for K-12 Cybersecurity
in the Age of AI
Based on feedback from 2,310 district technology leaders nationwide, this dashboard surfaces five cybersecurity realities — and the leadership questions that must follow. Explore through the lens of your role.
higher risk than ever
their #1 challenge
than a year ago
leaders surveyed
The same research means different things depending on where you sit in the district. Select a lens to see the findings most relevant to your role and responsibilities.
You know the threat landscape and the data reveals that the biggest barrier to effective cybersecurity isn't technical — it's organizational. Only 22% of your peers say district leadership strongly prioritizes cybersecurity. Meanwhile, 67% of district leaders name cyber threats as their #1 challenge. Closing that gap requires translating your technical knowledge into the language of your audience.
- Which of your leadership colleagues has the lowest cybersecurity awareness — and what language would resonate most with them?
- Does your district have a line item in the budget specifically for cybersecurity? (Only 43% do.)
- How would you describe the business cost of a cyberattack to your superintendent in terms they'd actually respond to?
- Is your cybersecurity training program reaching beyond the technology department to teachers and students?
- Map your district colleagues to impact messages: learning disruption for CAOs, reputational risk for comms officers, financial loss for CFOs
- Audit your training effectiveness by audience — only 15% of tech leaders rate teacher training as highly effective
- Build a districtwide cybersecurity ecosystem charter that assigns shared responsibility beyond IT
- Evaluate AI-powered cybersecurity detection tools as part of your next product or vendor review cycle
Your technology director is telling you this is urgent — and the data backs them up. Your engagement with cybersecurity, and that of your cabinet, directly determines whether your district invests appropriately, trains consistently, and responds effectively. The research is clear: districts with stronger leadership awareness have better protection outcomes.
- Does your district have a formal cybersecurity policy and procedures in place — and does every cabinet member know what it says?
- What would a 3-week school closure due to a ransomware attack mean for students in your district?
- Is cybersecurity a line item in your district's budget, or is it absorbed informally into the tech department's general fund?
- Have you participated in any cybersecurity professional development as a leader in the past year?
- Ask your CIO to brief the full cabinet on the district's current cyber risk exposure and preparedness — in plain language
- Add cybersecurity explicitly to the district's strategic planning agenda for 2025–26
- Commission a districtwide ecosystem review: who is responsible for what, and what gaps exist?
- Participate in at least one cybersecurity professional learning experience this year alongside your tech leadership team
Of all the district leaders assessed, CBOs and CFOs have the highest cybersecurity awareness — 47% are rated at a high level, up 10 points since 2022. That awareness has grown through your work procuring cyber insurance. But awareness without action leaves your district vulnerable. The financial exposure from a cyberattack — ransom payments, recovery costs, reputational damage, and bond measure risk — is significant and quantifiable.
- Does your district's cyber insurance policy cover the full range of current threats — including AI-enhanced phishing and ransomware?
- What is the estimated cost of 3 weeks of district closure — and does leadership understand that's a real cyber-attack outcome?
- Is there a dedicated cybersecurity line item in next year's budget, or is this function unfunded and invisible?
- What financial risk disclosures does the district have to its board around cybersecurity exposure?
- Work with your CIO to create a formal cybersecurity budget line item with year-over-year targets
- Review the district's current cyber insurance policy against the updated threat landscape, including AI-enabled attacks
- Translate the financial cost of a cyberattack into a format the superintendent and board can act on
- Advocate for cybersecurity funding at the cabinet level — your credibility on financial risk makes you uniquely effective here
School boards set policy, approve budgets, and are accountable to the community. Yet district technology leaders rate school boards as the lowest awareness group when it comes to cybersecurity risk — with 32% rated as having LOW awareness. In an era where a single ransomware attack can shut schools for weeks, that governance gap is a community trust and liability issue, not just a technical one.
- When did the board last receive a formal briefing on the district's cybersecurity posture, risks, and preparation?
- Does the district have a current, board-approved cybersecurity policy — and when was it last reviewed?
- Is cybersecurity explicitly funded in the district budget, or is it invisible in the technology department's general allocation?
- What is the board's liability exposure if a preventable cyberattack occurs and there was no documented oversight?
- Request a cybersecurity briefing from your district's CIO at the next board meeting — and make it a standing agenda item annually
- Review the district's current policies for cybersecurity, data privacy, and AI use — and identify gaps
- Champion explicit cybersecurity budget allocation in the next budget cycle
- Ask to receive a summary of incident response capabilities — does the district have a plan if attacked tomorrow?
More than half of district technology leaders say that students and teachers circumventing existing cybersecurity practices is a top obstacle — up from 22% to 49% in just three years. That's not a judgment of intent; it's a training failure. Only 15% of tech leaders say their teacher cybersecurity training is highly effective. And student training rates even lower. Cybersecurity is everyone's job — and schools are only as secure as their least-informed user.
- Do you know your school's policies for handling a suspected phishing email or data breach — and would you feel confident acting on them?
- Are students in your building using personal devices and consumer AI tools in ways that may bypass district security controls?
- When was the last time your school had a meaningful conversation about cybersecurity that included teachers and students — not just IT?
- What would you tell a parent who asked how your school protects their child's data?
- Ask your school's tech coordinator for a brief refresher on the most common current threats — especially AI-enhanced phishing
- Review what platforms and tools students are using for AI-assisted learning — and whether any fall outside district-managed systems
- Bring a short "digital safety" conversation into your next advisory, homeroom, or class meeting for students
- Request that cybersecurity training be part of your next professional development day — and advocate for it if it's not already planned
Select a question from the panel to explore findings from the 2025 Project Tomorrow National Research on K-12 Cybersecurity. Follow-up questions will appear after your first selection.