CTO and it was very scary. And that really pivoted everything for us budget wise from a financial standpoint. Our CFO and our superintendent were like, how can we make this score better? So it's terrible to say, but I think anything that you can put a number to and say, hey, we're at this out of five or we're at this out of 10, that's going to people want to be better. Right. They want to be that five or that 10. And how did they get there? And so that was a huge, huge pivot for us. Yeah, that's a that's a great point. And it's definitely it's a skill to be able to kind of tie those pieces together and get in another company to come in and evaluate you and kind of like develop that risk score for you. I mean, that's a really good idea to say, hey, like things could get scary really fast, you know, unless we increase the budget and bring in the certain the certain infrastructure or these certain platforms that can help us, you know, be more secure. Yeah. And I think now, like we have so many incidents in K-12 that you can easily take those incidents and say, hey, do we want to be do we want to be involved in this? Like what risk are you willing to take? Right. Unfortunately, there's a lot of examples out there that can paint a pretty, you know, bad picture that you'd want to avoid. So. All right. So CTO, let's talk about that for a second, because that's a pretty broad title with a potentially broad set of responsibilities. So does most of your time get taken up with things like meetings and project planning? Or do you find yourself still getting your hands dirty and directly dealing with users and like managing systems? Yeah. So I luckily am fortunate enough that I still deal with users and systems. That's always a question I have is you're the CTO. Why? Why are you responding to help desk tickets? And depending on the size of the district, we're a district that serves forty two hundred students and six hundred and fifty employees. And we have seven campuses. So only I have five technicians, one that is a network specialist, a help desk coordinator, and then three repair technicians. And they were all repair technicians. But I have really tried to find some of their strengths and coach them up into roles that will take take it off my plate is really what it is. And so I do I deal with a lot. I am constantly in meetings about things. But then I'm also provisioning users or making sure that our identity automation is working correctly. I'm in PDQ looking at how many vulnerabilities we have and and making sure that those are patched or setting up software things. So there's a lot of things that I do as a CTO that a CTO in a district of twenty five or fifty thousand may not be doing. Yeah. Four thousand something students. Is that what you said? Yeah. Forty two hundred. Forty two hundred students. And you said five thousand devices, right? Yeah. Now, are we talking about like all devices, network gear, Chromebooks? No. Yeah, those are just like we have. Honestly, we have a little more than five thousand devices. We have about six thousand Chromebooks, but we say about forty five hundred in use because we have some that are for testing and loaners and things like that. And then we have about four hundred Windows devices and then about 60 Mac or Apple devices. And then if you look at everything else, we have about twelve thousand endpoints when you look at all of our network gear, too. So access points, switches, servers, TVs, you know, any we have interactive flat panels and things like that. So I get to manage all of that. That is that is a lot to manage. Yeah. And I definitely feel like coming from education, a lot of people obviously use Chromebooks. They're cheap. They get the job done, I feel like. But Google has said that it's going to introduce a new premium device called Google Book, which maybe you've heard of or not, but some are considering that as the replacement for Chromebooks. I've seen some schools actually considering the switch to the new Apple Neo device. Do you think your district will switch devices from Chromebooks for the primary student usage anytime soon? I don't think so. So the the cost is very equitable right now between that Neo and a Chromebook. But Chromebooks are so easy to manage and they're literally just a Internet browser. So when you put them in, you think about these kids, especially our high school kids. They are like little hacktivists, you know, they're just trying to hack whatever they can. So I think the more you limit what they have, the better, as long as it does the job for what they need instructionally. So we have Chromebooks in all kids hands, but then there are specific classes like our AV class or a cyber computer science class that have Windows devices or Mac devices dependent on what they need. But in my experience, Mac is not as easy to manage on the student side as Google is. Google has a great interface for K-12 and Mac just doesn't. However, our whole executive leadership team is on MacBooks, but then we have Windows PCs in our office. So I think we'll see a little bit of a shift, but I don't think there will be a huge shift. I'm interested in the Google book or whatever. I've already forgot what it's called, but I'm interested to see how it's different than the Chromebook Pro because the Chromebooks our teachers have. So all our teachers are on Chromebooks, too. There are Chromebook Plus. There are the Chromebook Pluses. And so they have a bigger processor and more storage and all that. So I'm interested to see how those are different. Gotcha. Now, with the Google book, I think they said that they were kind of taking an AI first approach, which ties into my next question, which we don't know how, you know, they haven't shown off that much with the Google book yet, but they do seem like they're diving heavily into it, into the AI side of things. So I was curious, AI is obviously impacting like everything these days. How do you see, where do you see AI having the biggest impact in education right now? So I think that honestly, like people in education have jumped into we got to get all these AI tools and in teachers hands. And I don't necessarily think that that's what's best for student learning and student outcomes. However, our kids do know or do need to be AI literate and they do need to know how to use generative AI and things like that. And so I think that, you know, high school and up, you're teaching AI literacy and things like that. I don't think like, for instance, I have just turned six year old on Monday. I don't think he needs to know much about how to use AI, but maybe he does need to know how to spot things that were created with AI and how to look for authentic pieces. So I think teaching AI literacy, you know, pre-K-12 may look different. It may be hands on more in the older students and more instructional and teaching them how how to spot things and more of a cybersecurity standpoint for the youngers. Yeah, I've seen, I have two kids, one of them literally just graduated high school last week. Thank you. And then and then I have my daughter's going to be a sophomore this coming school year. And I've definitely seen her utilize like AI and stuff, which I was kind of like, I don't know how I feel about it. Right. At the same time that I recently saw a post about a school textbook that had been uploaded and there were still APT prompts in the book. And I was like, OK, well, if the teachers are using it, I guess it's fair game if the you know, the students use that. Well, that's one thing like our teachers are definitely using. I always like to look on our NDR and see like how many people are going to chat GPT or we're a Google district. So Google Gemini is open for teachers and then for specific groups of students. So like high school, we have a second grade class that uses Gemini and their teachers phenomenal and does really cool things. But I think first, teachers have to know how to use AI and they have to know that it's not always correct and that it's biased and that AI is more than just a chat bot. Right. So a lot of times they just think of generative AI as what AI is. And so I think that there's a big professional development opportunity to teaching adults about AI before they're teaching kids or utilizing with kids. Yeah. I mean, it's similar to, you know, when I was in school and computers were becoming a thing and Google was coming out and all of a sudden it was like everybody was using Google to find answers and create book reports and things like that. And this is just kind of the next evolution of it for this newer age of students. But it'll be interesting to see what kind of impact. Hopefully it's a positive impact and not a negative impact on the learning of our children and stuff. But yeah, I hope so, too. It'll be very interesting and I think it'll be interesting because hopefully schools are thinking about data security and what they're putting into these chat bots, where it's going and things like that. Right. Because, yeah, we are seeing a lot of security news and stuff around data that people are putting into chat bots that maybe their IT isn't managing and stuff. And so it's just easily getting out there into the void. And then it's pretty much impossible to pull back. But something else that came up in the news recently, which I know impacted you, was a recent Canvas breach that impacted a ton of people, a lot of schools, right around finals week, which was, you know, had to be intentional. So what was your experience like when that went down? So I learned about it from LinkedIn and came to find out, like I immediately sent our customer success manager from Instructure, like why was I not notified? Well, they had the wrong email in their system. And I'm like, shouldn't that be something I'll check quarterly? Like this should be a process you have to make sure you have the right stuff. But learned about it on LinkedIn, immediately contacted. It's not where you want to learn. Right. And thank God I'm on LinkedIn. Right. But immediately contacted our executive leadership team. We took action and disconnected the API from our student information system and then disconnected all LTI connections and our, you know, SAML, Google, everything. All connections were disconnected. We sent out communication to parents and staff and students, letting them know that there was a breach. We don't know if we're a part of it, but we took these proactive measures and that we would update them as it went. Before we sent communication, we came together as a team and decided like we're going to follow our incident response plan. We need, you know, if they can't use Canvas, what can they use? And so we made sure that we prepared some materials for Google Classroom and allowed our staff to get into Google Classroom. But then, like you said, it was finals week. So we learned very quickly. A lot of them had their finals in Canvas and nowhere else. They had no other documentation. So once Canvas said we're good, which doesn't mean they're good, you know, because a company says they're good doesn't mean they're good. But we went ahead and gave our staff access back. And with the understanding that you're going to have access back, but this platform has been breached, it could still have the bad actors could still have access. So you are taking the risk of using this to get your materials out. And we gave them three days to do that. And then we shut it back off. And we're waiting for the FBI clearance of the incident. I actually got two emails from Instructure yesterday saying all's good. You know, like they continue to send things that everything is good. But I'm of the belief you don't you don't believe them. You believe the people that have the resources to really make sure that all is good. And, you know, they paid a ransom. And so who knows that I don't think that the bad actors erase the data and all that. But I do think that Instructure will be better because of this. You know, they're probably really hardening their systems. And they learned that their communication was awful during it to everyone. And, you know, it didn't just happen once. It happened twice. And so when they said, oh, it's good in the beginning of the week and then that Thursday, it happened again. I think that they really realized, like, we've got some work to do and hopefully they're a better company because of that. For sure. And, you know, it really it's unfortunate that sometimes it has to resort to an incident like this for someone to take all of a sudden their security very, very seriously. Right. And, you know, and you can do you can spend all the money, do all the things, check all the boxes, you know. And sometimes it still comes down to a user maybe doing something they shouldn't have done. So, you know, definitely not wanting to, like, criticize or anything like that. But it is good to hear that they are taking additional measures to try to, you know, beef up their security, ensure this doesn't happen again. But it is an interesting question, one that we talked about recently on the webcast, because while I don't think that they actually said, hey, we paid a ransom, they did say they came to some sort of agreement. So very carefully worded there, which I assume most people thinks that, you know, they paid some kind of ransom. So how do you I was curious about your opinion on this. How do you feel about a company paying or coming to some sort of agreement with, you know, an organization like Shiny Hunters or other bad actors? How do you feel about them paying that ransom? Do you think, OK, it was their responsibility, they should do it to try to keep that information safe or should you just never give in, never pay, you know, an extortionist money? So I personally I've never been in that situation. So maybe if I was in the situation, I'd feel different. But I personally think you don't pay the extortionist money. Right. I love Darknet Diaries. And so I you know, I love listening to all of his craziness and cybercrime stuff. So I always listen, you know, to the ransomware people. And that that's their their whole crime is to extort people. Well, they already have the data. And so if you pay them and they say we've destroyed it, how do you know 100 percent that they did? Right. And a lot of people said that in this case, the data was already on the dark web and then pulled off. And again, like it's it's all hearsay of what actually happened. But I don't think you can ever trust a criminal. So I think you should spend your money being proactive about the incident. So if that's providing, you know, some identity coverage for the users that were that were hacked, if it's providing those schools like an instructor's case instead of paying millions or whatever it might have been providing those schools phishing protection or something more proactive, then here I'm going to pay you. And I don't really know if I'm going to get what you're saying I'm going to get out of it. Yeah. Now, how does this experience change the way that you look at vendors and services going forward? Because this can obviously you know, this is a pretty traumatic experience. And anyone that's been involved in like a supply chain attack of this nature, it can really change the way you look at your vendors and how you do your shopping and, you know, where you put your priorities. Yeah. So prior to the instructor incident, we had put in place DPAs and data privacy agreements with vendors and things like that. But I think that this really opened not only my eyes, but our whole leadership team's eyes to like those DPAs or paper. Right. So even though instructor has a data privacy agreement with a district doesn't mean that when they're hacked that anything's going to happen. Right. They're saying we're going to keep your data private, but they're hacked. It's out there. Now what? And so it's really helped us put in in place some really specific things that we expect from vendors. So we use a program called ClassLink to roster all of our different resources through. And that's one thing like they have to roster with ClassLink. They have to be open to DataGuard, which is a piece of ClassLink where we can kind of mask some of our data that they don't need. We will no longer do APIs to our sys that are just open APIs, you know, for here it is. Here's all the information not happening. So we are being very specific with what data we'll give them. And if they don't roster a ClassLink, it has to be through a secure SFTP and specific data fields, you know, that we can also mask there as well. So I think that it has helped from my perspective. It's helped others that aren't in my department realize how impactful a breach could be. Yeah. No, that's some really, really good advice for anyone that is kind of like shopping around for products, services, you know, take those things into consideration. It's not just like, hey, who's got the shiniest buttons, who needs my budget and stuff like that. There's a lot of other considerations to be thinking about during that process. And that's the thing, like right now with education is TikTok and teachers watch TikTok and they see all these things like going back to AI. They see all these crazy AI tools they want to use. And it's like, yeah, but just because you saw it on TikTok doesn't mean it's best for you. It's best for kids or best for data security. So it is definitely a great educating opportunity. For sure. Oh, man. I'm I just can't think of I'm I'm glad I never experienced a user come to me requesting a tool because they found it on TikTok. Oh, it's always like always. I saw this on TikTok. Can you allow access? I'm like, my goodness. All right. I'm banning TikTok. Exactly. Right. I'm like, it's actually on our like in Texas. It's on our governor's ban. So I'm like, hope you're not using your school account for that because the governor banned it. Yeah. Thank you for chatting with us today. Thank you for sharing your experience with that that Canvas breach. I know that again, finals week, definitely on purpose there because they knew it would cause the most panic and concern. And that's that's really frustrating, especially for you and teachers out there who are just trying to to do their jobs. Right. And to provide an education for students and wrap them up as they're all excited to go on summer break and stuff. Yes. So anyways, thank you for coming. Thank you for sharing your experience. I think a lot of people are going to get a lot of good information from your insights as a CTO in education. Kind of like paint that picture because, again, CTO can kind of mean a lot of things for a lot of different people. So I really appreciate that. Yeah, absolutely. Well, thanks for having me. OK, everybody. Thanks for watching PDQ Patch Notes. Catch us in the next episode. Thanks.

TL;DR

  • Amanda Lanicek went from biology teacher to K-12 CTO through a series of unplanned career pivots, ultimately managing 12,000 endpoints at Springtown ISD with a five-person team.
  • PDQ Connect's vulnerability scanning and campus-level grouping has significantly reduced manual remediation work, freeing the team to focus on higher-priority security tasks.
  • A third-party cybersecurity assessment early in Amanda's tenure was the key lever for unlocking budget support from district leadership by putting a quantified risk score in front of administrators.
  • The Canvas breach during finals week prompted Springtown ISD to overhaul vendor data-sharing practices, requiring ClassLink rostering, DataGuard masking, and eliminating open API access to student systems.
  • Amanda advocates for AI literacy over AI tool adoption in K-12, stressing that teachers must understand AI's limitations and security risks before deploying it with students.

From Classroom to CTO: An Unconventional IT Career Path

Amanda Lanicek, CTO of Springtown Independent School District in Texas, traces a career path that began in biology and psychology, moved through high school and elementary teaching, and eventually landed in educational technology leadership. After earning a master's degree in educational technology leadership and serving as a digital learning coach and director, she stepped into the CTO role when her predecessor retired after 26 years. Her story illustrates how non-traditional backgrounds can bring valuable perspective to IT leadership — particularly the ability to connect technology decisions to organizational goals like student success. She also announces in this episode that she is joining PDQ as a technical brand manager, citing the company's mission of helping IT professionals as a natural extension of her own values.

Managing 12,000 Endpoints on a K-12 Budget

Springtown ISD operates roughly 6,000 Chromebooks, 400 Windows devices, and 60 Apple devices for students and staff, with total endpoint count reaching approximately 12,000 when network gear, access points, switches, servers, and interactive flat panels are included — all managed by a team of five technicians. Amanda explains how she uses PDQ Connect's vulnerability scanning and campus-level grouping to let individual technicians own remediation for their assigned campuses, dramatically reducing the time spent manually matching vulnerabilities to devices. She credits a third-party cybersecurity assessment taken early in her tenure with unlocking budget support from district leadership, noting that quantified risk scores gave administrators a concrete target to improve. On device strategy, she sees Chromebooks remaining dominant for students due to their simplicity and manageability, while Windows and Mac devices serve specialized classes and staff.

AI in Education and Lessons from the Canvas Breach

Amanda offers a measured take on AI adoption in K-12, arguing that the priority should be AI literacy — teaching students and teachers to understand AI's limitations, biases, and security implications — rather than rushing to deploy AI tools in every classroom. She monitors teacher usage of tools like Google Gemini through her network detection and response platform and emphasizes that professional development for educators must precede student-facing AI deployment. The conversation turns to the Canvas (Instructure) security breach, which hit during finals week. Amanda describes her district's incident response: disconnecting all API, LTI, and SAML integrations, communicating proactively with parents and staff, and following a documented incident response plan. She expresses skepticism about Instructure's ransom payment — believed to have been made to the Shiny Hunters group — and argues that proactive spending on identity protection and phishing defenses would have been a better use of those funds. The breach has since driven Springtown ISD to tighten vendor data-sharing requirements, mandating ClassLink rostering, DataGuard data masking, and eliminating open API access to student information systems.

Chapters

0:00 - Introduction & Guest Welcome
0:36 - Amanda Joins PDQ
2:17 - Teacher to CTO Career Journey
4:46 - Advice for Aspiring IT Leaders
6:40 - Tabletop Exercises & Vendor Risk
8:28 - Wildest Help Desk Tickets
10:20 - Discovering & Adopting PDQ Connect
13:19 - Budget Challenges & Security Scores
15:46 - Life as a K-12 CTO
17:09 - Managing 12,000 Endpoints
18:01 - Chromebooks vs. Apple in K-12
20:15 - AI Literacy & Security in Education
23:53 - Canvas Breach Response & Vendor Trust

Key Quotes

6:43 "I think one of the most important things we did as a district was started implementing tabletop exercises. And then you find out like, oh, who's gonna call the Texas Cyber Command or the FBI if we have a cyber breach? ..."
11:49 "The vulnerability piece of PDQ Connect is phenomenal and it has made my life a hundred times easier because I don't have to go and match vulnerabilities to softwares or different things on devices."
14:44 "I think anything that you can put a number to and say, hey, we're at this out of five or we're at this out of 10, that's going to — people want to be better. They want to be that five or that 10."
25:24 "Once Canvas said we're good, which doesn't mean they're good, you know, because a company says they're good doesn't mean they're good."
28:45 "I don't think you can ever trust a criminal. So I think you should spend your money being proactive about the incident."
29:49 "Those DPAs are paper. Right. So even though Instructure has a data privacy agreement with a district doesn't mean that when they're hacked that anything's going to happen."

FAQ

How does Springtown ISD manage vulnerability remediation across multiple campuses with a small IT team?

Amanda uses PDQ Connect to create campus-level device groups, giving each technician visibility into and responsibility for the vulnerabilities on their assigned campus. The vulnerability scanner automatically surfaces which devices have which vulnerabilities, eliminating the manual process of cross-referencing CVEs against software inventories. Technicians can then remediate directly from within PDQ Connect without escalating everything to the CTO.

What changes did Springtown ISD make to vendor management after the Canvas breach?

The district now requires all vendors to roster through ClassLink and use DataGuard to mask data fields that vendors don't actually need. Open API access to the student information system has been eliminated. Any vendor that cannot roster through ClassLink must use a secure SFTP connection with specific, limited data fields. The breach also prompted district leadership outside of IT to take vendor risk far more seriously than they had previously.

How did Amanda convince district leadership to increase the IT security budget?

She commissioned a third-party cybersecurity assessment shortly after becoming CTO. The resulting risk score — a concrete number on a scale — gave the CFO and superintendent a tangible target to improve. She also pointed to real K-12 breach incidents as evidence of what could happen without investment, framing security spending in terms of protecting student data and enabling student success rather than as a pure cost center.

Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Vulnerability Management
  • Endpoint Management
  • Data Protection
  • Best Practices
  • Interview
  • Getting Started
  • K-12 IT management
  • Vulnerability management
  • Endpoint management
  • Cybersecurity in education
  • Incident response
  • Vendor risk management
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: From Biology Teacher to K-12 CTO: Amanda Lanicek

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Aug
                  13

                  Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                  08/13/202612:00 PM ET
                  More events

                  Upcoming Webinar Calendar

                  • 08/13/2026
                    12:00 PM
                    08/13/2026
                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                    https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                  • 08/27/2026
                    01:00 PM
                    08/27/2026
                    Becoming Agent Ready with Cyera: Essential Strategies and Insights
                    https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                  • 09/02/2026
                    12:00 PM
                    09/02/2026
                    Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                    https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                  • 09/30/2026
                    04:00 AM
                    09/30/2026
                    AI Command Center: Optimizing Visibility and Control in Your Operations
                    https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                  • 11/19/2026
                    01:00 PM
                    11/19/2026
                    360View: Govern, Secure & Recover Your Microsoft 365 Environment
                    https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                  Truth in IT
                  • Sponsor
                  • About Us
                  • Terms of Service
                  • Privacy Policy
                  • Contact Us
                  • Preference Management
                  Desktop version
                  Standard version