Dive Brief:
- The U.S. Cybersecurity and Infrastructure Security Agency released a free collection of K-12 cybersecurity resources on Wednesday to help school and district leaders mitigate and respond to their unique cyber risks.
- The CISA resources include two guides: The first aims to give school leaders the basic foundations for developing and improving K-12 cybersecurity programs, and the other is designed for K-12 cybersecurity leaders to find ways to sustain their approaches to cyber defense.
- The guidance comes at a time when the education sector is among the most targeted for cyberattacks, whether directly or through third-party vendors. In recent years, however, CISA and other federal resources have faced significant funding disruptions and staff cuts under the Trump administration, creating an uncertain future for the high-level support that cash-strapped schools desperately need.
Dive Insight:
The most common cybersecurity threats that K-12 schools face are data breaches, ransomware attacks, business email compromises, denial of service attacks, and invasions, according to CISA, a division of the U.S. Department of Homeland Security.
“Unfortunately, cyber criminals often see K-12 schools and school districts as lucrative soft targets for their exploits,” CISA said in the Aug. 12 guidance. “Part of this may be attributed to the fact that K-12 policy, planning, budgeting, resources and personnel are a matter of public record in many jurisdictions.”
CISA added that cybersecurity may often “take a back seat to other priorities” in school systems, as schools are often forced to choose between students’ education and other cyber defense options like equipment, information technology infrastructure, personnel and software.
Between 2018 and 2021, CISA found that schools and districts disclosed over 1,300 cybersecurity incidents. Still, the agency noted, not all K-12 cybersecurity incidents are publicly reported.
During the first half of 2025, CISA’s workforce was reduced by nearly a third as the Trump administration drastically cut staff across the federal government, according to Cybersecurity Dive.
The Multi-State Information Sharing and Analysis Center, run by the nonprofit Center for Internet Security, also lost its federal funding last year and has since lost 70% of its membership, including dozens of states and over 10,000 local jurisdictions that can no longer afford its crucial cybersecurity services, Cybersecurity Dive reported in June. Schools also leaned on MS-ISAC for free cybersecurity services, such as threat intelligence and incident response.
K-12 cyberattacks have led to significant school disruptions in recent years, including temporary closures and widespread exposure of sensitive student and staff data.
In the first half of 2026, there were a total of 34 ransomware attacks in the U.S. targeting both K-12 and higher education institutions, according to Comparitech, a cybersecurity and online privacy product review website. Twelve of those cases were confirmed. The remaining 22 attacks were unconfirmed, because a ransomware group claimed responsibility for an incident but the organization never acknowledged it.
In one example, Comparitech pointed to a March 2026 data breach at Texas’ Alamo Heights Independent School District that affected 26,629 individuals and shuttered the district’s systems for five days.
In recent years, ransomware attacks on major ed tech companies like Instructure and PowerSchool have also led to huge amounts of sensitive school information landing in the hands of cybercriminals.
Between both new CISA guidance reports, the agency advises K-12 district and cybersecurity leaders to implement the following objectives to strengthen their networks:
- Protect the login credentials of students and staff.
- Safeguard student and staff devices.
- Perform, verify and test backups.
- Create and practice a cyber incident response plan.
- Tap into available cybersecurity training and awareness campaigns.
- Protect sensitive data.
- Prioritize and invest in strategies outlined in the full list of applicable CISA Cross-Sector Cybersecurity Performance Goals.
- Develop a customized long-term cybersecurity plan that leans on the National Institute of Standards and Technology Cybersecurity Framework.