Skip to main content

Cybersecurity Best Practices for Schools

Woman at a computer with a lock graphic on her screen


Over time, schools have become increasingly dependent on technology, prompting the use of devices in the classroom to evolve. Computer labs were once where students would go to access technology. Now, they use personal take-home tablets and laptops, adding flexibility in learning but requiring new protocols.  

Beyond using technology for learning, administrators manage student records digitally and staff communicate through email and cloud applications. This constant flow of information throughout the day creates a breeding ground for cybersecurity risks.

No longer an issue that belongs exclusively to a school district's IT department, modern cybersecurity requires administrators, faculty, staff and students to play a role in protecting school networks and sensitive information. 

Rutgers Alternate Route teacher Dr. Tammy Bowling-Jenkins knows firsthand. 

In April 2021, while serving as a school principal in Hillsborough Township Public Schools, Dr. Bowling-Jenkins experienced the impact of a districtwide ransomware attack. The incident disrupted district systems and required a coordinated response involving district leadership, technology professionals, cybersecurity experts and law enforcement.

“It happened during an already challenging time for schools, as we were still navigating the impact of the COVID-19 pandemic, she said. “Suddenly, we were dealing with another disruption that affected systems we relied upon every day.”
 

When a cyberattack happens at home

 

Headshot of Dr. Tammy Bowling-Jenkins


Through this experience, Dr. Bowling-Jenkins and her school learned the importance of each cybersecurity measure in place and each person doing their part to protect the school’s digital safety. The district’s technology team worked with the appropriate authorities and cybersecurity professionals to secure the systems, assess the situation and begin recovery efforts.

As principal, Dr. Bowling-Jenkins received district protocols and communicated them to staff and families. Passwords were reset, additional security measures were implemented and staff cybersecurity training was increased.

“What struck me most was how quickly cybersecurity became everyone’s responsibility,” Dr. Bowling-Jenkins said. “The technology department certainly led the technical response, but administrators, teachers and staff all had a part to play in helping our district recover and strengthening our practices moving forward.”

The breach did come with a silver lining. It prompted Dr. Bowling-Jenkins and her staff to rethink their cybersecurity habits and adopt stronger practices, ultimately creating a safer environment for all.

“I became more intentional about password security, multi-factor authentication, emails, links and the information I share electronically,” she said. “I also became much more likely to stop and question something before clicking or responding.”

Dr. Bowling-Jenkins also approached her leadership with a new perspective.

“As a school leader, it also changed the way I viewed cybersecurity training. It wasn’t simply another required training or compliance activity. I understood firsthand why those safeguards were necessary and how one action can potentially impact an entire organization.

Now that the experience is behind her, Dr. Bowling-Jenkins has tips for fellow educators.
 

Start with the basics

“Be cautious about unexpected links and attachments, even when something appears to come from someone you know. If something doesn’t look or feel right, verify it before responding or clicking.”
 

Use strong passwords and multi-factor authentication whenever possible

Dr. Bowling-Jenkins believes it is critical to “make cybersecurity part of your school culture rather than something discussed only during an annual training.”
 

Provide ongoing education

“Short reminders throughout the year, phishing-awareness exercises and conversations during staff meetings can help keep cybersecurity at the forefront. Educators and school leaders can also take advantage of resources from organizations such as the Cybersecurity and Infrastructure Security Agency (CISA).”
 

Create a culture that encourages questions

“I’d much rather have a staff member say, ‘This email doesn’t look right. Can someone check it?’ and have it turn out to be legitimate rather than have someone click on something because they were embarrassed to ask.”

Most importantly, school leaders must put these tips into action and model safe digital practices for students and staff.

“We spend a great deal of time thinking about school safety in terms of our physical buildings—who can enter, how our doors are secured and how we respond in an emergency, Dr. Bowling-Jenkins said. “Our responsibility to protect children doesn’t stop at the schoolhouse door. Today, it extends into the digital spaces where we teach, communicate and store information. Protecting those spaces is another way we protect the students and families we serve.”

 

A serious concern for schools

Dr. Bowling-Jenkins’ experience was not an isolated one. 

Cyberattacks on schools are common: 82% of schools experienced an incident within an 18-month period, with 8,100 confirmed cybersecurity incidents in that timeframe.

Attacks can begin with something as ordinary as a phishing email. Disguised as legitimate emails, hackers trick recipients into clicking a malicious link or attachment. When this happens, the attackers can gain access to a network and encrypt critical files.

And, without reliable backups, a school could face significant disruption to teaching, administration, communication and other essential services.

Even strong cybersecurity practices cannot guarantee that a school will never experience an incident. That’s why a response plan should be part of school preparation.

Administrators should establish who is responsible for shutting down affected systems, contacting IT personnel, communicating with staff and families, documenting the incident and coordinating with appropriate authorities. 

The Cybersecurity & Infrastructure Security Agency (CISA) recommends that K-12 organizations regularly exercise their incident response plans and build the ability to continue essential operations during an attack. The goal is resilience: if technology goes offline, schools need a way to continue teaching, communicate, recover data and return to normal operations. 

School administrators should start with foundational protections rather than trying to implement every cybersecurity technology at once.
 

Require multifactor authentication

As Dr. Bowling-Jenkins asserted, passwords alone are not enough to protect important accounts. Multifactor authentication (MFA) adds another verification step, making it substantially harder for an attacker to access an account using a stolen password. MFA is one of the most impactful initial cybersecurity investments for K-12 organizations.
 

Keep systems updated 

Operating systems, applications, browsers, network equipment and security tools should receive updates and security patches promptly. CISA specifically recommends addressing known exploited vulnerabilities because attackers often exploit unpatched systems.
 

Back up critical data 

Schools should regularly back up important information and test whether those backups can actually be restored. Always maintain offline, encrypted backups because ransomware can attempt to encrypt or destroy backups that remain connected to an affected network.
 

Limit access

Staff and students should only have access to the systems and information they need. Limiting permissions can reduce the damage if an account is compromised.
 

Train teachers and staff 

Technology policies are only effective when the people using school technology understand them. The U.S. Department of Education's Student Privacy Policy Office recommends that teachers watch for social engineering, use strong authentication, install software updates, use antivirus protection, avoid public Wi-Fi for sensitive information, encrypt sensitive data, practice safe browsing, use approved software, back up data and never leave devices unlocked or unattended.

Training should focus on realistic situations rather than technical jargon. Teachers can practice identifying suspicious emails, questionable links, unusual requests for student information and unexpected password-reset messages. Schools can also conduct simulated phishing exercises to help employees recognize and report suspicious messages before they become real incidents.


Just as importantly, cybersecurity training should avoid creating a culture of blame. People make mistakes. The goal should be to encourage employees to report suspicious activity quickly, even if they already clicked something.


If you’re considering following your dream of teaching, Rutgers Alternate Route can offer you the support and training you need to succeed. Be sure to follow Rutgers Alternate Route on Twitter or sign up for Alternate Route’s monthly newsletter to receive more information and stories from the field of education.

Add new comment

Plain text

  • No HTML tags allowed.
  • Web page addresses and email addresses turn into links automatically.
  • Lines and paragraphs break automatically.

Dr. Jason Marx

Dr. Marx teaches in the 400-hour Alternate Route program at the Rockaway location through the Rutgers-Graduate School of Education.

Currently serving as Student Services Director of Butler School District, Dr. Marx is a 20-plus years veteran educator who has served public education as a middle school teacher, a middle school assistant principal, an elementary principal and a principal of a gifted and talented middle and high school.

Dr. Marx holds an Ed.D. and Ed.M. from Seton Hall University. He also holds a M.A. in History from Montclair State University.

Teaching is no simple task for a first-year teacher. Providing new teachers with support is vital for them not only in learning how best to educate students, but to ensure a successful and rewarding career. If through my work with new teachers, I can support their professional growth then I am helping to ensure that we are placing quality educators in front of students. New teachers are so passionate about entering the field of teaching, and I take great pride in helping them make this transition a seamless one.