Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the K12 Cybersecurity topic

No spam. Unsubscribe anytime.

CISA training urges K‑12 districts to adopt MFA, immutable backups and clearer incident roles

Cybersecurity and Infrastructure Security Agency (CISA) School Safety Task Force · June 1, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At a CISA virtual training, K‑12 cybersecurity experts from K12 SIX and DC Public Schools urged districts to adopt multi‑factor authentication, immutable backups, clear governance and vendor due diligence to reduce ransomware and data‑exposure risks.

Andrew Dominic, a member of the Cybersecurity and Infrastructure Security Agency (CISA) School Safety Task Force, opened a virtual training titled "Strengthening K‑12 Cybersecurity: Simple Steps for Safer Schools," and introduced two panelists who offered practical steps for K‑12 leaders.

Doug Levin, co‑founder and director of the nonprofit K‑12 Security Information eXchange (K12 SIX), said attackers target schools for sensitive student and staff data, operating funds and the trust channels schools use to communicate. "Threat actors are going after personal and sensitive information... and third‑party access can compromise hundreds or even thousands of school systems," Levin said, describing common attack vectors as phishing, unpatched internet‑facing systems and compromises of vendors used by multiple districts.

Cyrus Virani, chief information officer for DC Public Schools (DCPS), told attendees that the urgency to restore instruction and services makes districts particularly vulnerable to ransomware. "There is a high pressure to restore operations as quickly as possible," Virani said, arguing that that pressure can increase the likelihood of costly or risky decisions after an incident.

Both panelists said cybersecurity must be a shared responsibility led by district leadership. Levin said the superintendent and school board must own risk‑management decisions and prioritize funding and governance; IT is responsible for carrying out the plan. "Sometimes the notion that it’s everyone’s job means it becomes no one’s job," Levin said.

On technical defenses, panelists recommended authentication and credential hygiene as foundational measures. Levin called identity "the perimeter" and recommended multi‑factor authentication (MFA) and monitoring for compromised credentials. Virani noted practical barriers—students often lack a second device for MFA—and described mitigations such as device‑based lists and contextual authentication. Both urged use of single sign‑on where appropriate and role‑based access to limit privileges.

Panelists urged robust asset and software inventories, including operational technology such as door controls and cameras. Levin warned that decentralized procurement in schools can leave IT unaware of devices and recommended periodic reviews, especially as products integrate new features (for example, AI capabilities) that can change privacy or security guarantees.

On backups and recovery, Levin recommended immutable and air‑gapped backups; Virani described the 3‑2‑1 model (three copies, two different media, one offsite) and urged districts to prioritize backing up the highest‑risk systems when budgets are limited. Both panelists stressed regularly testing recovery procedures so districts can meet recovery time and recovery point objectives without depending on a ransom payment.

Levin also warned that cloud or vendor‑hosted systems do not automatically guarantee adequate backups: "Do your due diligence to make sure your cloud vendors are backing up your data," he said, and recommended contract and procurement reviews and, when necessary, maintaining independent backups for critical systems.

For incident response, the speakers advised districts to define what constitutes an incident, who declares it, and in what order internal and external contacts should be notified (leadership, insurer, legal counsel and law enforcement where appropriate). They emphasized preserving evidence, scoping the compromise, agreeing on restoration priorities between IT and district leadership, and conducting lessons‑learned reviews after recovery.

Advanced practices discussed included continuous monitoring and automated response tools (often called SOAR), 24/7 coverage where feasible, and regular tabletop exercises and phishing drills that include non‑IT staff. Virani said simulation exercises help identify staff who need more training without stigmatizing them.

Levin highlighted a collaboration example in which K12 SIX coordinated outreach after an open‑source vulnerability (LogForge) affected many education products, enabling coordinated vendor patching. Virani described DCPS's partnership with the District's Office of the Chief Technology Officer (OCTO) to deploy phishing detection tools that significantly reduced phishing messages reaching staff inboxes.

Andrew Dominic closed by directing attendees to the Q&A tab for post‑event resources and announcing a forthcoming CISA Cybersecurity Resource Package for K‑12 schools. The session prioritized implementable, governance‑led steps—authentication, inventories, backups, vendor due diligence and practiced incident response—as immediate actions districts can take to reduce the risk and impact of cyber incidents.