School DecisionThe Newsroom
SATURDAY, SEPTEMBER 5, 2026
Beyond the headline
SCHOOLDECISION.COM/NEWSROOM
National · Policy & Funding

CISA releases free K-12 cybersecurity guidance as ransomware attacks evolve and federal resources face cuts

The new resource package, released August 12, provides eight operational objectives for school districts. It arrives as education-sector ransomware attack frequency drops but ransom demands rise, and as CISA itself reports staff and funding disruptions.

U.S. education-sector ransomware attacks61H2 202534H1 2026
Original Research by SchoolDecision.com
Ransomware attacks on U.S. K-12 and higher education institutions dropped 44 percent from the second half of 2025 to the first half of 2026. [2]

The Cybersecurity and Infrastructure Security Agency released the K-12 Cybersecurity Foundations Resource Package on August 12, 2026. The free collection includes a Getting Started Guide for school leaders, a more detailed Implementation Guide for district cyber leaders, a six-part video series, and quick-reference materials.

What the package covers

The guidance organizes essential cybersecurity practices around eight objectives: protecting login credentials, safeguarding devices and assets, testing backups, strengthening incident response capabilities, improving cybersecurity training, enacting policies to manage sensitive data, aligning investments with recognized cybersecurity frameworks, and developing long-term customized plans. The framework aligns with the NIST Cybersecurity Framework and advances Executive Order 14239 on state and local preparedness.

Scott Breor, acting executive assistant director for infrastructure security at CISA, said K-12 cybersecurity now extends beyond IT departments to become a core component of school safety. He said the package gives schools a practical tool to assess their current defenses and improve their cyber readiness.

Attack trends and costs

In the first half of 2026, there were 34 ransomware attacks targeting U.S. K-12 and higher education institutions, a 44 percent decline from 61 attacks in the second half of 2025, according to Comparitech. The U.S. accounted for 33 percent of 104 education-sector attacks recorded worldwide, more than any other country. Of those attacks, 36 were confirmed by targeted entities and 68 were unconfirmed. Nearly 693,000 records are known to have been breached in the confirmed attacks.

Median ransom demand in education sector attacks worldwide$275KH2 2025$420.62KH1 2026
Original Research by SchoolDecision.com
The median ransom demand rose 53 percent from H2 2025 to H1 2026. [2]

Federal context and local example

K-12 Dive reported that CISA and other federal cybersecurity resources have faced funding disruptions and staff cuts under the Trump administration, creating uncertainty around the level of federal support available to schools. CISA hosted a virtual training titled "Strengthening K-12 Cybersecurity: Simple Steps for Safer Schools" on May 28, 2026, indicating sustained federal engagement on K-12 cyber issues in the months preceding the August guidance release.

26,629Individuals affected by a ransomware attack on Alamo Heights Independent School District in Texas in March 2026, according to the San Antonio Express-News. [4]

The Alamo Heights Independent School District in Texas reported that a March 2026 ransomware incident disrupted district technology systems for nearly a week and led to a data breach affecting 26,629 Texans. The Texas Office of the Attorney General published the district's breach entry on June 22, 2026, listing names, Social Security numbers, driver's license numbers, financial information, and medical information as compromised. The district confirmed it did not pay any ransom. The district's cyber insurance paid more than $36,000 to restore systems, and the FBI was notified, according to the San Antonio Express-News and GovTech Insider.

Evolution of federal guidance

The new resource package builds on CISA's earlier K-12 work. A 2023 report, "Protecting Our Future: Partnering to Safeguard K-12 Organizations from Cybersecurity Threats," offered three high-level recommendations: invest in the most impactful security measures, recognize and actively address resource constraints, and focus on collaboration and information sharing. CISA later released an Online Toolkit that aligned those recommendations with specific actions such as implementing multifactor authentication, prioritizing known exploited vulnerabilities, performing and testing backups, and developing incident response plans. The 2026 Foundations Resource Package translates the same principles into eight specific, actionable objectives with companion videos and quick-reference materials, representing a shift from strategic recommendations to operational guidance.

The State and Local Cybersecurity Grant Program, referenced in CISA's earlier toolkit, provides $1 billion over four years for state, local, and territorial governments, with education required as a member of each state's planning committee. Publicly funded K-12 schools are eligible for sub-awards, making this a key federal funding mechanism for school cybersecurity even as broader CISA resources face reported cuts.

Texas enacted Senate Bill 820 in 2019, mandating that school districts adopt cybersecurity policies and establish processes to report breaches to the Texas Education Agency. That state-level legislative approach to K-12 cyber preparedness predates and parallels federal guidance efforts, the San Antonio Express-News reported in its coverage of the Alamo Heights breach.

Analysis

By the School Decision Newsroom, written after the reporting above was filed.

The grant money schools need to act on this guidance has been spent down to a trickle.

The article calls the State and Local Cybersecurity Grant Program a key federal funding mechanism for school cybersecurity. That program's original $1 billion from the 2021 infrastructure law is largely spent, with only $91.7 million awarded in FY2025. Congress reauthorized the program through 2033 via the PILLAR Act but has not appropriated new money. CISA is handing schools a free checklist because the grants that would let them act on it are running dry, and the administration's stated position is that cybersecurity belongs at the state and local level.

CISA is releasing K-12 guidance while cutting the staff that would help schools use it.

CISA has lost roughly a third of its workforce, about 1,000 positions, since the start of 2025. Its stakeholder engagement division, the office that works directly with state and local governments including school districts, was cut from 200 positions to 53. The Trump administration's budget documents say CISA should refocus on federal network defense rather than external engagement. The same agency publishing eight operational objectives for schools is simultaneously being stripped of the personnel who would walk districts through them.

Fewer attacks, but each one costs a district more than $2 million to clean up.

The 44 percent drop in attack frequency pairs with a 53 percent rise in median ransom demands to $420,620. Sophos reported K-12 average recovery costs at $2.28 million per incident in 2025, the highest of any sector surveyed. For context, Alamo Heights ISD's cyber insurance paid $36,000 to restore systems, but Providence Schools spent nearly $500,000 recovering from a similar breach. When a district gets hit, the bill runs from hundreds of thousands to millions, and the disruption to learning can last weeks.

Sources

  1. CISA. CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts View
  2. Comparitech. Education Ransomware Roundup: H1 2026 stats on attacks, ransoms, and data breaches View
  3. K-12 Dive. CISA issues K-12 cybersecurity guidance as schools' risks persist View
  4. San Antonio Express-News. 26,000 people affected in Alamo Heights ISD data breach View
  5. GovTech Insider. Alamo Heights ISD Data Breach Affected Nearly 30K View
  6. CISA. Protecting Our Future: Cybersecurity for K-12 View
  7. CISA. Online Toolkit: Partnering to Safeguard K-12 Organizations from Cybersecurity Threats View
  8. CISA. Strengthening K-12 Cybersecurity: Simple Steps for Safer Schools View
  9. StateTech Magazine. Congress Revives State and Local Cyber Grants, But Funding Remains Unclear View
  10. GovTech. Homeland Security Funding Bill Passed, Includes Money for CISA View
  11. Federal News Network. DHS budget request would cut CISA staff by 1,000 positions View
  12. K-12 Dive. Schools are getting better at navigating ransomware attacks, Sophos finds View
  13. WJAR / Turn to 10. Providence Schools data breach to cost hundreds of thousands of dollars View
CISA releases free K-12 cybersecurity guidance as ransomware attacks evolve and federal resources face cuts | School Decision