A school district holds a great deal of information about children. Enrollment records, health information, special education documentation, family contact details, and increasingly the digital work of students themselves. Districts are obliged to look after it, and most district technology directors need no persuading of that.
What they usually need is something less dramatic and more useful: an order of work. Security spending in districts tends to arrive as individual products, bought in the order they were offered, each solving a real problem but none of them in a sequence that makes the next thing easier. This is an attempt at that sequence.
It is not the only one, and it is worth reading alongside the federal guidance. The Cybersecurity and Infrastructure Security Agency publishes a body of material aimed specifically at school systems, collected at CISA's cybersecurity resources for K-12 education, including its report on partnering to safeguard K-12 organizations. Where this article and that guidance disagree on sequence, prefer the guidance.
It is a program, not a purchase
The single most useful reframing is to stop thinking of district cybersecurity as a thing to buy and start thinking of it as a standing capability that improves in stages.
That matters practically because it changes how it gets funded. A product is a line item that competes with other line items in one budget year. A program is a plan across several, in which each stage is justified partly by what it enables next. Boards approve the second more readily than the first, because it comes with an explanation of where it ends.
It also changes what you ask suppliers for. A program needs a starting assessment and a sequence. It does not need a demonstration.
Start with an assessment, and insist it is written down
Almost every district that has run into difficulty was surprised by something it owned: a server nobody had patched because nobody remembered it was there, an account belonging to someone who left, a supplier connection made for a project that finished. Security work that begins with a control rather than an inventory is guessing about where the exposure is.
A useful assessment for a district establishes what systems exist and who owns each one, where student and staff data actually lives including anything in cloud services bought by campuses, who and what can reach those systems, what is no longer supported by its vendor, and what would happen if the most important system were unavailable for a week.
Ask for the output in writing, in language a superintendent can read, with the findings ranked. An assessment that produces a conversation and no document cannot be taken to a board, cannot be handed to a successor, and cannot be measured against next year.
An order of work that holds up
The stages below are roughly in the order districts benefit from them. Local circumstances move things around, but a district that follows this shape rarely finds it has done something out of sequence.
Make recovery real first
Before anything else, know that you can get the district running again. That means backups that cover the systems that matter, stored so that a problem on the network cannot reach them, and, crucially, a restore that somebody has actually performed and timed. A backup that has never been restored is a belief, not a capability.
This comes first because it is the stage that limits how bad any other failure can be, and because it is usually the cheapest thing on the list.
Know who can reach what
Identity is where most practical improvement lives in a district. Accounts for people who have left, shared logins that several people use, administrative rights handed out for a task years ago and never withdrawn, and staff who can reach far more data than their role requires.
The work is unglamorous and highly effective: a real joiners and leavers process, multi-factor authentication on staff and administrative accounts, administrative rights granted deliberately and reviewed, and access to student information scoped to the role. None of this stops an attempt being made. It substantially reduces what an attempt can reach.
Reduce the obvious exposure
Patching on a known schedule for the systems that face outward and the ones that hold the most. Endpoint protection that is actually reporting rather than installed. Segmentation so that the network a student device sits on is not the network the finance system sits on. Retiring systems that no longer receive updates, which is often a procurement problem rather than a technical one.
Look at cloud services and third parties
Districts run on services somebody else operates, and many of those were adopted campus by campus. It is worth establishing which services hold student data, what each vendor commits to, and how access is granted and withdrawn when staff change. Where a district operates in a state with its own cloud security framework, that framework is a useful checklist even where it does not formally apply; LABUSA has written separately about TX-RAMP certified cloud services in Texas.
The movement of records between the district and outside parties deserves specific attention, because it is routine, high volume, and easy to leave on whatever mechanism was in place a decade ago. LABUSA has supported Texas school districts modernizing how student records are transmitted.
Write the policies down
Policy work is often deferred because it produces nothing visible. It is worth doing because it is what turns individual good practice into something the district can rely on when the person who was doing it leaves. Acceptable use, access control, data retention, vendor assessment, and a written incident response plan that names who decides what and who is called first.
An incident response plan that exists only as a shared understanding among three people is not a plan.
Bring people into it
Staff awareness is a control, and in a district it has to be designed for people whose job is teaching, not technology. Short, relevant, repeated, and specific to what staff actually encounter. Training that treats teachers as though they were a corporate security team is ignored, reasonably.
LABUSA operates a learning platform for security awareness training, which is one way of delivering this. The important part is not the platform; it is that the content fits the audience and that it recurs.
Turning that into a roadmap a board will fund
Districts fund in years, so the roadmap should be built in years. A workable version states, for each stage, what will be done, roughly what it costs, what it depends on, and what it makes possible next.
Two things make such a plan far more likely to be approved. The first is that each stage produces something that can be reported as finished, rather than an indefinite improvement. The second is that the plan is honest about what is not being addressed yet and why, which is what allows a board to accept the sequence rather than asking for everything at once.
Governance is the part that keeps the plan alive between budget cycles: someone accountable, a standing review, and a short report that goes to leadership whether or not anything has happened. Programs without a review rhythm quietly become a list of things that were bought.
What to ask a supplier for
Districts buying security help get better results when they ask for specific things rather than for security.
- An assessment with a written, ranked output and a named person who will present it.
- A sequence, not a shopping list. If a proposal recommends five things, ask which one comes first and why the others depend on it.
- Work your team can carry on. Configuration documented as built, and the routine tasks written down.
- Clarity about what is a project and what is ongoing. An assessment ends; monitoring, patching and alert handling do not, and are bought as managed services with a permanent cost. Districts sometimes approve the second believing they have approved the first.
- Plain statements about limits. A supplier who tells you what a control does not do is more useful than one who does not.
Obtaining the expertise
Most districts do not need a permanent security specialist and could not recruit one at the salary they can offer. What they need is access to that expertise at defined points: an assessment, a remediation project, help writing policy, and a review each year.
That is a professional services purchase, and cooperative purchasing suits it well, because the requirement is definable and the timing usually matters. Districts that are eligible TIPS members can obtain cybersecurity services through Contract 230601, subject to their own purchasing policies and approval requirements. The wider picture of what districts buy and how the calendar shapes it is covered in how school districts purchase IT services.
If you are starting from nothing, start with the assessment and the restore test. They cost the least, they tell you the most, and everything else on the list gets easier to justify once you have them.