Aug 11 2026
Security

K–12 Schools are Shifting To a Longer-Term Cyber Resilience Strategy

As ransomware attacks level out, IT teams can focus on a proactive cybersecurity plan.

Data from a recent Comparitech report shows a 9% decline in the number of confirmed ransomware attacks on U.S. educational institutions from 2024 to 2025. While incidents may not be rising as fast as they once were, and though average ransom amounts are down 33%, the overall rate of attacks and the severity of breaches is still high. The bottom line is that cyberattacks of any kind aren't going anywhere, and that’s leading schools to shift from emergency response mode toward a longer-term cyber resilience strategy.

Brock Boggs, IT director of Cityscape Schools in Dallas, Texas, says that his team has moved away from living in panic mode to an evolving framework that covers all contingencies. It’s an achievement that was made possible once he got connected with the free tools and resources provided by the Center for Internet Security and accessed the organization's MS-ISAC membership, thanks to sponsorship by the Texas Department of Information Resources.

"Implementing the CIS controls within our organization gave us a long-term strategy of what to improve, where to improve and a timeline of what to do, instead of feeling like you have to do everything all at once,” Boggs says. “But one tool doesn’t cover it all, so we really do try to cover as many bases as possible through as many resources as possible.”

Click the banner below to see how organizations are adapting to handle evolving security needs.

 

Proactive Security Starts With Leadership

Of course, getting school leadership on board with the evolving needs of a cybersecurity strategy is a big factor in influencing what can actually be carried out by the IT team. Boggs says that having the backing of executive leadership has “reduced a lot of panic and frustration for me. Cybersecurity is not an IT problem. It’s an organizational issue that we all work together on. We may not be able to do everything, but there is a plan in place. It really does start at the top; without executive buy-in, you’re toast.”

Live Training as Long-Term Strategy

As artificial intelligence is infused into an increasing number of tools used to improve the classroom experience, it’s also aiding threat actors, who are exploiting the data being put into those very tools. Boggs believes this data governance challenge could be the biggest general risk schools face in the near future. 

“Where is the AI tool being used? Is it an approved tool? Is there an agreement for your organization? Because how are you going to cover something you don’t know about?” says Boggs. 

Because every school employee deals with some level of personally identifiable information, as well as data that belongs to the school district, Boggs says that awareness training is critical: talking with staff and making them aware of what can and cannot be put into AI tools. Recently, Cityscape began conducting dedicated, live AI awareness training sessions for its staff, deciding not to rely solely on sending out informational videos that may or may not be viewed.

“Do we have to do the video because of certain laws and requirements? Yes, but we’re also getting in front of our staff and actually talking, trying to make it engaging, so people don’t just tune out. There’s jokes and pictures of my cat on the screen to keep their attention. I’ll stand on my head if I have to,” Boggs explains. “I know that live training is not always feasible for larger districts,” he adds. “Smaller ones, you can normally get in front of your staff at least once a year. I find the most engagement is when you’re in person.” 

Cyber Insurance Compliance

Although cyber insurance can also be important in case of an incident, the same rules apply as when shopping for any kind of insurance: Read the fine print. 

“If the insurance company says you need to do these 10 things, and you've only done nine of those things, your coverage may lapse. They may not cover you because of that one item. Just because you have a policy doesn’t mean you don’t need to not review it," says Boggs.

Reaching Out for Resources and Community

Schools should always be on the lookout for free cybersecurity resources from national agencies and can also check to see what their state government offers. Boggs sees CIS as an excellent untapped resource for K–12 cybersecurity.

“The thing I’ve learned most is that we are better together. The worst time I ever had in this journey was the first six months, when I was by myself. I was embarrassed by what I didn’t know — and I didn’t know what I didn’t know. It got better once I started connecting with people,” says Boggs. He adds that “I know it can make you nervous, wondering, ‘What will people think? They’re probably so far beyond me, they might not even want to talk with me.’ I found that none of that’s true. They’re all willing to help you.”

MTStock Studio/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.