Privacy & Security

Cyberattacks Are Up. The Feds Must Help Schools Cope, Watchdog Agency Says

By Alyson Klein — November 17, 2021 2 min read
Gloved hand reaching into a laptop screen hacking someone's account.
  • Save to favorites
  • Print

The U.S. Department of Education’s more-than-a-decade old plan to help protect schools from digital threats needs a rethink, as cyberattacks rise and new threats emerge, concludes the Government Accountability Office, Congress’ watchdog arm, in a report out this month.

Since 2010, when the plan was last updated, K-12 schools have dramatically ramped up their use of education technology, leaving their systems more vulnerable to threats. That’s been particularly true during the COVID-19 pandemic, which forced schools to switch over to online learning at lightning speed.

“The efforts that the schools had to go through last year to convert from in-person to virtual learning put a lot of strain and stress on the technology services that they either had or they needed to acquire very quickly,” said Nick Marinos, a director on the GAO’s Information Technology and Cybersecurity team in an interview with Watchdog Report, the GAO’s podcast. “In other cases where we’ve seen entities have to rush to put forward technology, cybersecurity often can be an afterthought or something that might not get attention until, unfortunately, an attack or an incident occurs.”

These attacks can carry a high price tag. Marinos cited a school district in Florida that was targeted by a criminal group in March. The group encrypted the district’s data and demanded a $40 million ransom to decrypt it. And back in 2019, a Kentucky school district got a fraudulent email that appeared to be from a vendor. The school ended up paying a $3.7 million invoice which went directly to an attacker.

All-in-all, 408 attacks were publicly reported in 2020, an 18 percent increase over the previous year, according to data from the Cybersecurity Resource Center that was cited in the report.

The department has taken some steps to help schools get their arms around these threats, GAO reported. The agency published guidance to help students and parents prepare for a cyberattack. It also put out guidance for schools on best practices in online learning. And it has provided schools with some resources, including training drills that have already been successful in other districts.

But “even though federal agencies do already provide a variety of products and services to help schools protect themselves against cyber threats, it’s time for them to ensure that these efforts meet current needs,” Marinos said.

Specifically, the report asks the Education Department to consult with the Department of Homeland Security’s Cybersecurity and Infrastructure Agency (CISA) to figure out how to update its plan for K-12 schools. And the GAO called for the Education Department to consider whether additional guidance is needed to protect teachers, parents, and students from cyberthreats.

The Education Department, which reviewed the report before it was published, agreed with the GAO’s recommendations, but expressed some concerns about its lack of authority over security standards for school districts.

Events

This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
Artificial Intelligence Webinar
Managing AI in Schools: Practical Strategies for Districts
How should districts govern AI in schools? Learn practical strategies for policies, safety, transparency, as well as responsible adoption.
Content provided by Lightspeed Systems
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
Reading & Literacy Webinar
Unlocking Success for Struggling Adolescent Readers
The Science of Reading transformed K-3 literacy. Now it's time to extend that focus to students in grades 6 through 12.
Content provided by STARI
Jobs Virtual Career Fair for Teachers and K-12 Staff
Find teaching jobs and K-12 education jubs at the EdWeek Top School Jobs virtual career fair.

EdWeek Top School Jobs

Teacher Jobs
Search over ten thousand teaching jobs nationwide — elementary, middle, high school and more.
View Jobs
Principal Jobs
Find hundreds of jobs for principals, assistant principals, and other school leadership roles.
View Jobs
Administrator Jobs
Over a thousand district-level jobs: superintendents, directors, more.
View Jobs
Support Staff Jobs
Search thousands of jobs, from paraprofessionals to counselors and more.
View Jobs

Read Next

Privacy & Security PowerSchool Paid a Hacker's Ransom. Now Cyber Criminals Are Threatening Schools
More extortion attempts are possible, and districts affected by the data breach should be prepared.
The New York Stock Exchange is decorated on July 28, 2021 for the first day of public trading of the cloud-based educational software maker, PowerSchool.
The New York Stock Exchange is decorated on July 28, 2021, on the first day of public trading of the cloud-based educational software maker, PowerSchool.
Richard B. Levine/Alamy
Privacy & Security 4 Things to Know About School Cybersecurity and Trump Funding Cuts
Schools stand to lose significant cybersecurity support as the Trump administration and DOGE slash and rearrange the federal government.
uturistic digital technological background with hexagonal elements, yellow glowing warning signs and binary code. Encryption your data. Big data security. Safe your data. Cyber internet security and privacy concept.
iStock/Getty
Privacy & Security Could Trump Budget Cuts Lead to More Cyberattacks Against Schools?
Schools stand to lose vital cybersecurity support as the Education Department is forced to suspend a cybersecurity initiative.
Illustration of setting computer security settings. Vector illustration of computer privacy management.
iStock/Getty
Privacy & Security Schools Face an Uphill Battle in Protecting Student Data in the Age of AI
A report from the Consortium for School Networking examines the state of districts' student data privacy practices.
3 min read
Blue Illustration of an open laptop displaying a badge and lock icon.
iStock/Getty