The Cybersecurity and Infrastructure Security Agency released the K-12 Cybersecurity Foundations Resource Package on August 12, 2026. The free collection includes a Getting Started Guide for school leaders, a more detailed Implementation Guide for district cyber leaders, a six-part video series, and quick-reference materials.
What the package covers
The guidance organizes essential cybersecurity practices around eight objectives: protecting login credentials, safeguarding devices and assets, testing backups, strengthening incident response capabilities, improving cybersecurity training, enacting policies to manage sensitive data, aligning investments with recognized cybersecurity frameworks, and developing long-term customized plans. The framework aligns with the NIST Cybersecurity Framework and advances Executive Order 14239 on state and local preparedness.
Scott Breor, acting executive assistant director for infrastructure security at CISA, said K-12 cybersecurity now extends beyond IT departments to become a core component of school safety. He said the package gives schools a practical tool to assess their current defenses and improve their cyber readiness.
Attack trends and costs
In the first half of 2026, there were 34 ransomware attacks targeting U.S. K-12 and higher education institutions, a 44 percent decline from 61 attacks in the second half of 2025, according to Comparitech. The U.S. accounted for 33 percent of 104 education-sector attacks recorded worldwide, more than any other country. Of those attacks, 36 were confirmed by targeted entities and 68 were unconfirmed. Nearly 693,000 records are known to have been breached in the confirmed attacks.
Federal context and local example
K-12 Dive reported that CISA and other federal cybersecurity resources have faced funding disruptions and staff cuts under the Trump administration, creating uncertainty around the level of federal support available to schools. CISA hosted a virtual training titled "Strengthening K-12 Cybersecurity: Simple Steps for Safer Schools" on May 28, 2026, indicating sustained federal engagement on K-12 cyber issues in the months preceding the August guidance release.
The Alamo Heights Independent School District in Texas reported that a March 2026 ransomware incident disrupted district technology systems for nearly a week and led to a data breach affecting 26,629 Texans. The Texas Office of the Attorney General published the district's breach entry on June 22, 2026, listing names, Social Security numbers, driver's license numbers, financial information, and medical information as compromised. The district confirmed it did not pay any ransom. The district's cyber insurance paid more than $36,000 to restore systems, and the FBI was notified, according to the San Antonio Express-News and GovTech Insider.
Evolution of federal guidance
The new resource package builds on CISA's earlier K-12 work. A 2023 report, "Protecting Our Future: Partnering to Safeguard K-12 Organizations from Cybersecurity Threats," offered three high-level recommendations: invest in the most impactful security measures, recognize and actively address resource constraints, and focus on collaboration and information sharing. CISA later released an Online Toolkit that aligned those recommendations with specific actions such as implementing multifactor authentication, prioritizing known exploited vulnerabilities, performing and testing backups, and developing incident response plans. The 2026 Foundations Resource Package translates the same principles into eight specific, actionable objectives with companion videos and quick-reference materials, representing a shift from strategic recommendations to operational guidance.
The State and Local Cybersecurity Grant Program, referenced in CISA's earlier toolkit, provides $1 billion over four years for state, local, and territorial governments, with education required as a member of each state's planning committee. Publicly funded K-12 schools are eligible for sub-awards, making this a key federal funding mechanism for school cybersecurity even as broader CISA resources face reported cuts.
Texas enacted Senate Bill 820 in 2019, mandating that school districts adopt cybersecurity policies and establish processes to report breaches to the Texas Education Agency. That state-level legislative approach to K-12 cyber preparedness predates and parallels federal guidance efforts, the San Antonio Express-News reported in its coverage of the Alamo Heights breach.
