Texas K-12 Cybersecurity  •  FERPA • HB 18 / SCOPE Act • CJIS (SRO) • TIPS/BuyBoard/DIR • SDVOSB

1,200 Texas ISDs. Every one a ransomware target.

Dallas ISD (Aug 2022) — RansomHouse published 2,000+ SSNs, student IEP records, and staff credentials. Athens ISD paid $50,000 to recover district systems in 2022. PowerSchool (Dec 2024–Jan 2025) exposed historical student and teacher data across 6,500+ districts nationwide, including multiple Texas LEAs. Cleveland MetroSchools (Dec 2024) lost student records for 18,000+. Your district is next on the list — or it already happened and you don't know yet.

Get your free $2,500 assessment → View cooperative contract pricing ↓
⚠️
HB 18 / SCOPE Act in effect since September 1, 2024. Texas districts must now ensure all EdTech vendors comply with strict minor data protections — data minimization, parental consent, and privacy notice requirements. Vendor data privacy agreements under TX Ed Code §32.151 must be updated to reflect SCOPE Act obligations. CoreRecon's Fortress tier includes SCOPE Act vendor assessment.
K-12 Attack Surface — Texas Districts

The attack surface isn't your servers.
It's your entire stack.

K-12 districts are uniquely vulnerable because the threat surface extends from campus HVAC controllers to PowerSchool vendor portals to the SRO's CJIS terminal. Texas K-12 SIX data and CIS MS-ISAC reporting confirm that education is the highest-growth ransomware sector — with summer dwell time as the primary attacker strategy. Districts don't discover the compromise until the September bell rings.

Student PII — FERPA Trigger
The Highest-Value Target in K-12
Student SSNs, IEP/504 accommodations, disciplinary records, parent financial data, and special education medical records. A single published dataset triggers FERPA breach notification and potential loss of Title I/II funding. Dallas ISD (Aug 2022): RansomHouse published 2,000+ SSNs. Fort Worth ISD region: multiple small districts hit in coordinated 2024–2025 waves. Average K-12 breach: 47,000 student records exposed.
EdTech Supply Chain — PowerSchool, Skyward, Frontline
Single Point of Catastrophic Failure
SIS platforms hold every student record going back years. The December 2024 PowerSchool breach hit 6,500+ districts via a single compromised vendor maintenance credential. Skyward and Frontline HR serve hundreds of Texas districts — a credential reuse attack on one vendor cascades across the entire customer base. Staff SSO means one phished admin = full district access. Vendor monitoring is not optional. It's the attack vector.
CJIS Data — Campus PD Risk
SROs Create Federal Compliance Obligations
Districts with school resource officers (SROs) who access TCIC/NCIC databases are in scope for FBI CJIS Security Policy v6.0. This applies to the entire district network, not just the SRO terminal — any system connected to the same environment as CJIS-accessed devices falls under the 13-policy-area framework. Most Texas ISDs with SRO programs don't know they're in scope. CJIS v6.0 auditing activated October 2025.
Chromebook Fleets + Legacy HVAC
Operational Technology on School Networks
Campus SCADA for HVAC, badge access, and door control systems often run on the same network segments as administrative endpoints. Legacy BMS (Building Management Systems) run Windows XP and Server 2003 — unpatched by design, unmonitored by default. Meanwhile, Chromebook MDM misconfiguration creates lateral pivot paths from student devices to admin networks. Summer break = 10 weeks of unmonitored dwell time.
Staff Payroll + IEP Records
IDEA Confidentiality + Double Extortion
IDEA mandates strict confidentiality for Individualized Education Programs (IEPs). A ransomware group that exfiltrates IEP files — diagnoses, accommodations, behavioral intervention plans — holds maximum extortion leverage: districts pay or face the reputational catastrophe of publishing special-needs children's medical data. Ransomware groups specifically search for /IEP/, /504/ directories.
Summer Break Timing
The Attacker's Favorite Calendar Window
K-12 SIX and CIS MS-ISAC incident data confirm: June–August is peak K-12 ransomware season. Attackers establish persistence in May or early June, then detonate ransomware the week before school starts — when operational pressure is maximum and IT staff is minimum. Glen Rose ISD (2022): hit during summer. Athens ISD (2022): summer deployment. The pattern is consistent. No SOC coverage during summer = open season.
K-12 Regulatory Stack — Texas

Seven frameworks.
One managed SOC team.

Texas K-12 districts face more compliance obligations than most mid-market healthcare organizations — with a fraction of the IT staff. FERPA, HB 18/SCOPE Act, SB 820 TEA coordinator requirements, CJIS for SRO programs, and Texas Government Code 2054 stack on top of each other. Here's every framework in scope and what CoreRecon covers.

Requirement Effective / Status Key Obligations Penalty / Consequence CoreRecon Coverage
FERPA Active — ongoing Protect student education records; breach notification; restrict third-party data access; data privacy agreements with vendors Loss of federal Title funding; OCR investigation; mandatory corrective action plan Sentinel Data access monitoring, breach detection, 72-hr notification support, audit logging
IDEA Confidentiality Active — ongoing IEP/504 records treated as education records; strict access controls; parent rights to records OCR investigation; IDEA complaint resolution; loss of IDEA Part B funding Sentinel Sensitive data classification, privileged access monitoring for IEP system access
TX Ed Code §38.027 (Breach Notification) Active — ongoing Districts must notify TEA, affected individuals, and law enforcement of security breaches involving student PII TEA corrective action; parent/community trust damage; media exposure Sentinel Breach event documentation, IR playbook, notification timeline support
HB 18 / SCOPE Act — Minors' Data Eff. Sep 1, 2024 Digital service providers must: data minimization for minors, parental consent for sensitive data, no behavioral advertising, privacy notice disclosures; districts must enforce via vendor agreements AG enforcement; fines up to $7,500/violation/day; reputational damage; parent lawsuits Fortress SCOPE Act vendor assessment, data privacy agreement review, vendor data use mapping
SB 820 — TEA Cybersecurity Coordinator Active — TEA reporting required Each district must designate a cybersecurity coordinator; complete TEA-approved training; file annual cybersecurity reports to TEA; report cybersecurity incidents TEA corrective action; accreditation risk; state funding conditions Fortress Coordinator reporting cadence support, incident documentation, TEA report templates
CJIS Security Policy v6.0 (SRO Programs) v6.0 audit active Oct 2025 All 13 CJIS policy areas: physical protection, personnel security, mobile devices, incident response, auditing & accountability, access control, identification & authentication, configuration management, media protection, systems & comm. protection, formal audits, security awareness Loss of NCIC/TCIC access; FBI audit findings; federal criminal justice funding risk Command Full CJIS v6.0 — 13 policy areas, SRO environment scoping, audit-ready evidence packages
TX Gov. Code §2054 (State-Funded Entity Cyber) Active — DIR oversight State-funded entities must: maintain cybersecurity programs aligned to Texas Cybersecurity Framework (TCF), participate in statewide threat intel sharing, report cybersecurity incidents to DIR within required timeframes DIR audit findings; state funding conditions; mandatory remediation timelines Fortress TCF-aligned security posture documentation, DIR incident reporting support

* COPPA applies to districts using online services for students under 13. CIPA/E-Rate compliance applies to E-Rate Category Two recipients (internet safety policy, content filtering). Both covered at Sentinel tier.

Why CoreRecon for Texas K-12

Three differentiators that matter
when it's your students' data.

🏛️
Texas-Resident 24/7 SOC — No Overseas Routing
CoreRecon's SOC team is Texas-resident. No routing student PII alerts through overseas analyst desks. No night-shift handoff to third countries. Every analyst who touches your district's data is subject to US federal law and Texas data protection obligations. For districts with CJIS obligations, this is a hard requirement — CJIS prohibits routing CJI through non-vetted foreign nationals. We comply by design.
⏱️
30-Minute Contractual SLA — Not an Aspiration
The industry standard for MDR response is 1–4 hours. Our contractual SLA is 30 minutes — written into the service agreement, not a marketing claim. When ransomware hits at 2am during summer break, your IT director isn't checking email. Our SOC contains the incident, preserves forensic evidence, and calls you directly. The 30-minute window is the difference between containment and full encryption.
📋
SDVOSB — TIPS, BuyBoard, DIR Cooperative Contracts
CoreRecon is a Service-Disabled Veteran-Owned Small Business (SDVOSB). Texas ISDs can procure our services through TIPS cooperative contracts, BuyBoard (TASB), and DIR — eliminating standalone RFP requirements and satisfying competitive bidding rules under Texas Education Code Chapter 44. Region ESC purchasing offices coordinate district onboarding. Procurement timelines shorten from 6 months to 6 weeks.
Scenario — 800-Student Texas District

Summer ransomware.
What 30 minutes looks like vs. the alternative.

A hypothetical based on actual K-12 ransomware patterns in Texas. The events are composite — the attack surface, timing, and recovery costs are drawn from confirmed 2022–2025 Texas district incidents.

Without 24/7 SOC Coverage
District IT Director Discovers It Monday Morning
  • Attacker establishes persistence in June — summer break begins
  • 8-week dwell time: lateral movement, credential harvest, data staging
  • Ransomware deploys Sunday night before first day of school
  • SIS encrypted — student schedules unavailable, buses can't route
  • 38,000 student records published if district doesn't pay
  • First day of school delayed 5 days while board authorizes payment
  • Recovery cost: $1.2–2.8M total (ransom + forensics + rebuild + notification)
  • FERPA breach notification to all families; TEA report required
  • Cyber insurance renewal denied or premium +80%
With CoreRecon 30-Minute SLA
SOC Analyst Alerts District IT at 2:17am — Contained by 2:47am
  • Attacker establishes persistence in June — CoreRecon detects anomalous lateral movement June 12
  • Compromised account isolated within 30 minutes of first alert
  • No ransomware deployment — attacker evicted before staging completes
  • Forensic evidence package preserved — attack vector documented
  • No student records exfiltrated — FERPA notification not required
  • First day of school: unaffected
  • Incident cost: ~$12,000 (IR labor + forensics — covered by cyber insurance)
  • TEA report filed on time; cybersecurity coordinator documentation complete
  • Cyber insurance renewed at same rate; Letter of Engagement provided
Athens ISD — 2022
$50,000 Ransomware Payment
What Happened
Athens ISD (Henderson County, Texas) was hit by ransomware in 2022 and paid approximately $50,000 to recover encrypted district systems. Attack vector included exposed remote access and insufficient endpoint monitoring during a period of reduced IT staffing.
What detection would have changed: Exposed RDP identification plus after-hours anomaly alerts. The attack surface existed for weeks before deployment. This is Sentinel-tier.
Dallas ISD — August 2022
RansomHouse Publishes 2,000+ SSNs
What Happened
RansomHouse published data exfiltrated from Dallas ISD including 2,000+ SSNs, student IEP records, staff credentials, and disciplinary files. One of the largest public K-12 data exposures in Texas history — triggered mandatory FERPA notifications.
What detection would have changed: Data exfiltration monitoring with DLP controls. Ransomware groups stage and exfil before they encrypt. Detecting the staging phase stops publication. This is Fortress-tier readiness.
PowerSchool Supply Chain — Dec 2024
6,500+ Districts Including TX LEAs
What Happened
Attacker used compromised PowerSchool maintenance credentials to access the customer support portal and export historical student and teacher records — including SSNs and IEP medical data. Multiple Texas districts received vendor breach notification 3+ weeks after the event.
What detection would have changed: Vendor risk monitoring with anomalous SIS export detection. Districts with documented FERPA IR plans activated in under 72 hours vs. weeks. This is Fortress-tier readiness.
90-Day Onboarding — Texas K-12 Districts

From cooperative contract to
active SOC in 90 days.

Aligned to the TEA cybersecurity coordinator reporting calendar and SB 820 obligations. Cooperative contract execution (TIPS/BuyBoard/DIR) can happen in parallel with Phase 1 deployment.

1–30
Deploy + Baseline
Endpoint Deployment + Network Baseline + Asset Discovery
  • Cooperative contract executed (TIPS/BuyBoard/DIR) — procurement documentation package delivered
  • EDR sensor deployment to staff workstations, servers, and admin infrastructure (Chromebook fleets excluded)
  • Network baseline established — traffic patterns, east-west communications, DNS telemetry
  • Attack surface scan: exposed RDP, unpatched internet-facing services, domain/subdomain enumeration
  • Asset inventory completed — maps endpoint footprint for accurate billing and scope confirmation
  • SOC integration: alert routing, escalation contacts, cybersecurity coordinator contact designated
  • Initial threat hunt: check for existing indicators of compromise (common in districts that haven't been monitored)
  • ESSER III procurement documentation delivered if applicable (obligated within 30 days of contract)
31–60
Compliance + Hardening
SCOPE Act Vendor Audit + CJIS Readiness + TEA Alignment
  • HB 18 / SCOPE Act vendor assessment: audit all EdTech vendor data agreements against SCOPE Act obligations
  • FERPA vendor agreement review: confirm TX Ed Code §32.151–§32.156 agreements are current and SCOPE Act-compliant
  • CJIS scoping (if SRO program): identify all systems with CJI access or network adjacency; document CJIS policy area gaps
  • SB 820 TEA coordinator alignment: establish reporting cadence, incident documentation templates, annual report structure
  • TEA Cybersecurity Framework (TCF) posture mapping — gap analysis against required controls
  • PowerSchool/Skyward/Frontline vendor risk monitoring activated — anomalous SIS API access alerting
  • Firewall rule review and network segmentation assessment (Fortress tier)
  • DIR §2054 compliance posture baseline documented
61–90
Tabletop + Reporting
Tabletop Exercise + Reporting Cadence + Annual Readiness Package
  • Tabletop exercise: ransomware-during-summer-break scenario with superintendent, IT director, and TEA cybersecurity coordinator
  • FERPA breach response runbook finalized — TEA notification timeline, parent notification templates, OCR documentation
  • TEA cybersecurity coordinator annual report draft: incident log, security posture summary, training completion documentation
  • CJIS audit evidence package (Command tier): all 13 policy areas, personnel security documentation, audit-ready binder
  • Cyber insurance Letter of Engagement and Security Posture Summary delivered — formatted for carrier requirements
  • Monthly reporting cadence established: executive dashboard for superintendent, technical dashboard for IT director
  • Summer coverage briefing: SOC protocols for reduced-staffing periods, emergency contact escalation path
  • Onboarding complete — district is monitored, compliant, and procurement-documented
Pricing for Texas K-12 Districts

Staff endpoints only.
Procurable via cooperative contract.

CoreRecon's K-12 pricing covers staff workstations, servers, and administrative infrastructure — not 1:1 student device fleets. Typical endpoint counts by district size: small (200 students, ~40 staff endpoints), mid (1,500 students, ~200 staff endpoints), large (8,000+ students, ~800–1,200 staff endpoints). Month-to-month. No minimums. Procurable via TIPS, BuyBoard, and DIR cooperative contracts.

Tier $/Endpoint/Month What's Included Best For
Sentinel $89 24/7 TX-resident SOC, EDR deployment, FERPA breach detection, anomalous access monitoring, attack surface management, CIPA policy posture, monthly reports, cyber insurance Letter of Engagement Small-to-mid districts (no SRO program); FERPA + COPPA baseline; basic insurance requirements; budget-constrained procurement
Fortress $109 All Sentinel + SIEM, firewall management, network segmentation, vendor risk monitoring (PowerSchool/Skyward/Frontline), SCOPE Act / HB 18 vendor assessment, TX Ed Code §32.151 documentation, SB 820 TEA coordinator reporting support, DIR §2054 posture documentation Mid-size districts with active EdTech vendor stack; SB 820 TEA coordinator compliance; SCOPE Act obligations; E-Rate eligibility
Command $129 All Fortress + full CJIS v6.0 (all 13 policy areas), SRO program security architecture, annual CJIS audit support, TX DPS coordination, CJIS audit-ready evidence package, ESSER III procurement documentation, tabletop exercise included annually Districts with SRO programs (CJIS in scope); large ISDs; maximum insurance coverage; ESSER III-funded deployments requiring full documentation
Small District Example
~$3,560/mo
40 endpoints × $89 (Sentinel). 200-student district. No SRO.
Mid District Example
~$21,800/mo
200 endpoints × $109 (Fortress). 1,500-student district with EdTech stack.
Large District Example
~$129,000/mo
1,000 endpoints × $129 (Command). 8,000+ students, SRO program, CJIS in scope.

* Staff endpoints = workstations, servers, network appliances, administrative infrastructure. Student 1:1 devices (Chromebooks, iPads) excluded. Endpoint count confirmed during free assessment — no surprises before contracting. Cooperative contract numbers available for TIPS, BuyBoard, and DIR on request.

Start with a free assessment → Full Pricing Page →
The CoreRecon Track Record

Texas clients. Real outcomes.
Sectors that can't afford downtime.

6
Active Texas clients
30min
Contractual incident response SLA
$0
Ransom payments (monitored clients, 2025)
1,200+
Texas public ISDs in our target market

CoreRecon serves Texas clients across municipalities, law firms, oil & gas, healthcare, and defense. SDVOSB-certified. AT&T vendor for State of Texas incident response. Cooperative contracts via TIPS, BuyBoard, and DIR make procurement fast and compliant with TX Education Code Chapter 44. Zero ransomware payments among monitored clients in 2025.

Frequently Asked Questions

What IT directors, superintendents,
and purchasing officers ask us.

Active Breach? 24/7 Emergency Response
District under attack? We respond in 30 minutes.
No retainer required. AT&T TX state vendor. SDVOSB-certified. No voicemail.
📞 (800) 955-2596 Or submit emergency intake form →
Free Security Assessment — $2,500 Value

Find out before the next semester starts whether your district has been quietly breached.

Most K-12 breaches aren't discovered until ransomware detonates. Average attacker dwell time in Texas education networks is 8 weeks. Our free assessment maps your endpoint exposure, identifies active compromise indicators, benchmarks against FERPA and CJIS requirements, and delivers a prioritized remediation plan with ESSER III documentation if applicable. Procurable immediately via TIPS, BuyBoard, or DIR.

Request your free assessment →

Delivered within 14 days  •  No credit card  •  Cooperative contract procurement available  •  SDVOSB

Related Sector · Universities & Community Colleges
Same FERPA. Different Scale. GLBA Financial Aid + HIPAA Added On Top.
Texas universities and community colleges face the same FERPA obligations as K-12 districts — but at larger scale, with GLBA Safeguards for financial aid and HIPAA for student health clinics added. See how CoreRecon covers the full higher education compliance stack.
Higher Ed Cybersecurity →
Texas Data Privacy · SCOPE Act · EdTech Vendors
HB 18 / SCOPE Act Vendor Obligations — Do Your EdTech Agreements Comply?
SCOPE Act (eff. Sep 1, 2024) applies to digital service providers processing minor data. If your vendors haven't updated their student data privacy agreements, your district may be facilitating non-compliance. Run the TDPSA readiness quiz to understand your exposure.
Take the TDPSA Quiz →
Related Sector · Texas Municipalities
Shared CJIS Obligations — Districts and Cities Often Share Network Infrastructure
Districts sharing infrastructure or CJIS access paths with city networks create overlapping compliance scope. If your district uses city-managed network segments for SRO CJIS access, both the city and district are in scope.
Municipalities Cybersecurity →
Free Tool — vCISO ROI Calculator
Fractional vCISO vs. Full-Time Hire — Calculate the Real 3-Year Cost
IBM CODB breach model + compliance penalty exposure + tier recommendation. Know the math before your board asks the question.
Calculate vCISO ROI →