The agency’s free guides for district leaders come as the education sector continues to face a perfect storm of cyber vulnerability and limited resources.
This audio is auto-generated. Please let us know if you have feedback.
Dive Brief:
- The U.S. Cybersecurity and Infrastructure Security Agency released a free collection ofK-12 cybersecurity resourceson Wednesday to help school and district leaders mitigate and respond to their unique cyber risks.
- The CISA resources include two guides: The first aims to give school leaders the basic foundations for developing and improving K-12 cybersecurity programs, and the other is designed for K-12 cybersecurity leaders to find ways to sustain their approaches to cyber defense.
- The guidance comes at a time when the education sector is among the most targeted for cyberattacks, whether directly or through third-party vendors. In recent years, however, CISA and other federal resources have facedsignificant funding disruptionsandstaff cutsunder the Trump administration, creating an uncertain future for the high-level support that cash-strapped schools desperately need.
Dive Insight:
The most common cybersecurity threats that K-12 schools face are data breaches, ransomware attacks, business email compromises, denial of service attacks, and invasions a division of the U.S. Department of Homeland Security
“Unfortunately, cyber criminals often see K-12 schools and school districts as lucrative soft targets for their exploits,” CISA said in the Aug. 12 guidance. “Part of this may be attributed to the fact that K-12 policy, planning, budgeting, resources and personnel are a matter of public record in many jurisdictions.”
CISA added that cybersecurity may often “take a back seat to other priorities” in school systems, as schools are often forced to choose between students’ education and other cyber defense options like equipment, information technology infrastructure, personnel and software.
Between 2018 and 2021, CISA found that schools and districts disclosed over 1,300 cybersecurity incidents. Still, the agency noted, not all K-12 cybersecurity incidents are publicly reported.
During the first half of 2025,CISA’s workforce was reducedby nearly a third as the Trump administration drastically cut staff across the federal government
The Multi-State Information Sharing and Analysis Center, run by the nonprofit Center for Internet Security, alsolost its federal fundinglast year and has since lost 70% of its membership, including dozens of states and over 10,000 local jurisdictions that can no longer afford its crucial cybersecurity services, Cybersecurity Dive reported in June. Schools also leaned on MS-ISAC forfree cybersecurity services, such as threat intelligence and incident response.
K-12 cyberattacks have led to significant school disruptions in recent years, including temporary closures and widespread exposure of sensitive student and staff data.
In the first half of 2026, there were a total of34 ransomware attacksin the U.S. targeting both K-12 and higher education institutions a cybersecurity and online privacy product review website. Twelve of those cases were confirmed. The remaining 22 attacks were unconfirmed, because a ransomware group claimed responsibility for an incident but the organization never acknowledged it
In one example, Comparitech pointed to a March 2026 data breach at Texas’ Alamo Heights Independent School District that affected 26,629 individuals and shuttered the district’s systems for five days.
In recent years, ransomware attacks on major ed tech companies likeInstructureandPowerSchoolhave also led to huge amounts of sensitive school information landing in the hands of cybercriminals.
Between both new CISA guidance reports, the agency advises K-12 district and cybersecurity leaders to implement the following objectives to strengthen their networks:
- Protect the login credentials of students and staff.
- Safeguard student and staff devices.
- Perform, verify and test backups.
- Create and practice a cyber incident response plan.
- Tap into available cybersecurity training and awareness campaigns.
- Protect sensitive data.
- Prioritize and invest in strategies outlined in the full list of applicable CISA Cross-Sector Cybersecurity Performance Goals.
- Develop a customized long-term cybersecurity plan that leans on theNational Institute of Standards and TechnologyCybersecurity Framework.
Filed Under:Policy & Legal,Technology
