Rising digital threats are exposing stark disparities among school systems, where limited resources hinder recovery efforts and leave the most vulnerable learners facing the greatest consequences.
GUEST COLUMN | by Björn Hall

When Baltimore County Public Schools got breached in November 2020, the district stayed offline for three days. And while it might not seem like the worst outcome, the attack had deeper consequences: the school payroll data was compromised, leaving retirees affected by issues with benefits and payments. The financial damage from this incident alone is estimated at $10 million.
This experience shows that cybersecurity in schools is more than just an “IT issue”, yet most school districts treat it as a technical problem: they purchase software, offer annual training, and hope for the best. The reality is 82% of K-12 schools experienced a cyber incident between July 2023 and December 2024.
‘…cybersecurity in schools is more than just an “IT issue”, yet most school districts treat it as a technical problem…’
The stakes are higher than statistics alone suggest. According to the U.S. Department of Education, school districts now face an average of five cyberattacks per week. From 2016 to 2022, public schools in nearly every state reported 1,619 cybersecurity incidents. Each incident disrupted students’ access to education, ranging from three days to three weeks per event.
Breaches Are Increasing—and So Is Their Impact
Whether a district recovers quickly from a cyberattack depends on a few key factors: budget, staff, mindset, and infrastructure. Well-funded districts typically have IT professionals who can act quickly, restoring systems and student access within days. In contrast, a rural district like Boonville R-1 in Missouri had only two IT staff members serving five buildings and 1,500 students, and a recent security audit revealed a lack of critical capacity.
The gap isn’t due to a lack of effort or awareness, as every superintendent understands the importance of cybersecurity. However, awareness does not always translate into having enough staff and budget, especially when three people are doing the job of ten.
Capacity, Not Commitment, Is Where Systems Break Down
The real divide is capacity, not awareness.
CoSN’s 2023 survey reinforces this: two-thirds of school districts lack a full-time cybersecurity position. That means districts housing thousands of students task small IT teams with providing enterprise-level security on an education-level budget.
Let’s think about the wide range of responsibilities within school districts: manage device rollouts, track inventory, support 1:1 school programs, maintain classroom technology, and, on top of that, stay alert to cyberattacks that could take down the entire district.
For some kids, school is more than a place to learn—it’s where they eat, find safety, and receive mental health support. When a cyberattack disrupts these systems, those critical services vanish. The students who rely on schools the most feel the loss the hardest.
When Networks Fail, Critical Student Supports Disappear
The kids who depend on school for food, safety, and support lose the most. The district that can’t recover quickly enough doesn’t just fail at IT; it fails at reducing the opportunity gap in educational equity.
If equity truly matters in education, cybersecurity can’t be an afterthought, addressed only after a breach.
The Cybersecurity and Infrastructure Security Agency bluntly describes the current state: K-12 schools as “target rich, cyber poor.” These schools hold extensive personal and financial data, such as Social Security numbers, disability status, home addresses, and financial records, yet often lack the resources to defend themselves properly.
Faced with this reality, most districts handle cybersecurity like home insurance: they don’t think about it until something burns down, and when it does, they wish they’d acted sooner.
Further highlighting the urgency, a 2024 Department of Homeland Security threat assessment warns that K-12 districts have become “a near constant ransomware target,” a trend fueled by budget cuts and the history of schools paying ransoms.
Resilience Is the New Measure of Fairness
Equity in cybersecurity means resilience.
When an attack hits, many districts panic-buy tools, handing them to already stretched IT staff with little training. Districts with resources can learn from breaches and build sustainable programs, but 12% allocate no cybersecurity funds at all.
The gap is clear, as long as cybersecurity relies on local funding, student data protection and educational security will remain uneven. A student’s access to stable education shouldn’t hinge on whether their district can absorb unexpected technology costs, but that’s exactly how the system works right now.
It’s important to recognize: cybersecurity isn’t just about better training, software, or passwords. It’s about ensuring people and systems are ready to respond when something goes wrong.
Most districts fund essentials like transportation, building maintenance, and textbooks annually without question, as they are seen as essential assets. Similarly, with this mindset, cybersecurity should be treated as another important operational investment. Otherwise, the current broken system continues.
—
Björn Hall, Co-Founder and CEO @ Senturo, is an experienced software entrepreneur in mobile security fleet management. He has led Senturo’s evolution into a powerful enterprise solution that delivers advanced geotracking, compliance automation, and security enforcement across macOS, Windows, iOS, Android, and Chrome OS. Connect with Björn on LinkedIn.























0 Comments