A district holds the same kind of data a hospital does, on people who are mostly children, and runs it on a fraction of the staff.
Student records, health and IEP files, free and reduced lunch applications, staff payroll, parent contact and payment details. A district the size of a mid-market company carries more sensitive personal data than most of them, under more scrutiny, with an IT team that is also the help desk, the device fleet, the projector in room 214 and the network at the football game on Friday night.
Security is not that team's job. It is the job nobody has.
What makes a school different
These are not the exposures a commercial security assessment is built to find.
- The devices go home. A one-to-one program puts thousands of endpoints outside the building every afternoon, on networks you do not control, in the hands of users who are still learning what a password is for.
- The roster turns over twice a year. Every August and every May, hundreds of accounts are created, moved, or should be closed. Access that outlives the person is the most common finding in any district, and it is a calendar problem before it is a technical one.
- Teachers buy software. Ed-tech is sold into classrooms, not into districts. A free tool adopted by one teacher can be holding student data under terms nobody in the central office has read.
- Your empty weeks are published. Every district posts exactly when the buildings are closed. Ransomware crews read calendars.
- And a bad week means a closed school. A manufacturer loses a shift and a hospital diverts. A district that loses its systems sends children home, in front of every parent in the county.
What we do for a district
Senior security leadership for your district, without a district-sized salary on the payroll. The same fractional CISO model we run commercially, scoped to one district, reporting in language a superintendent and a board can act on.
- Where you actually stand. A risk assessment written for the cabinet rather than for an auditor, that says which handful of things matter and in what order.
- An incident response plan, and a tabletop that uses it. Run with the people who would really be in the room: the superintendent, communications, the technology director, counsel. Most districts find the plan's gaps in the exercise, which is the cheapest place to find them.
- Policy a working district can follow. Acceptable use, access and offboarding, vendor review, data retention. Short enough that people read it.
- Awareness training that respects teachers' time. The staff being phished are busy, and training built to satisfy a compliance quota is worse than none.
- Cyber insurance renewals. Carriers now ask districts the same hard questions they ask everyone else, and a renewal can turn on being able to answer them.
- Ed-tech and vendor review. Who holds your students' data, on what terms, and what happens to it when you stop paying them.
The part that is free, and stays free
Separately from any of the above, and with no connection to whether a school ever becomes a client: career events, classroom speaking and small-team mentoring are pro bono. Always.
- Career events and career fairs. What this work actually looks like day to day, what it pays, and the several routes into it that do not run through a four-year degree.
- Classroom speaking. A period or a full day, pitched at the class in front of you. Computer science, business, law and civics classes each have a real angle on this.
- Small team mentoring. Alongside a CyberPatriot team, a cyber club or a competition squad and the teacher running it -- most of whom volunteered without a security background, which is worth supporting rather than pointing at.
If the only thing that ever comes of a conversation with us is a morning in front of your students, that is a good outcome and not a consolation prize. More about events and speaking.
Where a paid engagement starts
Usually not with a retainer. Most districts begin with one piece of defined work that answers a question leadership has already asked: an assessment, an incident response plan, or a briefing that puts the risk in front of the board in plain terms. If ongoing leadership makes sense after that, you will be equipped to have the conversation. If it does not, you still own the work.
Where neighboring districts face the same problem, there is a version of this that is shared between them. Worth raising if your region already collaborates on other services.
Independent and private schools
A private school has no district office behind it and the same obligations in practice. The business office runs tuition, financial aid files and donor records, often on a team small enough that one person's inbox is the single point of failure for payments. Fraud aimed at that inbox is the most common expensive incident in independent schools, and it is a process problem with a process fix.
Technical and community colleges
Higher education carries an obligation K-12 does not. An institution participating in federal student aid falls under the GLBA Safeguards Rule: a written information security program, a named person accountable for it, risk assessments, access controls, encryption, vendor oversight, and an incident response plan. It is examinable. We build the program and the documentation, and we leave you able to run it without us.
Thirty minutes, no slide deck. Or if you would rather get a sense of where you stand before talking to anybody, the Pulse Check takes about ten minutes and gives you the result on the screen.