Cybersecurity best practices for K-12 schools

Earlier this year, we joined private sector and government cybersecurity leaders at the White House for the “Back to School Safely: Cybersecurity for K-12 Schools” event. There, we shared a K-12 Cybersecurity Guidebook that includes best practices to help school IT administrators prepare to return to school safely.

For Cybersecurity Awareness Month, we’re sharing a few highlights from the guide — now available in more than 30 languages — plus other helpful resources. Admins can also sign up for our Safer Digital Learning event on October 25, where we’ll demo more of the guide’s security features and best practices to keep schools safe from cybersecurity threats.

The importance of cybersecurity tools for schools

Educational institutions are top targets for cyberattacks, with bad actors looking to exploit schools for their own profit. Forty-six percent of schools which have yet to be targeted believe they’ll eventually be attacked.

We’re committed to helping schools keep data secure and digital learning environments safe. Our education products, like Google Workspace for Education and Chromebooks, can improve schools’ cybersecurity and make it easy to implement the recommendations in our guidebook.

With Google Workspace for Education, admins can get a complete view into security with notifications, alerts and actions in the alert center. They can also manage access to tools with two-factor authentication, single sign-on and password management, set their own data rules and policies with data loss prevention.

Meanwhile, Chromebooks are highly secure, scalable and easy to use thanks to their built-in security features. In fact, there has never been a reported ransomware attack on any business, school or consumer ChromeOS device. And they help protect schools from evolving threats with 10 years of automatic software updates.

Six Cybersecurity Tips for a Successful School Year

Headshot

By Jeff Janover
VP of Security & Interoperability, ClassLink

In today’s digital landscape, hackers and bad actors have developed increasingly sophisticated methods. Their main goal is to steal personal information for malicious purposes and wreak havoc on your system. There are many digital pitfalls. However, there are plenty of protective measures you can take to keep your school safe. Fortifying your cybersecurity skills can help shield school systems from cyber attacks. Below are some cyber preparedness tips to help safeguard your school’s data:

  1. Identify fake websites. Bad actors often create deceptive sites aimed at harvesting personal data, employing URLs that closely mimic legitimate ones. Always double-check a URL before engaging with a website. Fraudulent URLs might use subtle variations like numbers, letters, and dashes that may go unnoticed.
  2. Dodge phishing emails. Be wary of phishing emails that often ask for login credentials or other personal information. Phishing attempts are deceptive because an email domain may appear similar to a trusted email account. For example, an email from staff@sunva11ey.edu is not the same domain as staff@sunvalley.edu. 💡 Notice the letter “l” is replaced by 1s in the phishing email’s domain. If you receive an email from ClassLink requesting personal information such as your login credentials, it is a phishing attempt.
  3. Avoid suspicious links. Only click links you trust. For increased security, add commonly used links to your school’s website for students, educators, and staff to access easily. For even more security, transform any link into a LaunchPad application, bolstering both convenience and safeguarding!
  4. Implement MFA. Use multi-factor authentication whenever possible to add layers of identity protection. ClassLink offers extensive MFA options that help secure online accounts, even if your username and password get compromised.
  5. Implement cybersecurity training. Require mandatory cybersecurity training for all staff and students. You can create your own training or use a training service to help keep your school secure. One option is ClassLink Academy, available in your LaunchPad account! The following courses offer a robust understanding of how to protect against cyber attacks:
    • Security Awareness Anthology (available for ClassLink Administrators, educators, and staff)
      • 1.1 Online Security Fundamentals
      • 1.2 How to Protect Your Data
      • 1.3 Phishing Attack Protections
      • 1.4 What is Social Engineering
    • Directory Services (available only to ClassLink Administrators)
      • 2.1 Scope Your Google Directory
  6. Report suspicious activity. Unexpected logins, changes to passwords, and other unauthorized actions are examples of suspicious activity. If you notice any login attempts or password changes that seem out of the ordinary, reach out to your tech team. At ClassLink, we take all reports seriously and will work to investigate any unusual activity. Thanks for helping us keep everything safe and secure!

Take your cyber readiness to the next level with the Cybersecurity Rubric. The Cybersecurity Rubric is a free self-assessment tool that you can use to assess your school’s cyber preparedness.


Contact your dedicated Account Manager:

ClassLink
Lyle Dadian
Director of Instructional Technology
M: 414-588-9181
O: 862-203-2099
ldadian@classlink.com

Learn More About ClassLink

WEBINAR: K-12 Tech’s Security & Investigation Survival Guide

After what you’ve been through over the past several years, preparing for the worst is just about part of your daily routine.

Alas, summer break is right around the corner, and you know what that means—summer projects!

Join ManagedMethods in expecting the best while preparing for the worst during our next installment in the K-12 Cybersecurity & Safety Leadership webinar series.

We’ll discuss practical tips and recommendations for security, safety, and incident response that you can implement over summer break so that your district can thrive, not just survive, in the 2023/24 school year.

During this session, you will learn the following:

  • What other district technology teams have planned for summer projects
  • Practical tips for what they’ve put in place in previous years that have helped their teams with incident protection and response
  • How they’re keeping their districts’ data secure during summer vacation and staying vigilant for the inevitable back-to-school risk period

Register now to take part in the conversation and arm your district with the security and investigation strategies and skills needed for a successful school year.


Contact your dedicated Account Manager:

David Waugh
Sales and Marketing Vice President
303-415-3643
dwaugh@managedmethods.com

Learn More About ManagedMethods

CYBERSECURITY: How schools can protect their network, devices and data from cyber attacks

The shift to digital learning in response to the COVID-19 pandemic has opened up opportunities for schools to adopt new EdTech tools and create more innovative learning environments. But this has also given cybercriminals new avenues to attack school networks, devices, and data.

Experts recommend protecting all aspects of an educational organization’s online presence:

Endpoint Security

Protect end-user devices connected to a network or cloud with technologies including antivirus tools, endpoint protection platforms (EPP), and endpoint detection and response (EDR) to detect, prevent and respond to cyberattacks in real-time.

Network Security

Prevent and remediate internal and external threats with next-generation firewalls, intrusion prevention, and detection and response systems designed for complete system visibility.

Cloud Security

Safeguard cloud-based data and applications and protect against data loss and malicious theft with tools that elevate application visibility, security, and control for hybrid learning environments.

Applications Security

Detect and block threats deployed through email and the Internet with real-time protection technologies, including spam and DNS filters, encryption, and antivirus.

Data Protection

Keep user data secure with backup and recovery software for the cloud for on-premises and hybrid learning environments and backup-as-a-service (BaaS) solutions.

User Training

Awareness and compliance training for students and staff to improve cybersecurity hygiene and reduce phishing and social engineering attacks.

 

Put the building blocks in place to protect yourself from data leaks and cybercriminals with the support of the Bluum team.

 

 


Why is Cybersecurity a Critical Issue in K-12?

In 2021, district-level leaders ranked cybersecurity as the top concern for the seventh year straight. *

*based on CoSN survey data

408

Reported cyberattacks against K-12
schools in 2020. an 18% increase over 2019

1,387

Days of downtime in U.S. schools due to
ransomware attacks (Feb. ’18 – Jun. ’21)

20%

K-12 Schools with a full-time
staffer dedicated to cybersecurity

 

 

 


Contact your dedicated Account Manager:

Sarah Goncalves
Regional Vice President of Sales
888-226-5727 x3730
Sarah.Goncalves@bluum.com

Learn More About Bluum

Browse the Catalog

Cyber Liability Insurance and MFA: Securing Against the Unknown

Cyber liability insurance acts as a general line of coverage designed to mitigate losses and costs from a variety of cyber incidents, including data breaches, network damage, and the resulting business interruption. Multi-factor authentication (MFA) has proven to be a strong preventative strategy against stolen credentials and brute-force attacks, making it a top
criterionrequestedby cyberinsurance companies.

What You Will Learn

  • What is Cyber Liability Insurance?
  • Why Multi-Factor Authentication (MFA) is a Requirement for Purchasing or Renewing a Cyber Insurance Policy
  • How Duo & CDW can Help Reduce Risk and Premium Costs

 


Contact your dedicated Account Manager:

John Buttita
Sales Manager
877-325-3380
johnbut@cdw.com

Learn More About CDW-G

K-12 Cybersecurity, Safety & Compliance in Google Workspace & Microsoft 365

K-12 Cybersecurity, Safety & Compliance in Google Workspace & Microsoft 365 Webinar Registration

For the first time ever, technology is at the forefront of K-12 education. Technology teams are struggling to keep up with the ever-broadening demands on their time and expertise on a relatively flat budget.

According to an EdWeek Market Brief report, districts with more than 1,000 students are accessing an average of 1,449 edtech tools per school year.

Google Workspace and Microsoft 365 for Education fueled K-12’s move to cloud computing by providing many benefits at a low price compared to on-premises. But they have also introduced many new and unique risks to cybersecurity and student cyber safety.

ManagedMethods is a cybersecurity and student safety platform built specifically for K-12 technology teams. Our goal is to alleviate some of the challenges you face by providing visibility, control, and automation to your Google Workspace and/or Microsoft 365 demands.

Register to join Justin Feltus, Systems Administrator at Bremerton School District, and Reginald Gossett, Executive Director of Technology at Troup ISD. You will learn how ManagedMethods helped them secure data, monitor student safety risks, and generally make their jobs a little easier.

During this session, you will learn:

  • How ManagedMethods protects data from ransomware, phishing, and account takeovers
  • How your district can monitor Google Workspace and/or Microsoft 365 for student safety risks, such as self-harm, cyberbullying, violence, discrimination, sexually explicit content, and other types of toxic online behavior
  • How automating tasks helps keep your district more safe and secure—and helps you keep your sanity!
  • New platform features and updates—if you haven’t checked out ManagedMethods in the past 6 – 12 months, you won’t want to miss this!

 

 


Contact your dedicated Account Manager:

David Waugh 
Sales and Marketing Vice President
303-415-3643
dwaugh@managedmethods.com

Learn More About ManagedMethods

JourneyEd Webinar: New School Compliance Training with KnowBe4

Join in the upcoming webinar with ILTPP vendor partner JourneyEd as the KnowBe4 team discusses security awareness training options for the 2022-2023 school year. Compliance training has a reputation for being challenging for organizations to offer, difficult to do right, and hard to move beyond a tick-box approach. Old-school compliance training is generally very expensive to deliver because of the high per-user price tag. One of the most critical factors of meeting compliance requirements is your users’ understanding of those requirements and actually applying them on the job.

KnowBe4’s Compliance Plus training solves these issues by offering interactive, relevant, and engaging training with real-life simulated scenarios to help teach your users how to respond to a challenging situation.  As a new KnowBe4 customer or a current one, we make it easy to access this content, deliver it to users, and track their progress. The compliance content can help you satisfy Risk, Regulatory, and HR compliance needs, along with some education-specific training such as FERPA, SOPPA, COPPA, and Title IX.

 

Questions we’ll answer during the webinar:

• Why new-school compliance training is more engaging for your users

• The education-specific compliance pillars supported in KnowBe4’s Compliance Plus Training

• How to load users, distribute campaigns, track status and pull reporting

• How to use automated features to save your organization time for new staff and annual training

 

Presenter:

KnowBe4 is the world’s first and largest New-school security awareness training and simulated phishing platform that helps you manage the ongoing problem of social engineering. Forrester Research has named KnowBe4 a Leader in the 2020 Forrester Wave For Security Awareness and Training Solutions. KnowBe4 received the highest scores possible in 17 of the 23 evaluation criteria, including learner content and go-to-market approach.

Even if you can’t join us live, register now and we’ll send you the recorded webcast to watch at your convenience.

 


Looking to renew or purchase licensing with KnowBe4? Make sure to reach out to Christine McConnell at JourneyEd and mention you are an ILTPP member.

Contact your dedicated Account Manager:

Christine McConnell
Senior Account Manager
636-349-7058
cmcconnell@journeyed.com

Learn More About JourneyEd

How To Protect Student Data Privacy & Security in Education Technology

Join ManageMethods for this one-hour webinar exploring the ever-changing world of student data privacy and security in education. How many new apps and/or vendors has your district adopted in the past 2 years? You might be surprised to learn that number is likely much higher than you think.

The EdTech industry is exploding. Though these tools can provide many benefits, they are also creating real student privacy concerns and data security risks.

We’ll be discussing these risks live with Marlo Gaddis, Chief Technology Officer at Wake County Public Schools, and Libbi Garrett, Director of Resource Programs at CITE (California IT in Education), during this free live panel discussion specifically for K-12 technology pros and administration leaders.

You will learn:

  • How data privacy and data security are inextricably linked
  • What student privacy concerns you should consider when working with vendors
  • How using 3rd party edtech applications can create data privacy and security risks
  • And much more!

Presenters:

 

Marlo Gaddis
Wake County Public School System
Chief Technology Officer

 

 

 

 

Libbi Garrett
California IT in Education (CITE)
Director of Resource Programs

 

 

 

 

David Waugh
ManagedMethods
Cybersecurity Champion for Education

 

 

 

 


Contact your dedicated Account Manager:

David Waugh
Sales and Marketing Vice President
303-415-3643
dwaugh@managedmethods.com

Learn More About ManagedMethods

K12 Data Privacy & Cybersecurity Conference

A two-day professional development event focused on data privacy and cybersecurity for K-12 Administrators, Technology Leaders, and IT Staff.

SecurED Schools is an annual conference hosted by the Learning Technology Center that focuses on cybersecurity and data privacy best practices, strategies, and tools. Over two days, attendees participate in hands-on demonstrations, panel discussions, and presentations led by local, state, and national experts.

The goal of SecurED Schools is to improve the security posture of school districts. We know that the global pandemic fueled digital transformation and technology adoption in school districts across our country. With increased reliance on technology to empower learning comes increased risk, and PK-12 technology and education leaders increasingly understand the vulnerability of their networks and data. 

Where and When

Dates: January 19-20, 2022
Location: Virtual
Cost: $25
PD Hours: 10

Audience

SecurED Schools is geared toward technology leaders (CTOs, technology directors, IT managers), IT staff (network engineers, IT support staff), and district/building administrators, as well as anyone responsible for collecting, maintaining, reporting, certifying, and/or protecting and securing student data in an educational environment.

Questions?

Please contact Chris Wherley at cwherley@ltcillinois.org with questions.

K12 Data Privacy & Cybersecurity Conference

A two-day professional development event focused on data privacy and cybersecurity for K-12 Administrators, Technology Leaders, and IT Staff.

SecurED Schools is an annual conference hosted by the Learning Technology Center that focuses on cybersecurity and data privacy best practices, strategies, and tools. Over two days, attendees participate in hands-on demonstrations, panel discussions, and presentations led by local, state, and national experts.

The goal of SecurED Schools is to improve the security posture of school districts. We know that the global pandemic fueled digital transformation and technology adoption in school districts across our country. With increased reliance on technology to empower learning comes increased risk, and PK-12 technology and education leaders increasingly understand the vulnerability of their networks and data. 

Where and When

Dates: January 19-20, 2022
Location: Virtual
Cost: $25
PD Hours: 10

Audience

SecurED Schools is geared toward technology leaders (CTOs, technology directors, IT managers), IT staff (network engineers, IT support staff), and district/building administrators, as well as anyone responsible for collecting, maintaining, reporting, certifying, and/or protecting and securing student data in an educational environment.

Questions?

Please contact Chris Wherley at cwherley@ltcillinois.org with questions.