The Leadership Imperatives
for K-12 Cybersecurity
in the Age of AI

Based on feedback from 2,310 district technology leaders nationwide, this dashboard surfaces five cybersecurity realities — and the leadership questions that must follow. Explore through the lens of your role.

88%
believe K-12 is at
higher risk than ever
67%
say cyber threats are
their #1 challenge
65%
more concerned today
than a year ago
2,310
district technology
leaders surveyed
Urgency Is Rising Fast
District leaders cite AI-powered attacks, national reporting, and peer districts getting hit as the top drivers of their heightened alarm.
65% more concerned than last year
The Message Isn't Landing
Only 22% of district leaders strongly agree cybersecurity is a high priority — because most colleagues still don't speak the language of cyber risk.
Only 22% strong buy-in
A Shared-Responsibility Gap
Progress is being made — cybersecurity "owned by IT only" dropped from 67% to 56% — but district-wide ecosystem thinking is still the exception, not the rule.
56% still IT-only ownership
Explore Through Your Lens

The same research means different things depending on where you sit in the district. Select a lens to see the findings most relevant to your role and responsibilities.

CIO / CTO / Tech Director
Leading district cybersecurity strategy, infrastructure, and implementation
Explore findings →
Superintendent / Cabinet
Setting district vision and prioritizing where resources go
Explore findings →
Business / Finance Officer
Managing fiscal risk, insurance, and budget allocation for security
Explore findings →
School Board Member
Providing governance, policy oversight, and community accountability
Explore findings →
Teacher / School Principal
Understanding your role as a frontline actor in district cybersecurity
Explore findings →
1. Greater awareness of cybersecurity implications drives an increased sense of urgency to protect district assets and infrastructure.
2. Explaining the value proposition of effective cybersecurity preparations is more effective when the message is in the same language as the receiving audience.
3. K-12 cybersecurity demands root cause analysis — not just treating symptoms — to create more successful strategies for asset protection.
4. Effective cybersecurity preparation and response require a districtwide ecosystem approach.
5. Embracing AI as both an opportunity and a threat in K-12 education unlocks new discussions about effective cybersecurity.
CIO / CTO / Technology Director — "How do we protect our district while enabling learning?"
Your Colleagues Don't Share Your Sense of Urgency—That's the Real Security Vulnerability

You know the threat landscape and the data reveals that the biggest barrier to effective cybersecurity isn't technical — it's organizational. Only 22% of your peers say district leadership strongly prioritizes cybersecurity. Meanwhile, 67% of district leaders name cyber threats as their #1 challenge. Closing that gap requires translating your technical knowledge into the language of your audience.

Key Takeaways
1
65% of district tech leaders are more concerned about a cyberattack than they were a year ago — and AI-powered threats are a primary driver of that shift
Report p.3, Table 1 — Factors contributing to higher cyberattack concern
2
Cybersecurity "owned primarily by IT" dropped from 67% to 56% since 2022 — ecosystem thinking is gaining traction, but leadership buy-in is still the #1 unmet need
Report p.9 — Reality #4, district ecosystem findings
3
53% of district tech leaders view AI as both a threat AND an opportunity — the dual-use reality demands proactive strategy, not just defensive posture
Report p.11 — Reality #5, AI threat/opportunity perspectives
Data Highlights
88%
of district technology leaders say K-12 schools are at a higher risk for cyberattack than ever before
69%
of tech leaders say increased cybersecurity funding is their top internal need in 2025 — up from 39% in 2022
66%
of districts now have a cyber insurance policy — up from just 23% in 2022
Charts & Data
Why Are Tech Leaders More Concerned About Cyberattacks Today?
Steps Taken to Reduce District Cyber Vulnerability (% in place now)
Planning & Action
Questions for Planning
  • Which of your leadership colleagues has the lowest cybersecurity awareness — and what language would resonate most with them?
  • Does your district have a line item in the budget specifically for cybersecurity? (Only 43% do.)
  • How would you describe the business cost of a cyberattack to your superintendent in terms they'd actually respond to?
  • Is your cybersecurity training program reaching beyond the technology department to teachers and students?
Action Items
  • Map your district colleagues to impact messages: learning disruption for CAOs, reputational risk for comms officers, financial loss for CFOs
  • Audit your training effectiveness by audience — only 15% of tech leaders rate teacher training as highly effective
  • Build a districtwide cybersecurity ecosystem charter that assigns shared responsibility beyond IT
  • Evaluate AI-powered cybersecurity detection tools as part of your next product or vendor review cycle
Superintendent / Cabinet — "How do we lead our district through a cybersecurity era defined by AI?"
Cybersecurity Is No Longer an IT Problem—It's a District Leadership Imperative

Your technology director is telling you this is urgent — and the data backs them up. Your engagement with cybersecurity, and that of your cabinet, directly determines whether your district invests appropriately, trains consistently, and responds effectively. The research is clear: districts with stronger leadership awareness have better protection outcomes.

Key Takeaways
1
Only 39% of superintendents are seen as having a HIGH level of cybersecurity awareness by their district technology leaders — below the CBO/CFO and well behind what's needed
Report p.5, Table 3 — Colleague awareness ratings by role
2
A cyberattack can result in 3 days to 3 weeks of lost learning time — making this a student outcomes issue, not just an IT issue
Report p.4, citing 2022 U.S. Government Accountability Office report
3
52% of district tech leaders need professional learning for district leadership on cybersecurity — nearly double the 27% who said the same in 2022
Report p.10, Table 6 — Needs to improve cybersecurity posture
Data Highlights
Only 22%
of district leaders strongly agree that cybersecurity has been made a high-level district priority this year
42%
of tech leaders say "school and district leadership don't understand the potential of cyberattacks" — up from 27% in 2022
55%
of district leaders identify establishing Generative AI policies as their #2 most important challenge — directly linked to cybersecurity
Charts & Data
Colleague Cybersecurity Awareness Levels (as rated by tech leaders)
Most Consequential Negative Impacts of a Cyberattack
Planning & Action
Questions for Planning
  • Does your district have a formal cybersecurity policy and procedures in place — and does every cabinet member know what it says?
  • What would a 3-week school closure due to a ransomware attack mean for students in your district?
  • Is cybersecurity a line item in your district's budget, or is it absorbed informally into the tech department's general fund?
  • Have you participated in any cybersecurity professional development as a leader in the past year?
Action Items
  • Ask your CIO to brief the full cabinet on the district's current cyber risk exposure and preparedness — in plain language
  • Add cybersecurity explicitly to the district's strategic planning agenda for 2025–26
  • Commission a districtwide ecosystem review: who is responsible for what, and what gaps exist?
  • Participate in at least one cybersecurity professional learning experience this year alongside your tech leadership team
Chief Business / Finance Officer — "What is the real financial risk of a cyberattack — and how do we budget for it?"
You Are the Most Cyber-Aware Member of Cabinet—And That Advantage Needs to Become Action

Of all the district leaders assessed, CBOs and CFOs have the highest cybersecurity awareness — 47% are rated at a high level, up 10 points since 2022. That awareness has grown through your work procuring cyber insurance. But awareness without action leaves your district vulnerable. The financial exposure from a cyberattack — ransom payments, recovery costs, reputational damage, and bond measure risk — is significant and quantifiable.

Key Takeaways
1
66% of districts now have a cyber insurance policy — up from just 23% in 2022 — driven in large part by CBO/CFO involvement in procurement and risk discussions
Report p.6, Table 4 — Steps taken to reduce district vulnerability
2
Only 43% of district technology leaders report having a dedicated cybersecurity budget line item — 41% say they do not, leaving real risk uncovered
Report p.8 — Reality #3, budget findings
3
69% of district tech leaders cite increased cybersecurity funding as their top internal need in 2025 — dramatically up from 39% in 2022
Report p.10, Table 6 — Needs to improve cybersecurity posture
Data Highlights
47%
of tech leaders rate the CBO/CFO as having a HIGH level of cybersecurity awareness — the highest of any district leadership role
42%
of district leaders cite financial impacts — including potential ransom or data recovery costs — as a major consequence of a cyberattack
43%
of tech leaders cite negative district PR — including loss of community trust ahead of bond measures — as a top attack consequence
Charts & Data
Cybersecurity Insurance & Vulnerability Reduction: Steps in Place
Internal Needs for Improved Cybersecurity Posture: 2022 vs. 2025
Planning & Action
Questions for Planning
  • Does your district's cyber insurance policy cover the full range of current threats — including AI-enhanced phishing and ransomware?
  • What is the estimated cost of 3 weeks of district closure — and does leadership understand that's a real cyber-attack outcome?
  • Is there a dedicated cybersecurity line item in next year's budget, or is this function unfunded and invisible?
  • What financial risk disclosures does the district have to its board around cybersecurity exposure?
Action Items
  • Work with your CIO to create a formal cybersecurity budget line item with year-over-year targets
  • Review the district's current cyber insurance policy against the updated threat landscape, including AI-enabled attacks
  • Translate the financial cost of a cyberattack into a format the superintendent and board can act on
  • Advocate for cybersecurity funding at the cabinet level — your credibility on financial risk makes you uniquely effective here
School Board Member — "What is our governance responsibility for district cybersecurity?"
Only 18% of School Boards Are Seen as Highly Aware of Cyber Risk—And That Gap Has Consequences

School boards set policy, approve budgets, and are accountable to the community. Yet district technology leaders rate school boards as the lowest awareness group when it comes to cybersecurity risk — with 32% rated as having LOW awareness. In an era where a single ransomware attack can shut schools for weeks, that governance gap is a community trust and liability issue, not just a technical one.

Key Takeaways
1
Only 18% of school boards are rated as having HIGH cybersecurity awareness — the lowest of any district leadership group — and 32% are rated LOW
Report p.5, Table 3 — Colleague awareness levels by role
2
A cyberattack can result in 3 days to 3 weeks of lost student learning — a board-level student outcomes risk that demands policy-level attention
Report p.4, citing U.S. GAO 2022 report
3
Only 22% of districts have strong leadership-level agreement that cybersecurity is a top priority — boards can change that by making it an explicit agenda item
Report p.5 — District priority-setting findings
Data Highlights
32%
of school boards are rated as having LOW cybersecurity awareness by the district's own technology leaders
43%
of tech leaders cite negative district PR and loss of community trust as a top consequence of a cyberattack
Only 43%
of districts have a dedicated cybersecurity budget line item — without board advocacy, that won't change
Charts & Data
School Board Cybersecurity Awareness vs. Other District Leadership Roles
Obstacles to Cybersecurity Efficacy: 2022 vs. 2025 (% of tech leaders)
Planning & Action
Questions for Planning
  • When did the board last receive a formal briefing on the district's cybersecurity posture, risks, and preparation?
  • Does the district have a current, board-approved cybersecurity policy — and when was it last reviewed?
  • Is cybersecurity explicitly funded in the district budget, or is it invisible in the technology department's general allocation?
  • What is the board's liability exposure if a preventable cyberattack occurs and there was no documented oversight?
Action Items
  • Request a cybersecurity briefing from your district's CIO at the next board meeting — and make it a standing agenda item annually
  • Review the district's current policies for cybersecurity, data privacy, and AI use — and identify gaps
  • Champion explicit cybersecurity budget allocation in the next budget cycle
  • Ask to receive a summary of incident response capabilities — does the district have a plan if attacked tomorrow?
Teacher / School Principal — "What does cybersecurity actually have to do with me?"
Teachers and Students Are the Most Common Point of Entry for Attacks—And the Least Prepared

More than half of district technology leaders say that students and teachers circumventing existing cybersecurity practices is a top obstacle — up from 22% to 49% in just three years. That's not a judgment of intent; it's a training failure. Only 15% of tech leaders say their teacher cybersecurity training is highly effective. And student training rates even lower. Cybersecurity is everyone's job — and schools are only as secure as their least-informed user.

Key Takeaways
1
Only 15% of district tech leaders say their cybersecurity training for teachers is highly effective — and student training rates even lower at just 8%
Report p.4, Table 2 — Training effectiveness by audience
2
Students and teachers circumventing cybersecurity practices jumped from a concern for 22% to 49% of tech leaders between 2022 and 2025 — the steepest increase of any obstacle
Report p.8, Table 5 — Obstacles to cybersecurity efficacy
3
64% of parents say their top concern about AI in education is whether schools are adequately storing and protecting their children's data — teachers and principals are on the front line of that trust
Report p.4 — Parent data privacy concerns
Data Highlights
15%
of district tech leaders rate their cybersecurity training for teachers as "highly effective" — the second-lowest rating of any group
49%
of tech leaders cite teachers and students circumventing security practices as a top obstacle — up from 22% in 2022
54%
of district leaders identify learning disruption — including lost school days — as a top consequence of a cyberattack
Charts & Data
Cybersecurity Training Effectiveness by Audience (% highly effective)
Top Obstacles to Cybersecurity Efficacy: 2022 vs. 2025
Planning & Action
Questions for Planning
  • Do you know your school's policies for handling a suspected phishing email or data breach — and would you feel confident acting on them?
  • Are students in your building using personal devices and consumer AI tools in ways that may bypass district security controls?
  • When was the last time your school had a meaningful conversation about cybersecurity that included teachers and students — not just IT?
  • What would you tell a parent who asked how your school protects their child's data?
Action Items
  • Ask your school's tech coordinator for a brief refresher on the most common current threats — especially AI-enhanced phishing
  • Review what platforms and tools students are using for AI-assisted learning — and whether any fall outside district-managed systems
  • Bring a short "digital safety" conversation into your next advisory, homeroom, or class meeting for students
  • Request that cybersecurity training be part of your next professional development day — and advocate for it if it's not already planned
Explore Key Questions — Cybersecurity Leadership in the Age of AI
Five Leadership Imperatives—Explored Through the Research

Select a question from the panel to explore findings from the 2025 Project Tomorrow National Research on K-12 Cybersecurity. Follow-up questions will appear after your first selection.

Explore further
AI
Select one of the questions in the panel to begin exploring findings from the 2025 Project Tomorrow National Research on K-12 Cybersecurity. Follow-up questions will appear after your first selection.