With cyberattacks rising, schools can strengthen defenses through ethical hacking and proactive testing.
GUEST COLUMN | by Charlie Sander

This back-to-school season, cybersecurity protocols need to be front of mind for leaders across K-12 school districts.
The reason is clear: not only have we seen an alarming rise in the rate of cyberattacks during this past academic year, but we’ve also seen the malicious ways that hackers exploited sensitive student and staff data after the event of serious breaches.
‘… not only have we seen an alarming rise in the rate of cyberattacks during this past academic year, but we’ve also seen the malicious ways that hackers exploited sensitive student and staff data after the event of serious breaches.’
To illustrate, the Center for Internet Security found that 82% of 5,000 K-12 institutions suffered a cybersecurity incident between July 2023 and December 2024, while 61% of IT and security professionals working in education confirmed they were targeted by ransomware over the past 12 months, according to the 2025 Ransomware Risk Report.
The reason behind the relentless surge in cyberattacks is due to the value associated with sensitive student credentials. While hackers may decide to sell stolen credentials on the Dark Web, they are also known to use the possibility as a way to extort educational institutions.
Earlier this year, PowerSchool, a student information system, confirmed it decided to pay a ransom following an attack in December, in which the threat actor contacted “multiple school district customers” directly in an attempt to extort them using data stolen during the attack.
K-12 schools also need to recognize that hackers are constantly looking for ways to beat existing security controls and employ a sophisticated range of emerging technologies. This means that security solutions that provided robust coverage a few years ago can’t be relied on by default.
Instead, ethical hacking and “white hat” practices are gaining prominence as one of the most effective ways that schools can improve their security posture on a budget.
Why schools are turning to ethical hacking
What if one of the most effective ways for schools to strengthen their defenses was to test them by “attacking” them? Think of it like a vaccine: using a weakened form of the virus to protect against the real thing. That’s essentially how ethical hacking works.
A strong school network may have layers of protection, as with any other system, one or more of those layers can go down at any time.
Ethical hackers are legally employed to test these layers and attempt to hack into school systems using all the latest known attack methods.
‘Ethical hackers are legally employed to test these layers and attempt to hack into school systems using all the latest known attack methods.’
In turn, the process helps to identify vulnerabilities that could imminently be exploited by hackers with malicious intent so that targeted security improvements can be made.
An ethical hacker will look for missing patches, misconfigurations, a weakness in a tool deployment or a break in one’s firewall.
In-house “white hat” practices that actually work for K-12 IT teams
Ethical hacking is a great way to improve your security posture this academic year.
However, to become a truly cyber-resilient school, IT teams should complement this with a wider range of best practices.
For one, comprehensive penetration testing should not be a one-time event. Instead, aim to conduct these on an annual basis at the very minimum to account for the fact that technology is always changing and solution providers are constantly updating or distributing security patches.
It’s also important to recognize that many of the most serious risks actually come from inside your perimeters, in the form of teachers, administrators, and other employees.
Testing the defense mechanisms of your perimeters and firewalls is just part of the picture. To become cyber resilient, schools should also be testing how easy it is to manipulate their employees and trick them into gaining access to the system.
Teachers could unknowingly click on a phishing link, or a disgruntled employee could download malware. In fact, phishing attacks on K–12 institutions surged by an alarming 224% in 2024, fueled by increasingly sophisticated, AI-powered impersonation tactics.
‘…phishing attacks on K–12 institutions surged by an alarming 224% in 2024, fueled by increasingly sophisticated, AI-powered impersonation tactics.’
So, while testing employees is important, K-12 schools should recognize that the sophistication of AI-phishing attacks is increasingly hard to distinguish from the real deal. This underscores the importance of front-line screening tools that also use AI to spot these socially engineered emails.
How staffing impacts security defenses
Once hackers get into your network, they essentially have the keys to your home and can move laterally inside your network and wreak havoc.
A common mistake that schools make when testing their defenses is downplaying the seriousness of this risk. We often see schools conduct partial tests or rely on firewall updates that give a false sense of security.
‘A common mistake that schools make when testing their defenses is downplaying the seriousness of this risk.’
With tight budgets and competing priorities, assigning more resources to proactive cybersecurity testing often falls by the wayside, but the risk that hackers pose can’t be ignored.
Although schools may not have an immediate budget for internal and external penetration testing, the cost of not doing so could end up costing the district millions if a data breach occurs and the school is held to ransom.
Another issue stems from the lack of specialized IT support staff that schools have access to. According to the CoSN 2024 State of EdTech District Leadership survey, cybersecurity is the top concern among school IT leaders, and one of the main challenges with technology implementation is an inability to hire skilled staff.
When schools lack access to specialist cybersecurity IT staff, it’s even more important to conduct penetration testing and employ the skills of ethical hackers to improve the security posture this academic year.
—
Charlie Sander is Chairman and CEO of ManagedMethods, a leading Google Workspace and Microsoft 365 data security and student safety platform for K-12 schools. Connect with Charlie on LinkedIn.




















0 Comments