Ed-Tech Policy

Schools Are Major Targets of Cyberattacks. A Bipartisan Effort in Congress Aims to Help

By Lauraine Langreo — April 20, 2023 3 min read
Silhouette of a hacker in a hoodie using laptop with binary code overlay.
  • Save to favorites
  • Print

A bipartisan group of federal lawmakers reintroduced legislation that they argue would strengthen cybersecurity in schools.

The Enhancing K-12 Cybersecurity Act would give schools and districts better access to cybersecurity resources and improve tracking of K-12 cyberattacks nationally. The bill is sponsored by Reps. Doris Matsui, D-Calif., and Zach Nunn, R-Iowa, and Sens. Marsha Blackburn, R-Tenn., and Mark Warner, D-Va.

The proposal comes as cyberattacks targeting schools are becoming more common and more sophisticated. There have been 1,619 publicly disclosed cyber incidents between 2016 and 2022, according to K12 Security Information Exchange (K12 SIX), a nonprofit focused on helping schools prevent cyberattacks. Hackers have targeted districts of all sizes, including Los Angeles Unified, the nation’s second largest.

“Cybercriminals are rapidly evolving their strategies to cause chaos and disruption, yet a lack of resources for our schools is forcing them to do more with less,” said Matsui, the ranking member of the House Energy and Commerce Subcommittee on Communications and Technology, in a statement. “The Enhancing K-12 Cybersecurity Act would establish a crucial roadmap to prepare our K-12 cyberinfrastructure for future attacks.”

The legislation would direct the federal Cybersecurity and Infrastructure Security Agency (CISA) to establish a Cybersecurity Incident Registry to track incidents of cyberattacks on K-12 schools. Submitting incidents to the registry would be voluntary, and the information would be used to conduct trend analyses, increase awareness, and develop strategies to prevent and respond to incidents.

“There are a lot of very strong reasons that we want school systems to share information about their experience with cybersecurity,” said Doug Levin, the national director of K12 SIX. It informs policymakers, it helps law enforcement, it helps other school systems protect themselves from copycat attacks, and it informs the public if sensitive data has been inappropriately accessed.

While “it’s not unusual to see voluntary reporting regimes, the jury’s out on how effective that may be,” Levin said. “If there is not a direct return to the organization who is submitting that information, it just feels like an unfunded mandate. If the data goes into a black hole and if they’re not seeing a benefit, it can be difficult to convince people to do that work.”

Having voluntary reporting systems also means that districts might underreport incidents, Levin said.

Some states, such as New York and Texas, mandate K-12 schools to report data breaches and cyberattacks. And a federal cybersecurity incident reporting law passed in 2022 might include schools as one of the organizations required to report, but it’s still going through the rulemaking process, according to Levin.

The Enhancing K-12 Cybersecurity Act would also establish a program, which would be funded up to $20 million over two fiscal years, that would help districts address cybersecurity risks and threats to their information systems and networks.

The legislation would also direct CISA to establish a Cybersecurity Information Exchange to publish information, best practices, and grant opportunities to improve cybersecurity.

“This [$20 million] is a drop in the bucket in terms of need. I certainly wouldn’t say that it is sufficient,” Levin said. “But if invested smartly, at a national level, it can make a tremendous difference.”

The bill was first introduced in the U.S. House of Representatives in 2021 with bipartisan support. While it didn’t advance, Congress instead passed the K-12 Cybersecurity Act, which mandated CISA to publish a report on the risks K-12 schools face, along with recommendations and resources to help schools reduce risks and maintain resilient cybersecurity programs.

The CISA report was published in January and showed that the K-12 sector is becoming increasingly vulnerable and needs assistance. The agency recommended implementing effective security measures, addressing resources constraints, and focusing on collaboration.

Education organizations such as the State Educational Technology Directors Association and the Consortium for School Networking have endorsed the bill.

“It’s encouraging that Congress is continuing to be responsive, at least in part, to the concerns of the K-12 community,” Levin said. “This shouldn’t be a partisan issue. So whether it is this [bill] or something like this, the support from Congress would be much appreciated and put to good use.”

Related Tags:

Events

This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
Professional Development Webinar
Inside PLCs: Proven Strategies from K-12 Leaders
Join an expert panel to explore strategies for building collaborative PLCs, overcoming common challenges, and using data effectively.
Content provided by Otus
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
Science Webinar
Making Science Stick: The Engaging Power of Hands-On Learning
How can you make science class the highlight of your students’ day while
achieving learning outcomes? Find out in this session.
Content provided by LEGO Education
Teaching Profession Key Insights to Elevate and Inspire Today’s Teachers
Join this free half day virtual event to energize your teaching and cultivate a positive learning experience for students.

EdWeek Top School Jobs

Teacher Jobs
Search over ten thousand teaching jobs nationwide — elementary, middle, high school and more.
View Jobs
Principal Jobs
Find hundreds of jobs for principals, assistant principals, and other school leadership roles.
View Jobs
Administrator Jobs
Over a thousand district-level jobs: superintendents, directors, more.
View Jobs
Support Staff Jobs
Search thousands of jobs, from paraprofessionals to counselors and more.
View Jobs

Read Next

Ed-Tech Policy More States Are Moving to Ban Cellphones at School. Should They?
While cellphone bans are popular with many educators, some researchers say there's not much evidence yet that these policies work.
A student uses their cell phone after unlocking the pouch that secures it from use during the school day at Bayside Academy on Aug. 16, 2024, in San Mateo, Calif.
A student uses a cellphone after unlocking the pouch that secures it from use during the school day at Bayside Academy in San Mateo, Calif., on Aug. 16, 2024.
Lea Suzuki/San Francisco Chronicle via AP
Ed-Tech Policy What Schools Look Like Without the Cellphone Distraction
Student behavior has improved and disciplinary referrals have gone down, administrators say.
7 min read
School kids placing putting phones away during class
Dobrila Vignjevic/E+
Ed-Tech Policy FCC’s ‘Net Neutrality’ Rules Struck Down. Could This Mean Slower Internet for Schools?
Many schools fear that without the policy protection internet service providers could slow down the flow of content to schools.
Meg James, Los Angeles Times
5 min read
A home router and internet switch are displayed on June 19, 2018, in East Derry, N.H. Telecommunications industry groups on Wednesday, May 4, 2022, ended their bid to block California's net neutrality law that prevents broadband providers from throttling service. In a federal court filing in Sacramento, the groups and California Attorney General Rob Bonta jointly agreed to dismiss the case.
A home router and internet switch are displayed on June 19, 2018, in East Derry, N.H.
Charles Krupa/AP
Ed-Tech Policy Ed. Dept. Recommends These 3 Principles to Develop School Cellphone Policies
Cellphone policies should be developed in consultation with students, teachers, and parents, Secretary of Education Miguel Cardona said.
4 min read
Photograph of a white teen using a cellphone in the classroom.
iStock/Getty