With more than 70,000 students, over 150 schools and a requirement to retain data for 55 years, Dufferin-Peel Catholic District School Board has strengthened its cybersecurity capabilities to improve visibility, support regulatory compliance and protect students and staff from evolving cyberthreats.
Protecting one of Canada’s largest school boards presents a significant cybersecurity challenge.
Dufferin-Peel Catholic District School Board (DPCDSB) supports more than 70,000 students across more than 150 schools and employs thousands of staff. Alongside defending against increasingly sophisticated cyberattacks, the board must retain student records for 55 years while complying with evolving provincial regulations, including requirements around managed detection and response (MDR) and online safety.
“School boards are a perfect target for bad actors because we have large amounts of data,” said Chief Information Officer Ivana MacIsaac, according to a Trend Micro case study. “We have a large user community we must keep educated. And with new regulations requiring social media protections for our students, we want to make sure that they’re always protected within the school board environment.”
To strengthen its security posture, DPCDSB expanded its existing relationship with Trend Micro by implementing Trend Vision One Managed Detection and Response services.
“Having MDR in place is critical,” said MacIsaac. “It gives us peace of mind, knowing we have a partner available monitoring our environment 24/7.”
The school board is responsible for protecting more than 11,000 endpoints across school sites and remote environments. According to DPCDSB, improved visibility has enabled its IT team to identify vulnerable devices more quickly and respond more effectively to potential threats.
“We can now see every detail of endpoint networking activity; the depth and volume of incoming data is remarkable,” said Network and Security Analyst John Trembly, according to the Trend Micro case study.
“XDR agents give us direct control over the system. We can isolate an endpoint, run scripts, or open a CMD window to investigate. Thankfully, we haven’t needed to use those capabilities yet, but it’s reassuring to know they’re there.”
The board said continuous monitoring has also reduced the operational burden on its internal IT team, allowing staff to focus more on strategic security initiatives and regulatory compliance.
“With Trend Vision One, we have not had a single critical alert,” said Trembly. “And we don’t have to worry so much about threat hunting or ‘minding the gate’ when we have MDR doing it for us.”
DPCDSB has also strengthened the protection of its server and cloud environments, using cyber-risk exposure management capabilities to identify outdated systems, forgotten databases and other potential vulnerabilities before they can be exploited.
The enhanced visibility has improved reporting to senior leadership, helping the IT team demonstrate compliance, support requests for cybersecurity investment and prioritise remediation activities.
Reflecting on the partnership, Trembly highlighted the importance of responsive technical support during security incidents.
“Getting critical issues fixed is never a problem,” said Trembly. “There’s always somebody who knows a different part of the system, how to set it up, and how to run it effectively.”


