A Maddux Group publication · Est. 2026Public · Charter · Private
The Maddux Report

Technology operations for small and mid-sized schools

Steal these

Playbooks and copy-paste templates

Short documents meant to leave this site and enter a board packet. More will land here as they are field-tested.

Board · one page

Why we need MFA and backups we can restore

Paste into a Google Doc or slide. Replace the brackets. Do not add a fourth slide.

Slide 1 — The risk in our language

Most school incidents start with a stolen staff password or a backup nobody tried to restore. We are a [1 / 2 / 3]-person technology team supporting [N] students. We cannot buy a security operations center. We can close the two holes that take districts offline.

Slide 2 — What “done” looks like

Slide 3 — The ask

Cost this year: $[X] for [licenses / hardware keys / backup target]. Staff time: [Y] days over [Z] weeks. What we will stop doing to make room: [project]. What remains unfunded: [edge firewall replacement / IR retainer / second technician].

Vendor · ten questions

Questions before roster sync

  1. What student data elements do you receive, and which are optional?
  2. Where is data stored (country, cloud provider), and who are your subprocessors?
  3. Do you train models on our student or staff content? Default off, or can we contractually bar it?
  4. How do you authenticate district admins? SSO and MFA, or a shared vendor password?
  5. What is your documented breach-notification timeline to the district?
  6. How do we offboard: full export, deletion, and written confirmation?
  7. Is there a DPA you will sign, or only a privacy policy you can change?
  8. Which interoperability standard do you support for rostering (OneRoster, EDS, SDS, Clever/ClassLink)?
  9. What happens to data if you are acquired or shut down?
  10. Can we see a recent independent security assessment under NDA?