School just started back, and you’re already drowning.
Hot take… cybersecurity is not waiting for things to settle down.
So here is the most useful part of this post upfront.
We have pulled together two new CISA guides, the transcript of our conversation with a dedicated school district Data Protection Officer, and a prompt that can turn all three resources into a practical action plan for your district.
If you are already working with an AI that knows your schools, staff, systems and constraints, give it the three PDFs. Then give it our district-specific prompt.
It will assess your district against CISA’s recommendations, identify five priorities, assign likely owners and build a 90-day plan.
We think this is more useful than asking AI to summarize 80 pages of federal guidance.
The downloads and prompt are at the bottom.
First, here is why the resources are worth using.
Most cybersecurity guidance has one big problem. It assumes you have plenty of people, money and time. Most school districts have none of those to spare.
CISA’s new K-12 Cybersecurity Foundations resource package actually does understand that.
It was built for schools with limited staff, limited cybersecurity expertise or both.
No federal guide is going to secure your district for you. But this package does something useful: it tells you where to start, then gives you a path forward when you are ready to go deeper.
The 23-page Getting Started Guide focuses on four things.
Protect student and staff login credentials. Safeguard devices and other technology assets. Perform, verify and test your backups. Establish an incident response capability and practice it.
That is a sensible starting point.
The language around backups is especially important. Having a backup is not the same as knowing you can recover from it. If nobody has tested a full restoration, you do not have a recovery plan. You have a hope.
The same is true for incident response. A plan sitting in a shared drive will not do much good if the network is unavailable, nobody knows who is supposed to call whom, and the superintendent is standing in your office asking for an update.
CISA recommends keeping a physical copy of the plan and exercising it regularly. We agree!
The 57-page Implementation Guide is for districts ready to turn those first steps into an actual program.
It breaks the work into specific practices, identifies who needs to be involved and calls out the problems districts are likely to run into. It also separates quicker fixes from work that will require more time, money and coordination.
The guide expands beyond credentials, devices, backups and incident response. It covers staff training, sensitive data, cybersecurity leadership and long-term planning using the NIST Cybersecurity Framework.
And it gets one important thing right.
Cybersecurity cannot belong only to IT.
Human Resources has a role when staff accounts need to be removed. Data owners need to know what sensitive information the district collects and where it lives. Administrators need to approve plans and budgets. Physical security needs a seat at the table when an incident could affect intercoms, door controls, cameras or other building systems.
Someone still has to own the work.
That is what makes our conversation with Michelle Krieger, Lake Shore Central School District’s dedicated Data Protection Officer, worth watching.
Michelle stepped into the role in 2023 with a focused responsibility for data protection. In the interview, she talks about what that focus changed for the district and why schools need to prepare before a data incident forces the issue.
Not every district can add a full-time Data Protection Officer. Most cannot.
But every district can name the person responsible for decisions about sensitive data, staff training, vendor agreements and breach response. When ownership belongs vaguely to everyone, it usually belongs to no one.
If your district’s cybersecurity work has stalled because the list feels too long, begin with the Getting Started Guide. Use the Implementation Guide when you are ready to assign owners and build a work plan.
But I would actually start with Michelle’s interview. It shows what dedicated ownership looks like inside a real school district.
Make the three resources work for your district
Are you an IT director working with an AI that already knows your schools?
Give it the podcast transcript and both CISA guides. Then use our prompt to turn the information into district-specific next steps.
Download:
- The podcast transcript
- CISA’s 23-page Getting Started Guide
- CISA’s 57-page Implementation Guide
Upload all three resources to your AI. Then give it this district-specific cybersecurity action-plan prompt.
The prompt tells your AI to separate facts from assumptions, assess your district against CISA’s eight objectives and choose the five actions that would reduce the most risk. It also asks for likely owners, cost and effort estimates, proof of completion, and a practical 30-, 60- and 90-day plan.
Review the result. Correct what the AI does not know!
Please DON’T NOT PROOFREAD THIS! We all know AI is useful and makes mistakes!
Then take the plan to your superintendent, safety committee or governance team.
You will still have to do the work!
But at least you will know where to start.