A Maddux Group publication · Est. 2026Public · Charter · Private
The Maddux Report

Technology operations for small and mid-sized schools

Security

Cybersecurity if you are a two-person team: a 90-day plan

Sept 7, 2026 · Working briefing · Not an incident-response retainer

CoSN’s State of EdTech surveys keep putting cybersecurity at the top of the list. That is not a surprise. What is a surprise is how much of the published advice assumes a security analyst, a SIEM, and a change-control board. A 1,400-student district does not have those. It has a director, maybe a tech, and a superintendent who will ask whether the district is “covered.”

You will not become a SOC in 90 days. You can close the paths that actually knock K–12 systems offline: stolen passwords, unpaid-attention backups, unpatched edge devices, and a vendor that stores student data with no review.

Use free starting points and then do the work in order. CISA maintains a K–12 protection toolkit. K12 SIX publishes Essential Cybersecurity Protections and a district self-assessment written by practitioners. CoSN maintains a cybersecurity toolkit and a Community Vendor Assessment Tool. Membership in K12 SIX is priced by enrollment — $1,000 at under 2,500 students — if you want the ISAC feed later. Do not wait on membership to start.

Days 1–30: stop the easy account takeover

  1. Inventory the identity plane. Google Workspace, Microsoft 365, SIS, payroll, banking, MDM, filtering, and the firewall admin page. If it can reset a password or export a roster, it is in scope.
  2. MFA on staff first, then vendors who have admin. Start with email and SIS. Student MFA can wait unless you have a specific threat. Phishing-resistant methods beat SMS. If SMS is all you can ship this month, ship it and schedule the upgrade.
  3. Kill shared admin accounts. One named person, one admin role, a break-glass account in a sealed envelope or password manager vault the superintendent can reach.
  4. Turn on official alert mailboxes. Registrar notices, Google/Microsoft security alerts, and filter quarantine should not land only in a personal inbox that vanishes when someone leaves.
  5. Write a one-page “who to call.” ISP, firewall VAR, insurance carrier, regional FBI or CISA contact, superintendent, and the person who can shut off email. Tape it inside the closet and put a copy in the vault.

Days 31–60: make backup a restore test, not a checkbox

  1. 3-2-1 in language a board member can repeat. Three copies, two different media or locations, one offline or immutable. SIS, financial system, student files, and the identity directory matter more than the file share of 2014 field-day photos.
  2. Restore something real. Pick one Chromebook image, one SIS table or export, and one file share folder. Time it. Write the time on the board slide. Untested backup is press-release backup.
  3. Patch the edge. Firewall, VPN concentrator, and any appliance with a public UI. These are the boxes ransomware crews scan. If a device is out of support, it is a project, not a finding you stare at.
  4. Mail filtering with a human loop. Impersonation of the superintendent and payroll change requests still work. Give bookkeepers a callback rule: no banking or W-2 changes from email alone.

Days 61–90: vendors, logging you will actually read, paper

  1. List every app that sees student data. Roster sync is the tell. If it gets SIS data, it gets a review. Use CoSN’s Community Vendor Assessment Tool or K12 SIX’s vendor-risk note as the questionnaire. You do not need a legal novel. You need: where data lives, who can subcontract, breach timeline, and how you offboard.
  2. Turn on the logs you will look at. Admin audit logs in Google or Microsoft, firewall allow/deny for VPN, and MDM compliance. A SIEM you never open is a subscription, not a control.
  3. Tabletop for 45 minutes. “Email is encrypted and the SIS is down on a Monday of state testing.” Walk the one-pager. Fix the holes the exercise reveals. K12 SIX publishes an incident-response runbook written for schools; steal structure, do not photocopy a hospital playbook.
  4. Tell the board what is done and what is not. Three slides: controls in place, top three gaps, dollars or time required. Superintendents fund what they can repeat in public.

What to refuse in year one

If you only do five things

  1. MFA on staff email and SIS.
  2. Named admins, no shared passwords on the firewall.
  3. Offline or immutable backup of SIS and identity, with one restore test.
  4. Edge devices on a supported OS.
  5. A printed call tree.

That list will not impress a conference panel. It will change the outcome of the incident you are statistically more likely to have.