In response, school districts are increasingly turning to security awareness training as a frontline defense, pairing education with technical controls to create a more resilient digital environment. The goal, in an ever-changing threat environment, is to turn a weak link into the first line of defense.
“Phishing attacks evolve like anything else, especially with generative artificial intelligence. The things we used to teach people to look for aren’t always happening anymore,” Rose explains. “Districts have to train staff on the latest attacks, and a great way to do that is through security awareness training.”
Districts Place an Increased Focus on Cybersecurity Training
Implemented as a managed service or a feature of endpoint protection software, security awareness training is meant to mitigate human error, giving teachers and staff the information they need to avoid costly mistakes. Although it can be hard for districts to require such training of staff, a growing number of insurance companies are making it mandatory when issuing cyber policies.
“There’s definitely an increased focus on cybersecurity training in the K–12 sector,” Rose says.
The Appleton Area School District (AASD) in Wisconsin is looking hard at how to mandate its cyber training and phishing simulations. It’s been using the Infosec IQ security awareness training alongside a Fortinet endpoint detection and response (EDR) solution for three years and has seen good results.
Today, when the platform sends out a phishing simulation, the number of staff who mistakenly click a link is down about 60%, according to Scott Werfal, the district’s director of technology services. “The product is well integrated and automated, so we don’t have to touch it much,” he says.
Simulated emails include a button to report them as phishing, and should staff erroneously click a link, the system explains how they could have identified it correctly as a phishing attempt.
Werfal says the ongoing training is important because phishing is relentless. “It’s 99% of our issues,” he explains. “So, all staff, including IT, get four simulations a month and then monthly video training with assessments on various topics. The content is high-quality, and it’s been well received by staff.”
Still, although the number of compromised accounts has dropped through training and other endpoint security measures voluntary participation in the video trainings hovers around 40%. “No one necessarily likes training,” Werfal says.
Having recently presented to AASD leadership, Werfal says that momentum is building to better formalize security awareness as required training. “It’s coming,” he says, “because we’re getting attacked constantly. We have to make sure people understand what they should and shouldn’t be doing.”
WATCH: K–12 districts are building a culture of shared responsibility for cybersecurity.
