Good cyber-hygiene ultimately comes down to buy-in from every individual from the top down, promoting a culture that takes cyber threats seriously — and is willing to act.
- Require multi-factor authentication (MFA): Whether in the form of a one-time PIN sent to email or instant message, or proximity to a recognized device such as a smart phone, MFA offers an extra level of user verification.
- Have a solid plan in place before an incident: Train and drill staff on specific areas of responsibility and procedures for different “what if?” scenarios:
- How to proceed in mitigating or remediating an incident
- Whom to contact, and in what order
- What not to do
Even with good cyber hygiene, mistakes still happen; attackers may still get in. So it is equally important to build up cyber resilience to defend against successful intrusions.
- Create and test frequent backups: In addition to regularly backing up data, it’s also important to back up structures such as Active Directory, as well as the hardware housing the back-ups. Then test them at a regular interval to make sure they work reliably before you need them.
- Consider running “chaos engineering” exercises: Randomly shut down servers or data centers to test the response; if your detection systems fail to register a problem, then your preparations have failed. This will reveal where you need to improve.
- Establish and nurture critical relationships: It’s good to have allies outside of your organization that you can reach out to in the event of an attack, including colleagues who can offer their material support and guidance.
The right technology stack is of course integral to implementing these best practices. Outdated technology stacks make it much harder to adequately perform these types of cyber resiliency actions. School districts need to leverage modern technology tools to effectively detect, resist and recover from attempted cyberattacks. Because product options can seem overwhelming, it’s important to seek the right guidance to help you understand what those tools are, how they work and how to apply them most effectively.
Don’t Leave Money on the Desk!
Fortunately, for the first time, there is now significant federal funding available to help K-12 organizations address their increased cybersecurity needs. These funds go well beyond limited E-rate basics. The $2.2T Coronavirus Aid, Relief, and Economic Security Act (CARES Act) provides emergency funding assistance that K-12 schools can use to advance their technology capabilities for distance learning and ensure continuity of operations. A strengthened cybersecurity posture is essential to that purpose. In particular, the Elementary and Secondary School Emergency Relief Fund (ESSER) was allocated as part of the CARES Act Education Stabilization Fund provision, tying directly back to addressing cybersecurity concerns. Other funding is available under the American Rescue Plan Act (ARPA) and the Coronavirus Response and Relief Supplemental Appropriations Act (CRRSA).
The pandemic clearly brought forward the need to focus on big problems like ransomware and bolstering cyber posture. Under these special funding programs, K-12 organizations can deploy needed solutions for little to no money coming from their existing budget. More information can be found on each Act’s website.
These are temporary relief programs, so there is no time to wait. There has never been a more critical time to safeguard schools’ and children’s digital lives.
- Quit saying “I’m not a math person” - September 16, 2026
- 5 questions to help every district leader make better decisions - September 15, 2026
- Why K-12 cybersecurity education needs practice, not just awareness - September 14, 2026
