• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • COVID-19 Update
  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Subscribe
  • Project of the Week
  • Latest News
  • About Us
    SEARCH
IT Infrastructure, Network Security, News

Cybersecurity Incidents at K-12 Schools Nearly Tripled in 2019, Report Says

For the first time since the K-12 Cybersecurity Resource Center began collecting data, schools have canceled classes or closed due to cybersecurity attacks.

March 25, 2020 TD Staff Leave a Comment

Cybersecurity, K-12

As schools become increasingly reliant on technology for teaching and learning, it is putting them at greater risk for cybersecurity incidents, which is apparent in the findings of a new cybersecurity report.

“The State of K-12 Cybersecurity: 2019 Year in Review,” released by the K-12 Cybersecurity Resource Center, found there were 348 cybersecurity incidents reported at 336 K-12 education agencies across 44 states in 2019 — a 185% increase from 122 incidents in 2018.

Of the 348 incidents, 60% were due to data breaches, primarily involving the unauthorized disclosure of student data. The second most frequent type of cyber incident was ransomware or malware at 28%. These types of incidents are the most expensive and disruptive, according to the report.

For the first time since the resource center began tracking school incidents, malware/ransomware incidents resulted in numerous school districts canceling classes or closing in 2019.

The report also shared the worst cybersecurity incidents affecting public schools in 2019, including:

  • Louisana public schools: A State of Emergency was declared in July 2019 after three public school districts fell victim to ransomware, affecting 10% of Louisana’s 5,000 network servers and more than 1,500 computers.
  • Rockville Centre School District: On July 25, 2019, Ryuk ransomware struck the New York school district. The district’s insurance company negotiated the ransom demand down to $88,000 from $176,000, which was covered by them.
  • Las Cruces Public Schools: An October 2019 ransomware attack infected thousands of servers and devices in the New Mexico school district. The district did not pay the ransom and had to reformat nearly 30,000 devices.

The report further breaks down the characteristics of public school districts that experienced these attacks, including by community type, enrollment size, poverty status and region. See below graphic.

 

What Should Be Done Next?

The report ends by providing next steps that should be taken to combat these incidents. More than 50% of the 775 cybersecurity incidents impacting students and educators since 2016 were due to insiders in the school community, including vendors and other third-party partners, suggesting additional focus should be placed on shared school data.

“While school districts must be on guard against criminal actors preying on school communities from afar, they would do well to focus also on shoring up internal policies and practices involving the collection, storage, and sharing of student and employee data under their direct control,” reads the report.

To combat cybersecurity attacks, the report also recommends policymakers, school leaders, and technology leaders do the following:

  • Invest in greater IT security capacity dedicated to the unique needs of school districts
  • Enact federal and state school cybersecurity regulations to ensure baseline school district and vendor cybersecurity practices
  • Support K-12-specific cybersecurity information sharing and research
  • Invest in the development of K-12 specific cybersecurity tools

“These ideas notwithstanding, keeping K-12 schools ‘cyber secure’ is a wicked problem – one that will surely grow more severe until the practice of ongoing cybersecurity risk management becomes institutionalized in school district culture,” concludes the report.

“It won’t be solved solely by an infusion of money, new technologies, new policies and regulations, or a cybersecurity awareness campaign; all are likely necessary, but how they are implemented and evolve over time to meet the specific and idiosyncratic needs and constraints facing public K-12 schools will matter most of all.”

Related: The Cyber Security Checklist: Make Sure Employees Follow These 4 Cyber Security Best Practices

In Florida and Michigan, respective senators Gary Peters and Rick Scott introduced a new bill called the “K-12 Cybersecurity Act” in December 2019, which pushes for some of the above recommendations, according to CISO MAG.

The bill directs the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) to study the specific cybersecurity risks associated with K-12 institutions, and then develop cybersecurity recommendations and set up online tools to help schools meet cybersecurity requirements.

This article originally appeared in our sister publication Campus Safety. 

Tagged With: Cybersecurity

Related Content:

  • Google Password Manager Google Updates Password Manager For Unified Experience
  • VMware vSphere+ vSAN+ VMware Releases vSphere+ and vSAN+ to Enhance On…
  • Microsoft Cybersecurity Architect Expert Microsoft Adds New Expert-level Cybersecurity Architect Certification
  • Microsoft Basic Auth Prepare: Microsoft Begins Disabling Basic Auth in Exchange…

Free downloadable guide you may like:

  • Uber Advanced Technologies Group Drives its Business Forward

    The guiding principle for the new Uber meeting room redesign was “invisible comfort” to ensure that everyone could maximize productivity.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the FREE Tech Decisions eNewsletter

Sign up Today!

Latest Downloads

Uber Advanced Technologies Group Drives its Business Forward

The guiding principle for the new Uber meeting room redesign was “invisible comfort” to ensure that everyone could maximize productivity.

Windows 11
Blueprint Series: Upgrading to Windows 11

Upgrading end users to Windows 11 could be one of the most challenging tasks IT has to face in the coming years. Although the new version is touted...

The State of the IT Department in 2022

The role of the IT professional has shifted from one that supports the business to one that is deserving of a seat at the table when it comes to ma...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!
Sharp Microsoft Collaboration HQ Logo

Learn More About the
Windows Collaboration Display

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Subscribe to the Newsletter
  • Contact Us
  • Media Solutions & Advertising
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSTERMS OF USEPRIVACY POLICY

© 2022 Emerald X, LLC. All rights reserved.