When we asked the technology director of a Texas school district which K-12 security myth most needed busting, she didn't hesitate: "They won't pick on schools because we're broke."
It's an understandable belief. Most districts don't have money sitting in an account worth stealing. But attackers aren't after a district's bank balance. They're after its leverage, and a school district has plenty.
She also told us two stories that every school IT team should hear before their next incident, not after. One is about a single device that undid a district's recovery. The other is about what a cyber insurer required in the middle of one.
Why would anyone attack a district with no money?
Because a school district can't function without its systems.
A school that can't take attendance, run its student information system, or get buses routed has families, staff and a board demanding it reopen now. That pressure is the first pain point. Student and staff records add a second. CISA's report on K-12 cybersecurity notes that attackers target K-12 organizations with potentially catastrophic impacts on students, families and staff.
Then there's the question of who’s defending. Districts often run with a small IT team, frequently led by someone who came up through the classroom rather than security. Attackers also know when that team is thinnest. We covered the holiday timing problem in what "someone watching" misses.
Broke doesn't make a district a poor target. Lean IT does.
What makes K-12 different from a company?
Device count, for one. Many districts now have more devices on campus than students.
The bigger difference is what happens when a user breaks the rules. She put it simply: "Unlike a company that gets to fire an employee who violates an AUP, at schools we have to keep them, and we have to put that device back in their hand the very next day." (An AUP, or acceptable use policy, sets the rules for how a district device can be used.)
A company can remove a risky user. A district can't remove a risky ninth grader. The same student, on the same device, comes back tomorrow. Security has to be built around users you can't remove.
What happens when the device goes home?
Post-COVID, she pointed out, traditional firewall and DNS rules stop mattering the minute a Chromebook leaves campus.
The device still belongs to the district. It still holds a student account tied to district systems. But its traffic no longer passes through anything the district owns. Every control that lives at the network edge goes quiet until the device comes back.
That changes where monitoring has to live. Coverage that depends on traffic crossing your firewall covers the school day on campus and not much else. Coverage that follows the device and the identity covers evenings, weekends, snow days and summer.
The question to ask of your own tools and any service provider: what share of our monitoring still depends on the device being on our network?
How did one device reinfect a recovered district?
Here’s a story relayed from another district, and one that will stay with you.
The district was hit, recovered, and declared all-clear. A teacher had kept a second device to move files around, and never turned it in during the cleanup. Two or three weeks after the all-clear, the teacher brought it back and connected it. It reinfected everything.
Nobody did anything malicious. The teacher was just trying to get work done. The district did the hard part of recovery. The gap was one device that wasn't on anyone's list.
The lesson is about what "all clear" means. It isn't the moment the known systems are clean. It's the moment every device is accounted for, and any device that was off the network during the incident is reimaged before it reconnects. That standard is only as good as your inventory.
What can a cyber insurer require mid-recovery?
Her second story is less dramatic, but arguably more useful.
A breached district, to satisfy its cyber insurer, had to pull every hard drive and seal them as evidence. Then it had to buy new drives and clone them to keep operating, in the middle of the recovery.
Nobody plans for that line item. It adds cost and days at the worst possible moment. Evidence preservation requirements are in your policy now. Read them before an incident, so the purchase order and the process exist before you need them.
How do you make the case to a school board?
Boards think in cost per pupil, not in security tools. Frame it that way.
The budget backdrop is tight. Districts had to obligate the last of their federal pandemic relief funds by September 30, 2024, and many are still absorbing that loss alongside declining enrollment. She called it "a double whammy."
That makes one-time money the wrong home for security. Monitoring is a recurring cost, so it needs a recurring line, expressed per pupil, next to the cost of a week with no attendance system, no SIS and no buses.
Where does Gradient Cyber fit?
Quorum AI correlates telemetry across endpoint, network, identity, SaaS and cloud, and monitoring runs around the clock, including the breaks when district staff are out. What reaches your team is a SitRep: the supporting evidence, a severity, and prioritized actions.
That coverage reaches past the campus edge in two ways. Quorum AI connects directly to Microsoft 365 and Google Workspace by API, so account activity is monitored whether the device is at school, at home or on a coffee shop network. And when a device comes back on campus, its network behavior is analyzed like everything else. A device that picks up something while away and starts acting out of character once back on the network is the kind of activity QAI is built to flag.
A note on student devices. In the districts we work with, endpoint detection typically goes on faculty and staff devices, not student Chromebooks. That makes the account and the network the main places student activity is seen, which is exactly why they need to be monitored continuously.
What stays with the district: your inventory, your device policies, your recovery decisions, and who has authority to pull a device during a school day.
What should a district do this semester?
- Reconcile your device inventory against rosters. Every student and staff device, issued and returned.
- Define the all-clear in writing. Every device accounted for, and anything that was off-network during an incident reimaged before it reconnects.
- Measure off-campus coverage. Find out what you can see when a device is at home.
- Read your cyber insurance policy's evidence requirements. Plan the drive replacement before you need it.
- Plan coverage for breaks. Winter and summer are on a public calendar.
- Put security on a recurring budget line, expressed per pupil.
Frequently asked questions
Are small rural districts really targets?
Yes. Attackers aren't sizing the bank account. They're sizing the pressure to restore operations and the depth of the team defending them, and small districts tend to have plenty of the first and little of the second.
Does our content filter cover devices at home?
It depends on where the filter is enforced. If it runs at your network edge, it stops applying when the device leaves campus. If it's enforced on the device or through the student account, it may follow. Check which one you have.
What should "all clear" mean after an incident?
Every device accounted for, not just every known system cleaned. Devices that were off the network during the incident get reimaged before they reconnect.
Can a district afford 24/7 monitoring?
Run the number per pupil and put it next to the cost of a week without your systems. That's the comparison a board can act on.
Hear more at TCEA SysAdmin
Neal Hartsell, Gradient Cyber's CMO, is presenting "The One-Person SOC: 24/7 Coverage for Lean IT Teams" at the TCEA System Admin Conference in Georgetown, TX, Thursday, November 5 , 1:00 to 1:50 PM, in San Gabriel J/K. The session covers how to tell whether your current tools are actually being watched, and what to look for, and avoid, when evaluating an MDR or MXDR partner to extend coverage without adding headcount.
If you're attending, come find us.
Being broke was never protection. A district is a target because of what it can't afford to lose, not what it has in the bank.