Privacy & Security

Education Dept. Slow to Recognize Seriousness of Cyberattacks, GAO Watchdog Report Finds

By Alyson Klein — October 25, 2022 3 min read
 abstract digital key with technology interface, cybersecurity, key, lock, cellphone, fingerprint, and cloud computing icons
  • Save to favorites
  • Print

Cyberattacks on K-12 schools are becoming an increasingly serious problem, costing districts money and lost learning time. But the federal government, including the U.S. Department of Education, has largely dropped the ball on some key steps to help schools prevent, plan for, and deal with these attacks.

That’s the message of a report released Monday by the Government Accountability Office, Congress’ investigative arm. It’s the third report in as many years that points to the escalating nature of K-12 cyberattacks and the second in a row that criticizes the federal response. It comes on the heels of one of the most high-profile cyberattacks yet, on the Los Angeles Unified school district, the nation’s second largest.

Cyberattacks have cost districts anywhere from three days to three weeks in lost instructional time, while recovery times tend to range from two to nine months, the GAO reported. It’s tough to know the exact number of attacks that have occurred, because many aren’t publicly reported, the agency noted. (The K12 Security Information Exchange, or K12 SIX, found that there have been more than 1,330 publicly disclosed attacks since 2016, when the nonprofit first began tracking these incidents.)

The Education Department is supposed to be serving as a communications and collaboration hub among K-12 districts and federal agencies that work on cybersecurity, including the Cybersecurity Infrastructure Security Agency (CISA), GAO said. But right now, it’s falling down on the job, the watchdog reported.

“The biggest issue we found is that there needs to be better coordination between the federal-level and the actual K-12 organizations,” said David Hinchman, the acting director of the GAO’s information technology and cybersecurity team, in an interview with GAO’s podcast. “There’s very little actual direct interaction between the agencies or with the K-12 community.”

That disconnect, he said, may be happening in part because the Education Department hasn’t acted on federal guidelines that call for it to create a government coordinating council, to help the feds and school districts collaborate and share information on attacks.

The GAO formally recommended the department create the council or find another way to ensure there’s continuing coordination and communication among school districts and the feds on cybersecurity. In response, the Education Department told the GAO it had begun informal coordination with other agencies, to which the GAO reiterated its recommendation for a more formal approach.

What’s more, while the Education Department and CISA have some products and services aimed at helping schools with cybersecurity, neither agency measures the effectiveness of those resources, GAO said. That’s something the GAO recommended the agencies get started on, noting that “doing so would provide further input on the needs of the schools.” CISA agreed.

The Education Department, on the other hand, promised only to explore what kinds of metrics would be best for measuring the effectiveness of its cybersecurity resources.

Finally, the GAO wrote that the Education Department should figure out how to help districts cope with challenges like inadequate staff, limited funding, and difficulty getting cybersecurity insurance. The department said it would.

Reading between the lines of the report, Doug Levin, the national director of K12 SIX, was stunned by what he saw as the department’s lackadaisical response to a major K-12 threat.

“I think that we have had more than enough evidence that this issue is serious and that schools need support specifically targeted to their context, their unique circumstances,” he said. Despite multiple letters from members of Congress, K12 SIX’s reports, and more, he doesn’t “see any sense of urgency by the federal agencies who are best positioned to help. I just think that there is a leadership void here.”

Events

This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
Special Education Webinar
Hidden Costs of Special Ed Vacancies: Solutions for Your District
When provider vacancies hit, students feel it first. Hear what district leaders are doing to keep IEP-related services on track.
Content provided by Huddle Up
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
Privacy & Security Webinar
How Technology Is Reshaping Childhood
How do we protect kids online while embracing innovation? Learn about navigating safety, privacy, and opportunity in the Digital Age.
Content provided by Connect x Protect
Budget & Finance Webinar Creative Approaches to K-12 Budget Realities
What are districts prioritizing in 2026? New survey data reveals emerging K-12 budgeting trends.

EdWeek Top School Jobs

Teacher Jobs
Search over ten thousand teaching jobs nationwide — elementary, middle, high school and more.
View Jobs
Principal Jobs
Find hundreds of jobs for principals, assistant principals, and other school leadership roles.
View Jobs
Administrator Jobs
Over a thousand district-level jobs: superintendents, directors, more.
View Jobs
Support Staff Jobs
Search thousands of jobs, from paraprofessionals to counselors and more.
View Jobs

Read Next

Privacy & Security A Cyberattack on Canvas Could Cause Lasting Aftershocks for Schools
Data from millions of students might have been compromised.
Concept image of security breach, system hacked alert with red broken padlock icon showing vulnerable access.
Nicolas Herrbach/iStock/Getty
Privacy & Security A Potential Breach of an Anonymous Tip App Could Have Exposed Sensitive Student Data
The breach may have exposed personal information of students attending more than 30,000 schools.
A person types on a laptop, in Miami. Reuters reports that the hacker, using the name Internet Yiff Machine, said in a statement that they hacked and shared the data to expose that the confidential tips people submit through Navigate360’s P3 Global Intel platform are neither secure nor anonymous. The breach may have exposed the personal information of students attending more than 30,000 schools in the United States.
Cybersecurity experts recommend that schools should take steps now to protect student data as they wait for confirmation of a potential hack of Navigate360’s P3 Global Intel platform, which features a safety tip line.
Wilfredo Lee/AP
Privacy & Security How School Leaders Can Combat Rising Cyber Threats
Continuous training and student engagement can be key in protecting schools.
4 min read
Image with icons for "i" information, email, eye for "watch", and locks.
Collage via Canva
Privacy & Security From Our Research Center Is AI Ready to Protect Schools From Cyberattacks?
Some experts and district tech leaders are unsure what role the tech should play in cybersecurity.
6 min read
Illustration of woman defending school from monster with tentacles.
DigitalVision Vectors