Cybersecurity
Schools are becoming a new cybersecurity battleground
Schools often operate with limited cybersecurity budgets and relatively small IT teams, while managing vast amounts of sensitive information. CISA unveils a new roadmap to help them prevent and respond to cyberattacks.
- The educational giant behind Canvas suffers a cyberattack affecting 8,800 schools and universities
- Russia-linked hackers targeting Microsoft 365 accounts via public Wi-Fi
- 1
‘Out of Office’: the goldmine cybercriminals are waiting for
- 2
France runs into its own law in bid to ban social media for minors
- 3
Metabase hacked in major breach affecting more than 100,000 companies
- 4
A state’s true strength is tested when the earth shakes: Colombia vs. Venezuela
- 5
EU advances digital euro plans amid disinformation, privacy concerns and public scepticism
- Juan Carlos De la Torre
- Security and Technology Expert
- Published on
15 August 2026 at 07:53
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched its K-12 Cybersecurity Foundations Resource Package, a new set of tools designed to help schools and school districts prevent, mitigate and respond to cyber threats.
The initiative reflects a growing concern on both sides of the Atlantic: aseducation becomes increasingly dependent on digital platforms, cloud services, connected devices and online learning tools, schools are becoming an increasingly attractive target for cybercriminals.
Unlike many private companies, schools often operate with limited cybersecurity budgets and relatively small IT teams, while managing vast amounts of sensitive information. Student records, teachers’ personal data, financial information, health-related information, login credentials and communications with families can all become valuable targets for attackers.
A successful attack can also have consequences that go far beyond data theft. Ransomware can bring lessons, administrative services and even entire school networks to a halt. Stolen credentials can give attackers access to email accounts and cloud platforms, while compromised devices can provide a gateway into wider school or district networks. For students, the risks can extend to identity theft, online harassment, exposure of personal information and the misuse of their digital identities.
“Cyberattacks on K-12 schools and districts jeopardize not only the integrity of our educational mission, but the safety and security of our students and teachers as well,” said CISA Acting Director Nicholas Anderson.“The K-12 Cybersecurity Foundations Resource Package empowers school communities with practical strategies and supports our school safety mission.“
Schools face a growing and increasingly complex threat
CISA’s package is designed to help school and district personnel understand these risks and adopt basic security measures. It provides resources for education leaders and non-technical staff, as well as cybersecurity and IT professionals, recognising that cybersecurity can no longer be treated as a problem belonging exclusively to the IT department.
The package includes a Getting Started Guide, a detailed Implementation Guide and a six-part video series. Its recommendations are organised around eight key objectives, including protecting login credentials, securing devices, testing backups and strengthening cybersecurity training.
That focus on basic cyber hygiene is particularly important in education, where a single compromised account can potentially provide access to multiple services. Teachers, students and administrative staff regularly use email, learning-management systems, cloud storage, video-conferencing platforms and third-party educational applications.The resulting ecosystem creates multiple entry points for attackers.
The rapid adoption of artificial intelligence is adding another layer of complexity. Students and teachers are increasingly interacting with generative AI tools, while cybercriminals are using AI to make phishing messages, impersonation attempts and social-engineering campaigns more convincing. Human error therefore remains one of the most important attack vectors.
CISA Acting Executive Assistant Director for Infrastructure Security Scott Breor said that “K-12 cybersecurity has evolved beyond an IT department concern and must now be recognized as a fundamental pillar of school safety and security.”
The problem extends beyond the United States
The challenge is not unique to American schools. European education systems face many of the same vulnerabilities as they undergo their own digital transformation.
The European Union Agency for Cybersecurity (ENISA) identifies ransomware, malware, threats against data, social engineering, attacks on availability and supply-chain attacks among the major threats affecting Europe’s digital environment. Its2025 Threat Landscape analysed 4,875 incidents recorded between July 2024 and June 2025, with phishing accounting for about 60% of observed initial intrusion vectors.
For schools, this createsa particularly difficult combination of risks.Educational institutions are highly interconnected but often have fewer cybersecurity resources than large corporations. They also depend increasingly on third-party cloud providers, educational software, digital identity systems and connected devices. A vulnerability in one of those services can potentially affect large numbers of schools simultaneously.
The consequences can also be amplified by the nature of the information schools hold. Children’s personal data is particularly sensitive because it can remain valuable for years and may be used for identity fraud or other forms of abuse. At the same time, students themselves are frequent users of social networks, messaging platforms and online services, making them exposed not only to attacks against school infrastructure but also to phishing, account theft, cyberbullying and other forms of online exploitation.
ENISA has recognised the need to address this problem directly. Its CyberEducation platform provides cybersecurity resources tailored to primary and secondary schools across EU member states, while a separate 2024 study assessed the maturity of cybersecurity education in primary and secondary schools across the Union.
Cybersecurity is becoming part of school safety
The growing convergence between physical safety and digital security is changing how schools need to approach cybersecurity.
An attack that disables a school’s network can disrupt communications with parents, prevent access to administrative systems and interfere with teaching. A stolen teacher account can be used to impersonate staff. A compromised student account can expose private information or become a stepping stone for attacks against other users.
This means that protecting a school increasingly requires more than firewalls and antivirus software. Schools need strong authentication, regular software updates, secure backups, access controls, staff training, incident-response plans and clear procedures for dealing with compromised accounts and devices.
CISA’sresource package is intended to provide precisely that kind of roadmap. Its guidance complements other U.S. cybersecurity resources, including CISA’s Protecting Our Future: Partnering to Safeguard K-12 Organizations from Cybersecurity Threats and the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
The broader message is increasingly relevant on both sides of the Atlantic: cybersecurity is no longer simply about protecting a school’s computers. It is about protecting the school itself — its students, teachers, data, services and ability to operate.
Become a premium member for free!
You may be interested in
- CybersecurityThe educational giant behind Canvas suffers a cyberattack affecting 8,800 schools and universitiesSergio Delgado Martorell
- CybersecurityRussia-linked hackers targeting Microsoft 365 accounts via public Wi-FiAlberto Payo
- CybersecurityUkrainian police bust over 100 fraudulent call centersAlberto Payo
- CybersecurityLazarus leverages fake job offers as gateway to aerospace attacksAntonio Bustos
“;
$(“#container-comentar-comentarios”).html(respuesta);
} else if (data == 2) { //TIEMPO
var respuesta =
“No ha pasado aún un minuto desde tu último comentario. Espera un poco y podrás comentar de nuevo una noticia.
“;
$(“#container-comentar-comentarios”).html(respuesta);
} else if (data == 3) { //PALABROTA
var respuesta = “Por favor, utiliza un lenguaje correcto para comentar las noticias.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
} else { //NO LOGUEADO
var respuesta =
“Lo sentimos, al parecer no tienes una sesión iniciada. Vuelve a Iniciar Sesión y podrás publicar este comentario.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function sumarPositivo(id_comentario, id_usuario) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/sumar_reaccion_comentario.php?t=` +
generarCadenaAlfanumerica(),
data: {
tipo: ‘positivo’,
id_comentario: id_comentario,
id_usuario: id_usuario
},
success: function(data) {
//console.log(data);
if (data == 1) {
var likes = parseInt($(“#like_” + id_comentario + ” span”).text());
$(“#like_” + id_comentario + ” span”).text(parseInt(likes + 1));
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function sumarNegativo(id_comentario, id_usuario) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/sumar_reaccion_comentario.php?t=` +
generarCadenaAlfanumerica(),
data: {
tipo: ‘negativo’,
id_comentario: id_comentario,
id_usuario: id_usuario
},
success: function(data) {
//console.log(data);
if (data == 1) {
var dislikes = parseInt($(“#dislike_” + id_comentario + ” span”).text());
$(“#dislike_” + id_comentario + ” span”).text(parseInt(dislikes + 1));
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function recargar_widgets_sesion() {
recargar_cabecero_sesion();
recargar_menu_sesion();
recargar_comentar_sesion();
recargar_comentar_comentar();
comprobar_user_sesion_215_articulo(0);
}
function iniciarSesion() {
var continuar = true;
var msg = “”;
var usuario_log = $(“#usuario_log”).val();
var password_log = $(“#password_log”).val();
var valor_periodico = $(‘#valor_periodico’).val();
// console.log(valor_periodico);
if (usuario_log.length == 0) {
continuar = false;
msg += “Es necesario rellenar el correo electrónico n”;
}
if (password_log.length == 0) {
continuar = false;
msg += “Es necesario rellenar la contraseña.n”;
}
if (continuar) {
$.ajax({
type: “POST”,
data: $(“#formulario_login”).serialize(),
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/login-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
// console.log(data);
if (data == 1) {
recargar_widgets_sesion();
$(“#modal-login .modal-action.modal-close.close-btn”).trigger(“click”);
$(“#usuario_log”).val(“”);
$(“#password_log”).val(“”);
if (window.location.href.includes(“area-usuario”)) {
// window.location.reload();
}
} else {
var respuesta =
“No hemos encontrado ningún usuario con el correo electrónico y la contraseña introducidos. Por favor, vuelve a intentarlo o recupera la contraseña pulsando el botón inferior.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
}
});
} else {
Swal.fire({
text: msg,
icon: “warning”
});
}
}
function comprobar_user_sesion_215_articulo(es_premium) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/comprobar_sesion_user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
console.log(“COMPROBADO SESION USUARIO ” + data);
if (data == 1) {
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).removeClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).addClass(“d-none”);
$(“#banner-premium”).addClass(“d-none”);
} else {
// $(“#art-cuerpo-visible”).removeClass(“art-cuerpo-visible”);
// $(“#art-cuerpo-visible”).addClass(“art-cuerpo-no-visible”);
if (es_premium) {
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“d-none”);
$(“#art-cuerpo-visible-premium”).addClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).removeClass(“d-none”);
$(“#banner-premium”).removeClass(“d-none”);
} else {
$(“#art-cuerpo-visible-premium”).removeClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).addClass(“d-none”);
$(“#banner-premium”).addClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“art-cuerpo-visible”);
}
}
}
});
}
function comprobar_user_sesion_215() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/comprobar_sesion_user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
console.log(“COMPROBADO SESION USUARIO ” + data);
if (data == 1) {
$(‘.col-comparador-registro-login’).addClass(‘w-auto’)
} else {
$(‘.col-comparador-registro-login’).removeClass(‘w-auto’)
}
}
});
}
function cerrarSesion() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/delete-session-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
recargar_widgets_sesion();
$(“#offCanvasClose”).trigger(“click”);
if (window.location.href.includes(“area-usuario”)) {
window.location.href = ‘/’;
}
}
});
}
function registrarCuenta() {
var continuar = true;
var msg = “”;
var email_registro = $(“#email_reg”).val();
var pass_registro = $(“#password_reg”).val();
var pass_registro2 = $(“#password_reg_2”).val();
var nombre_registro = $(“#nombre_reg”).val();
var apellidos_registro = $(“#apellidos_reg”).val();
var ref_id_periodico = $(“#ref_id_periodico”).val();
if (pass_registro2 != pass_registro) {
continuar = false;
msg += “Deben coincidir ambas contraseñas. n”;
}
if (email_registro.length == 0) {
continuar = false;
msg += “Es necesario rellenar el correo electrónico. n”;
}
// if (pass_registro.length < 8) {
// continuar = false;
// msg += “Cal omplir la contrasenya amb un mínim de 8 caràcters. n”;
// }
if (nombre_registro.length == 0) {
continuar = false;
msg += “Hay que llenar el nombre. n”;
}
if (!$(“#aceptopoliticas”).is(“:checked”)) {
continuar = false;
if (ref_id_periodico == 8) {
msg += “You must accept the privacy policy. n”;
} else {
msg += “Debes aceptar la política de privacidad. n”;
}
}
if (continuar) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(“#formulario_registro”).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/register-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
if (data == 0) {
var respuesta = “Este correo electrónico ya está registrado.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
} else {
var respuesta = “¡Enhorabuena! Te has registrado con éxito.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
recargar_widgets_sesion();
$(“#email_reg”).val(“”);
$(“#password_reg”).val(“”);
$(“#nombre_reg”).val(“”);
}
}
});
} else {
Swal.fire({
text: msg,
icon: “warning”
});
}
}
function recuperarPass() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(‘#formulario_recuperarpass’).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/reset-pass-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
var respuesta =
“Revisa tu e-mail y sigue las instrucciones para recuperar tu contraseña.”;
Swal.fire({
text: respuesta,
icon: “info”
});
$(“#modal-pass .modal-action.modal-close”).trigger(“click”);
$(“email_recuperar”).val(“”);
}
});
}
function resetearPass() {
if ($(“#nuevo-pass”).val() == $(“#nuevo-pass-repeat”).val()) {
if ($(“#nuevo-pass”).val().length >= 8) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(‘#resetear-clave’).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/resetear-pass.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
$(“#email_recuperar”).val(“”);
var respuesta = “La contraseña se ha actualizado. Ya puedes volver a Iniciar Sesión.”;
Swal.fire({
text: respuesta,
icon: “success”
}).then((result) => {
window.location.href = ‘http://www.escudodigital.com/’;
});
}
});
} else {
var respuesta = “La contraseña debe tener un mínimo de 8 caracteres.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
} else {
var respuesta = “Ambas contraseñas deben coincidir.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
}
$(document).ready(function() {
recargar_widgets_sesion(); //DESCOMENTAR ESTO
});
‘)
.text(msg)
.insertAfter($el);
}
function esEmailValido(email) {
return /^[^s@]+@[^s@]+.[^s@]{2,}$/.test(String(email).trim());
}
function validar() {
limpiarErrores();
let ok = true;
const $nombre = $(“#nombre”);
const $email = $(“#email”);
const $motivo = $(“#motivo”);
const $check = $(“#checkbox”);
const nombre = $nombre.val().trim();
const email = $email.val().trim();
const motivo = $motivo.val().trim();
if (nombre.length < 2) {
marcarError($nombre, “Enter your full name.”);
ok = false;
}
if (!esEmailValido(email)) {
marcarError($email, “Enter a valid email.”);
ok = false;
}
if (motivo.length < 5) {
marcarError($motivo, “Briefly explain how we can help you.”);
ok = false;
}
if (!$check.is(“:checked”)) {
marcarError($check, “You must accept the legal terms.”);
ok = false;
}
return ok;
}
function setLoading(isLoading) {
$btn.prop(“disabled”, isLoading);
$btn.text(isLoading ? “Sending…” : “Sent”);
}
function submitFormWithToken(token) {
setLoading(true);
const payload = {
nombre: $(“#nombre”).val().trim(),
email: $(“#email”).val().trim(),
motivo: $(“#motivo”).val().trim(),
legal: $(“#checkbox”).is(“:checked”) ? 1 : 0,
periodico_id_periodico: 8,
periodico: ‘www.escudodigital.com’,
url: window.location.href,
periodico_nombre: ‘DigitalShield’,
token: token
};
$.ajax({
url: URL_ENDPOINT,
method: “POST”,
data: payload,
dataType: “json” // Expects JSON response from server
})
.done(function(res) {
if (res && (res === 1 || res === “1” || res.ok)) {
$(“#msgFormContacto”).html(‘Message sent successfully.
‘);
$form[0].reset();
} else {
$(“#msgFormContacto”).html(‘Message not sent. Try again.
‘);
}
})
.fail(function(xhr) {
$(“#msgFormContacto”).html(‘Connection error. Try again.
‘);
})
.always(function() {
setLoading(false);
});
}
$btn.on(“click”, function(e) {
e.preventDefault();
e.stopPropagation(); // Stop default button behavior if any
if (!validar()) return;
// Execute reCAPTCHA
if (window.grecaptcha) {
grecaptcha.ready(function() {
grecaptcha.execute(RECAPTCHA_SITE_KEY, {
action: ‘submit’
}).then(function(token) {
submitFormWithToken(token);
});
});
} else {
// Fallback or error if grecaptcha not loaded
alert(“reCAPTCHA not loaded. Please refresh.”);
}
});
$(“#nombre,#email,#motivo,#checkbox”).on(“input change”, function() {
$(this).removeClass(“is-invalid”);
$(this).next(“.error-text”).remove();
});
});
