At the federal level, 2023 also saw increased activity. The Federal Communications Commission (FCC) launched a three-year, $200 million pilot program to help schools and libraries acquire cybersecurity equipment and services. Meanwhile, the Cybersecurity and Infrastructure Security Agency provided recommendations to guide districts in prioritizing and implementing security measures.
Julia Fallon, executive director of SETDA, which represents state leaders in digital learning and educational technology, points to several factors driving states’ increased attention. The number of cyberattacks on schools nearly doubled between 2021 and 2023, she says, including several ransomware attacks on high-profile districts. She believes that lawmakers also recognized that schools are more susceptible to attacks due to their rapid adoption of technologies during the pandemic, combined with new risks related to artificial intelligence.
There is also growing awareness that small and under-resourced districts need help, says Fallon.
“It’s important to recognize that smaller districts, especially those in rural areas, face unique challenges,” she says. Without an influx of students or funds to support a dedicated cybersecurity professional, “they rely heavily on external support from the state.”
Task forces and other collaborative efforts give small districts the benefit of shared resources, training and cost-effective solutions, while state-funded assessments and cybersecurity awareness platforms can help them strengthen their security posture, Fallon says.
Here’s how schools in Michigan and Texas are leveraging state resources to help them navigate cybersecurity challenges.
RELATED: Small and independent schools are managing cybersecurity.
Michigan Schools Team Up to Improve Cybersecurity Posture
In the Wolverine State, Senate Bill 173 amended the State School Aid Act in 2023 to allocate $9 million for a statewide security operations center (SOC), called MiSecure, service area of the Michigan Association of Intermediate School Administrators. MiSecure provides managed detection and response (MDR) services. The Michigan Education Technology Leaders (METL) group, a collaborative network of MAISA, played a pivotal role in securing the funding with the goal of helping districts implement high-impact cybersecurity measures, according to Dwight Levens. Levens is a MiSecure advisory board member and chief technology and information officer of Oakland Schools, an intermediate school district.
The METL cybersecurity task force and MiSecure developed a self-assessment tool for districts to evaluate their cybersecurity readiness. The state funding supporting MiSecure and its offering of a managed detection and response solution will allow districts to improve their cybersecurity posture immediately as they work to remediate any deficiencies found in the self-assessment, says Levens.
“Michigan has done a lot of statewide initiatives, and I think this one is going to be impactful for many years into the future,” he says.
The SOC offers districts the option to receive centralized support through MiSecure or purchase more granular security management while also leveraging the support of MiSecure. Having that flexibility is key to supporting the cybersecurity postures of the diverse districts served.
SOCs and other centralized services are one of the most effective ways that states can raise the overall cybersecurity posture, says Fallon. “State-managed services relieve some of the burdens on districts and provide them with real-time support,” she says.
In Michigan, MiSecure selected CrowdStrike Falcon Complete as the SOC’s MDR solution and is working with districts to obtain licenses. CrowdStrike’s suite of capabilities encompasses endpoint and cloud security as well as 24/7 threat hunting and response.
WATCH NOW: Check out one California district’s proactive cybersecurity efforts.
Levens emphasizes that while MDR services can vary by vendor, they are particularly important for districts that don’t have dedicated security teams. Through the SOC, districts will have access to consistent support and expertise they may not have budgets to sustain otherwise.
“You have organizations that are all sitting in different places from a cybersecurity maturity and resource perspective, and this leverages the collective power of the group as designed in Michigan,” says Levens.
Texas District Seeks Funding for Security Assessment and Training
Texas took significant action in 2023, passing five cybersecurity bills, including House Bill 1, which allocates $55 million to the state’s K–12 Cybersecurity Initiative. The Texas Education Agency (TEA) said it sought the funding “to counter the rising surge of ransomware and malicious activity.” The funds will support in-kind services to local education agencies, especially those in rural areas.
While some state initiatives focus on long-term goals, such as expanding the cybersecurity workforce, this one is designed for immediate impact. TEA encourages districts to take advantage of the opportunity to implement controls such as endpoint detection and response, multifactor authentication and enhanced email security.